Jobs and Careers
EX

Senior Offensive Security Engineer (Remote)

Experian
., ., United States, United StatesRemotefull_timeVerifiedPosted 18 Jan 2024

About the role

Company Description

Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been name in the 100 “World’s Most Innovative Companies” by Forbes Magazine

Job Description

What you’ll be doing 

Experian’s Offensive Security team is charged with improving the organization’s security posture through clarifying risk and verifying the efficacy of our technical, people, physical and process controls from an attacker perspective. In order to accomplish this, the team performs regular Adversary Simulation (Red Team) testing, leads and contributes to Purple Team Exercises and performs Ad-Hoc and Tactical Assessments based on changes to the threat landscape and organizational needs. 

As a Senior Engineer within the Offensive Security team, you will participate in the design and execution of both campaign-based adversary simulation assessments and tactical assessments, whilst contributing to collaborative Purple Team exercises. Successful team members must be capable of evaluating environments, applications, systems and processes to discover weaknesses, and subsequently leverage those discoveries into actionable real-world attack strategies. In addition, all team members are expected to be able to provide an “attacker perspective” and be able to effectively communicate highly complex technical issues to a variety of audiences. 

To succeed in this role the candidate will possess breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programming. All Offensive Security team members are expected to continuously improve their tradecraft through research, to add breadth and depth to their knowledge. 

Responsibilities

  • Collaborate closely with other teams within the Cyber Fusion Centre and the wider organization to ensure threat-informed Cyber Risks are understood and articulated appropriately, with a goal of contributing to the successful defense of the organization
  • Support Offensive Security’s engagement at multiple organizational levels, from senior leaders to technical analysts to help drive risk understanding and verify the efficacy of remediation/mitigative actions
  • Actively participate in performing physical exploitation, network exploitation and social engineering assessments against authorized targets
  • Leverage CyberThreat Intelligence, Offensive Security Research, previous Adversary Simulation (Red Team) findings and internal risk intelligence to develop test cases demonstrating TTP effectiveness against Experian’s control environment
  • Continuously research and stay up to date with the latest cyber threats, attack vectors and attacker methodologies
  • Work with the team to provide remediation recommendations across the organization to aid with mitigation of identified Cyber Risks
  • Actively engage in all phases of Offensive Security operations
  • Develop scripts, tools and methodologies to increase Offensive Security’s capabilities and educate other team members
  • Leverage MITRE ATT&CK Framework and other structured attack analysis tools to describe and classify attacker methodology and significance

Qualifications

What your background looks like 

  • Relevant, recent and verifiable experience in offensive security and adversary simulation
  • Detailed knowledge of global cyber threats, threat actors, and the tactics, techniques and procedures used by cyber adversaries, specifically those targeting the financial services and healthcare sectors
  • 5-8+ years of experience in Cyber Security in enterprise environments 
  • 3+ years of experience in two or more of the following areas: 
    • Network penetration testing and manipulation of network infrastructure 
    • Web application penetration testing assessments 
    • Email, phone, or physical social-engineering assessments 
    • Developing, extending, or modifying exploits, shell code or exploit tools 
    • Red/Purple teaming exercises 
    • Covert physical intrusion 
    • Cloud security or penetration testing (any major provider) 
  • Experience in enterprise-scale information technology implementations and operations preferred
  • Industry certifications such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN or equivalent experience 
  • Proficient in attacker tooling, including post-exploitation frameworks and tooling
  • Proficient in one or more of the following programming languages (C, C++, C#, Go)
  • Proficient in one or

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Experian

View company profile →