Senior Consultant, Red Team, Google Cloud, Mandiant Consulting
About the Job
The mission of the team is to scope, plan, and execute offensive security assessments for Google Cloud and Mandiant customers.
Mandiant's Red Team delivers offensive security engagements. This may involve delivering a Red Team for a large enterprise, breaching external perimeter through application compromise, preparing command and control infrastructure, developing social engineering campaigns and the associated collateral, executing phishing campaigns and attempting to compromise internet-facing systems, conducting privilege escalation and lateral movement within customer networks, hunting for objectives with little-to-no information provided by the customer and exfiltrating data from the network all while avoiding detection from the customer security operations teams.
To always operate in the true hacker spirit - be curious, learn, tinker and evolve.
Responsibilities
- Perform Red and Purple Team assessments, including end-to-end adversarial emulation of cyber attacks against customer organizations, and other technical cyber assessments including external penetration, web application, mobile and wireless security testing.
- Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders.
- Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.
Qualifications
Minimum qualifications:
- Bachelor's degree in cybersecurity, with a focus on offensive security or equivalent practical experience.
- 5 years of experience in three of the following security areas: application security, red team assessments, endpoint detection and response (EDR) evasion, exploit development, cloud, social engineering, scripting, tool development.
- Experience delivering reporting and presentations to both technical and executive audiences.
- Experience with operating system security across operating systems or Linux.
Preferred qualifications:
- Certifications related to offensive security including OSCE, OSEP, OSEE, OSCP, CCSAS, CCT INF or relevant SANS courses.
- Experience in four or more of the following: network protocols, threat intelligence analysis, system and network administration, project management, developing applications, technical incident response processes, source code review, reverse engineering.
- Experience in finding 0-day vulnerabilities in web or mobile applications.
- Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar).
- Experience in performing application source code review.
- Experience in payload development, lateral movement, privilege escalation and EDR evasion.
Summary
Conduct offensive security assessments, develop tools, and advise clients on cybersecurity defenses.
Job title
Senior Consultant, Red Team, Google Cloud, Mandiant Consulting
Experience level
5+ years
Minimum experience
5+ years exp
Industry
cybersecurity
Location requirements
Dubai, Riyadh, Doha; remote work allowed
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Dubai - United Arab Emirates
Riyadh Saudi Arabia
Doha, Qatar