Senior Defensive Security Consultant
SpecterOpsAbout the role
SpecterOps is looking for senior defensive security consultants to serve on the Consulting Services team as analysts, detection engineers, and program developers. The SpecterOps Adversary Detection service line provides strategic advisory positions to mature our customer’s internal detection capabilities. They often perform independent assessments to determine the overall state of a customer's detection program or to proactively identify adversaries operating silently in a customer’s environment. Additionally, our consultants frequently support SpecterOps training offerings by developing course content and delivering training during public and private events.
A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.
Salary Range: Base salary annually, commensurate with experience.
- Associate Consultant - $100,000 - $125,000
- Consultant - $125,000 - $145,000
- Senior Consultant - $145,000 - $170,000
Location: This position is remote, based in the U.S. with optional travel quarterly for in person company events and other ad hoc meetings.
-
Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas
Responsibilities
- Create evasion-resilient detections based on independent research alongside supporting resources, documentation, and automation
- Evaluate existing detection content in client environments and make improvements as necessary
- Evaluate the maturity of common security operations roles and functions, including: threat intelligence, threat hunting, detection engineering, SOC operations, incident response, and security engineering
- Utilize common security tooling, including: EDR, SIEM, and live response tools
- Utilize and provide guidance regarding common telemetry sources, including: EDR, Sysmon, Windows Event Logging, SIEM, WAF, IDS/IPS, cloud platforms (Azure, AWS, GCP), and others
- Build scripts, tools, or methodologies to enhance investigation processes
- Serve as a subject matter expert (SME) in one of the following areas: detection engineering, network, memory, and/or disk forensics, log analysis, malware triage, or reverse engineering
- Effectively communicate successes and obstacles with fellow team members and team lead(s)
- Interface with client contact(s) and staff in a constructive and professional manner
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
- Effectively communicate investigative findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel
- Assist with scoping prospective engagements, participating in investigations from kickoff through remediation, and mentoring less experienced staff
- Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, student support, etc.)
- (Senior Consultant) Create and deliver at least two pieces of content a year (e.g., blog post, conference presentation, workshop, or webinar)
Requirements (All Positions)
- Ability to travel domestically and internationally up to an average of 25% over the course of one year
- Must be able to pass a criminal background check
- Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency
As an Associate Consultant, your primarily responsibility will be to learn. You will engage, participate, and contribute to the execution of a variety of services and projects. In doing so, you will actively develop a basic understanding of the SpecterOps Adversary Simulation service line and develop skills in one or more technical areas.
Desired Qualifications (Associate Consultant)
- Foundational knowledge of defensive security concepts and assessments
- Foundational knowledge of security principles, policies, and industry best practices
- Working knowledge of Windows and *NIX-based operating systems
- Working knowledge of networking concepts
- Working knowledge of Active Directory
- Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
- Aptitude for technical writing, including assessment reports, presentations, and operating procedures
- Strong written/verbal communication and interpersonal skills
- Determination to better self and the overall information security community through research efforts and release through blog posts, conference
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s