← к выдаче
безопасность

Consultant, Red Teaming

EnsignSG11 дн. назад

Коротко

Plans and conducts red team engagements, adversarial simulations, and objective-based security assessments; collaborates with blue teams on purple team

Описание от работодателя

Ensign is hiring ! Red Team Engagements - Plan and conduct authorised Red Team engagements, adversarial simulations, and objective-based security assessments. - Translate relevant threats and customer risks into realistic attack scenarios. - Perform reconnaissance, initial-access testing, social engineering, privilege escalation, lateral movement, persistence, and data-access simulations where authorised. - Assess security controls across networks, endpoints, applications, cloud platforms, identity systems, and operational processes. - Identify and demonstrate attack paths that could expose critical systems or business assets. - Develop or adapt tools, scripts, payloads, and supporting infrastructure to achieve engagement objectives. - Maintain operational security and minimise the risk of unintended disruption throughout each engagement. Purple Team Engagements - Collaborate with Blue Teams, Security Operations Centres, incident response teams, and other defensive stakeholders. - Design and execute controlled attack scenarios to validate preventive, detective, and responsive security controls. - Map simulated adversary behaviours to recognised frameworks such as MITRE ATT&CK. - Evaluate security alerts, telemetry, logging coverage, investigation workflows, and response procedures. - Help defensive teams develop and refine detection rules, use cases, playbooks, and response processes. - Facilitate knowledge-sharing sessions to explain attacker techniques and strengthen defensive capabilities. - Conduct validation and retesting to confirm that identified security gaps have been addressed. - Document improvements and remaining areas of security exposure. Engagement Planning and Governance - Define engagement objectives, scope, assumptions, success criteria, and rules of engagement with relevant stakeholders. - Ensure all activities are conducted within approved legal, ethical, safety, and customer-defined boundaries. - Follow applicable change-control, data-handling, access-control, and escalation procedures. - Maintain accurate records of actions, evidence, findings, and attack paths. - Communicate critical findings, operational concerns, and potential business risks promptly. - Coordinate with project managers, internal teams, and customer stakeholders throughout the engagement lifecycle. Reporting and Stakeholder Communication - Produce clear technical reports, executive summaries, attack narratives, and prioritised remediation recommendations. - Explain technical findings in terms of their operational and business impact. - Present engagement outcomes to technical teams, senior management, and executive stakeholders. - Deliver engagement debriefs and remediation workshops where required. - Support remediation planning, validation, and retesting. Capability Development - Contribute to the improvement of Red Team and Purple Team methodologies, tools, procedures, and knowledge bases. - Research emerging threats, vulnerabilities, attack techniques, defensive approaches, and security technologies. - Share technical knowledge, lessons learned, and good practices with team members. - Support the development of reusable attack scenarios and detection-validation content. Customer Engagement and Adaptability - Deliver assignments of varying scope, complexity, and duration based on customer and business needs. - Work at customer premises when required. - Adapt to different industries, technologies, operating environments, and levels of security maturity. - Remain flexible in supporting planned and ad-hoc project requirements. - Communicate effectively with internal teams and customer stakeholders throughout each assignment. - Offensive Security Certified Professional (OSCP) is required. - Advanced or specialist certifications, such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN, GXPN, would be advantageous. - Demonstrated experience in Red Teaming, Purple Teaming, adversarial simulation, penetration testing, or a related offensive security role. - Strong knowledge of adversary tactics, techniques, and procedures, including the MITRE ATT&CK framework. - Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud, and identity-based attack techniques. - Experience collaborating with defensive security teams to validate and improve security controls. - Understanding of defensive technologies and processes, including SIEM, endpoint detection and response, network monitoring, security logging, threat hunting, and incident response. - Proficiency with relevant commercial or open-source offensive security tools and frameworks. - Ability to develop or modify tools and scripts using languages such as Python, PowerShell, Bash, C#, or another relevant programming language. - Ability to analyse complex attack paths and translate technical findings into clear business risks and actionable recommendations. - Strong report-writing, presentation, communication, and stakeholder-management skills. - Sound professional judgement and a strong commitment to ethics, confidentiality, operational security, and authorised testing boundaries. - Ability to work independently and collaboratively within multidisciplinary teams. - Willingness and ability to undertake customer-facing assignments of varying duration, including working at customer premises when required. - Flexibility to support ad-hoc assignments and changing project requirements. - Eligibility to obtain any security clearance or customer-specific access approval required for assigned engagements. - A degree or diploma in cybersecurity, computer science, information technology, or a related discipline is preferred; equivalent practical experience will also be considered.