NetSPI

Principal Security Consultant (Red Team Operator)

NetSPI United States

Description

Title: Principal Security Consultant (Red Team Operator - US)

Locations: US, Remote

NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance. We help secure the most trusted brands on Earth with our Penetration Testing as a Service (PTaaS), Attack Surface Management (ASM), and Breach and Attack Simulation (BAS) solutions. Leveraging a unique combination of dedicated security experts, intelligent process, and advanced technology, NetSPI brings a proactive approach to cybersecurity with more clarity, speed, and scale than ever before.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

We are seeking a highly experienced professional with demonstrated technical depth and breadth in adversarial simulation as well as the soft skills to effectively communicate with executive and technical teams. Our Red Team operates globally in some of the largest and most well-defended networks. In this role, you’ll have the ability to work alongside a world-class team using top-tier custom tools. Applicants are expected to leverage strong problem-solving skills, as well as lead, collaborate, and innovate to deliver high-quality exercises and exceptional experiences for our

customers.

A day in the life of a NetSPI Principal Security Consultant:

  • Serve as a Red Team lead while planning, executing, and delivering exercises.
  • Utilize sophisticated technologies and capabilities to simulate complex attacks against mature, highly defended networks.
  • Research and develop innovative techniques, tools, and methodologies in support of Red Team Operations.
  • Author and deliver narrative driven and findings-based reports to clients.
  • Collaborate with clients to create remediation strategies that will help improve their detection and response capabilities.
  • Share technical expertise and best practices for various service lines aligned to NetSPI’s overall offensive security services catalog.
  • Assist in providing technical guidance to other team members as well as identifying areas of growth they should target to pass key exams or performance metrics.
  • Help define and document internal technical, and service processes and TTPs.
  • Contribute to the information security community through the development of tools, presentations, white papers, and blogs.


Requirements

  • Bachelor’s degree or higher with a concentration in computer science, engineering, math, IT, or equivalent experience.
  • Minimum of 10 years combined in IT and information security experience.
  • Minimum of 5 years’ experience performing offensive/attack-oriented security assessments.
  • Recognized Red Team or Penetration testing specific qualifications such as CCSAS, CCSAM, CRTO, OSED, OSCE(3) (GXPN, GPEN, OSCP, GWAPT or similar certifications may also be considered).
  • Strong communication, presentation and writing skills.
  • Expertise in both offensive and defensive security concepts.
  • Demonstratable knowledge in the following areas:
    • Windows and/or *nix administration within client and server architecture.
    • Networking concepts such as routing, switching, and transport layer protocols i.e., TCP/IP suite.
    • Common application layer protocols, HTTP/S, DNS, SSH, etc.
    • Active Directory and related authentication/authorization technologies.
    • Modern attack strategies rooted in social engineering and technological abuse primitives.
    • Utilizing and customizing a variety of C2 frameworks and offensive toolkits used to deliver Red Team Operations as well as network and application testing.
Preferred Experience

  • Programming experience in one or more of the following languages: Python, C, C++, C# Go, Rust, Nim, and JavaScript.


About the Organization NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance, so businesses can protect what matters most.

Leveraging a unique combination of dedicated security experts, intelligent process, and advanced technology, NetSPI helps security teams take a proactive approach to cybersecurity with more clarity, speed, and scale than ever before.

By continually advancing solutions such as Penetration Testing as a Service (PTaaS), Attack Surface Management (ASM), and Breach and Attack Simulation (BAS), NetSPI goes beyond the noise to deliver high impact results and recommendations based on business needs, so customers can protect their priorities, perform better, and innovate with confidence.

NetSPI secures the most trusted brands on Earth, including nine of the top 10 U.S. banks, four of the top five leading cloud providers, three of the five largest healthcare companies, four MAMAA companies, seven of the top 10 U.S. retailers & e-commerce companies, and many of the Fortune 500.

EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.
  • Seniority level

    Mid-Senior level
  • Employment type

    Full-time
  • Job function

    Information Technology
  • Industries

    Computer and Network Security

Referrals increase your chances of interviewing at NetSPI by 2x

See who you know

Get notified about new Principal Security Consultant jobs in United States.

Sign in to create job alert

Similar Searches

Looking for a job?

Visit the Career Advice Hub to see tips on interviewing and resume writing.

View Career Advice Hub