Vulnerability Analyst (Red Team)
DiscoverAbout the role
Discover. A brighter future.
With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.
Come build your future, while being the reason millions of people find a brighter financial future with Discover.
Job Description:
At Discover, be part of a culture where diversity, teamwork and collaboration reign. Join a company that is just as employee-focused as it is on its customers and is consistently awarded for both. We’re all about people, and our employees are why Discover is a great place to work. Be the reason we help millions of consumers build a brighter financial future and achieve yours along the way with a rewarding career.
As a Vulnerability Analyst (Red Team), you will analyze and assess technologies and build your expertise across the compliance, vulnerability and threat landscape. Actively manages and escalates risk and customer-impacting issues within the day-to-day role to management. Actively manages and escalates risk and customer-impacting issues within the day-to-day role to management.
You will help optimize cybersecurity program processes and output. Vulnerability Analysts (Red Team) at Discover contribute to the broader program roadmap. You will reduce cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment by conducting covert/overt adversary simulation and emulation. This position works closely with offensive and defensive partner teams to plan, coordinate, execute and report on detection gaps and control weaknesses to improve cyber defense across the enterprise.
The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Discover’s brand, systems and data. Offensive Security is part of the Attack Surface Management team and assists with identifying opportunities to reduce Discover’s attack surface and overall cybersecurity posture against a broad range of cyber threats and develop strategies to most effectively address the threats.
Responsibilities
· Execute sophisticated adversary simulation activities against Discover to enable identification and mitigation of identified vulnerabilities, attack paths, and weaknesses in detective or responsive controls
· Understand the defensive side, blue team, Security Operations Center (SOC), and security monitoring and response (SIEM, IDS/IPS etc), as well as EDR (e.g. for bypasses), overall monitoring, detection and indicators of compromise, and creating effective red team activities to test these (e.g. developing / using malware, pivoting, escalating privileges, staying stealthy etc)
· Research, develop, maintain and apply offensive tactics, techniques, and procedures (TTPs) in order to effectively mimic the capabilities of relevant threat actors
· Provide subject matter expertise for cyber defenders, remediation teams, and enterprise technology teams
· Build and maintain technical infrastructure to support adversary operations and testing activity
· Automate repetitive pre and post-exploitation activities as applicable
· Documentation of team processes/infrastructure, write reports of attacks/vulnerabilities, and present findings to stakeholders
· Communicate with all stakeholders, internal and external, finding, advising and implementing the best solutions.
Minimum Qualifications
At a minimum, here’s what we need from you:
· Bachelors – Computer Science, Information Security, Business or Analytics or related
· 4+ years – Information Security, Cybersecurity, Computer Science, Data Analytics or related
· In lieu of a degree 6+ Years – Information Security, Cybersecurity, Computer Science, Data Analytics or related
Internal applicants only: technical proficiency rating of competent on the Dreyfus cybersecurity scale
Preferred Qualifications
If we had our say, we’d also look for:
· OSCP
· GIAC
· CISSP
· PNPT
· CRTO
External applicants will be required to perform a technical interview.
What are you waiting for? Apply today!
And by the way, while you're waiting to hear from us, don't forget to check out the great benefits Discover offers.
All Discover employees place our customers at the very center of our work. To deliver on our promises to our customers, each of us contribute every day to a culture that values compliance and risk management.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s