Description:
The Red Team Consultant will perform dedicated Red Team activities simulating known threat actors, to help CrowdStrike customers determine the impact and likelihood of threat actors to accomplish objectives across the Kill Chain and MITRE ATT&CK Framework. The Red Team Consultant is expected to be able to coordinate with senior leadership, plan, execute assessments and assist the other CrowdStrike Services’ functions to help improve customers' security defense.
What You’ll Do
- Perform penetration assessments of operating systems, applications, databases and network infrastructure components to detect, enumerate threats.
- Produce high-quality written and verbal reports, presentations, security-focused recommendations, and factual findings of results of Red Team activities to customer management.
- Must be able to effectively communicate at all levels (executive leadership and technical support teams) within CrowdStrike.
- Be a team player and lead/assist in developing and improving an information security program and information security resources.
- Provide guidance using specialized knowledge and toolsets to operational teams during enterprise wide crisis scenarios, e.g. large-scale production service outages, outside of the routine change management process.
- Must be able to work as an technical operator on various types of penetration testing offerings with an OPSEC mindset.
What You’ll Need
- Minimum 3 years of experience in a Red Team/Penetration Testing activities is highly preferred.
- Security community participation (conference speaker, tool development contributor etc.) is highly preferred.
- Advanced experience with security assessment tools (Metasploit, NMAP, Cobalt Strike, Nessus, Burp Suite, etc.).
- Comprehensive understanding of the security methodologies, technologies, and best practices.
- Windows / Linux / UNIX / Mac operating systems.
- Advanced experience with Networking components (routers, switches, load balancers, wireless access points, etc.).
- Comprehensive knowledge of firewalls, proxies, mail servers and web servers.
- Advanced experience with operational support for operating systems, applications and networks.
- Advanced experience with Red Teaming (vulnerability/penetration testing/adversary emulation assessments).
- Advanced experience in automation and scripting of applications and systems.
- Desirable Certifications: OSCP, GPEN, OSCE, GCIH, GXPN.