Red Team Associate Operator / Penetration Tester

Federal Reserve SystemPrior Lake, IL
1d$92,600 - $127,400

About The Position

Our National Incident Response Team (NIRT), a national service provider for the Federal Reserve System (FRS), delivers effective and efficient national intrusion detection, incident response, security intelligence, threat assessment, and vulnerability assessment services for the FRS. NIRT’s mission is to play a leading role in the FRS’ efforts to protect its information systems against unauthorized use. NIRT’s Adversary Emulation team has an immediate opening for an Associate Operator to join their team as a key participant on a variety of engagements and projects that will target and evaluate the cyber security posture of people, processes, and technology within the FRS. As an Associate Operator, you will report to the Sr. Manager and work on a team of security professionals focused on enabling business line initiatives by performing security assessments against people, processes, and technologies by using automated tools and expertise of hands-on tools that simulate attacker tactics, techniques and procedures (TTPs). You will also perform assessments for new and existing services, infrastructure, and applications to identify weaknesses before an attacker does. You will use a variety of tools and techniques including penetration testing, red teaming, purple teaming, and social engineering and have the opportunity to combine your technical expertise with your imagination to discover innovative methods for ensuring that the FRS remains one step ahead of its adversaries around the world.

Requirements

  • 1-3 years of relevant information security related work experience in areas such as: computer network defense, computer network exploitation and post-exploitation
  • Bachelor’s degree or equivalent work experience
  • Understanding of adversary emulation operations including web application testing, network penetration testing, reconnaissance, social engineering, exploitation and post-exploitation, covert techniques, lateral movement, and data exfiltration
  • Knowledgeable in offensive cybersecurity roles, such as malware development, red teaming, penetration testing (e.g., web, infrastructure, cloud), purple team exercises in cloud and on-prem environments
  • Team player with interpersonal, collaborative and consultative skills
  • Adept attention to detail, oral and written communications skills tailored to audiences ranging from technical subject matter expert partners to senior executive stakeholders
  • Understanding client relationships, including determining needs, learning expectations, and demonstrating commitment to delivering quality results
  • Familiar with scripting/programming of Python, PowerShell, or C# with the ability to create and customize tools

Nice To Haves

  • The following certifications are highly preferred: GWAPT, GPEN, OSCP, CRTO

Responsibilities

  • Strengthen FRS security posture through offensive security assessments where you will perform complex security assessments including the identification and exploitation of vulnerabilities across the system
  • Leverage offensive security foundational knowledge to support in the execution of cybersecurity solutions to benefit security engagements and mitigate cyber threats
  • Improve operational efficiency by building and evaluating workflow processes, procedures, checklists, automation, and tooling
  • Enable success of security initiatives by performing tasks to development surrounding security or technology capabilities and creating operations-based documentation
  • Address cybersecurity needs by advising clients on best practices and how to implement changes to securely address complex business needs
  • Execute on cross-team initiatives to implement cybersecurity improvements for recognized gaps
  • Grow security capabilities to defend the FRS by working with internal and external stakeholders to execute on strategies and plans to enforce security requirements
  • Identify and prioritize key risk areas balancing business risk and cyber threats via research of industry trends and business partner missions
  • Assist and execute technical security assessments to identify risk, likelihood and impact an attacker may have on the System due to weak or missing controls
  • Perform cybersecurity and Associate Operator duties as assigned

Benefits

  • Great medical benefits
  • Pension and 401(k) with employer match
  • Paid time off
  • Tuition reimbursement
  • Paid volunteer leave
  • Onsite amenities that make working here fun!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service