Senior Adaptive Threat Replication Engineer

Bank of AmericaWashington, DC
147d

About The Position

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being. Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization. Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us! The Cyber Security Assurance Division is looking for a Senior Adaptive Threat Replication Engineer to join a team of world-class offensive security professionals. In this role you will diligently hunt for hi-risk vulnerabilities across the bank's global technology environment. Understanding security policy and compliance is important but in this role your focus is to identify exploitable vulnerabilities; ones that can bring about that "nightmare scenario." This is a highly technical role that requires broad technical knowledge and a deep understanding of threats and threat TTPs. You will lead and participate in advanced technical assessments that leverage red team, penetration testing, and vulnerability assessment tools and techniques to identify hi-risk vulnerabilities across a variety of technologies. You will coordinate with senior leadership on development projects, share your knowledge and experience by mentoring junior engineers, and assist the monitoring and response functions so those functions can practice and improve their capability to respond and recover against a realistic threat actor.

Requirements

  • 5+ years of professional offensive security experience.
  • Ability to critically examine an organization and system from a threat actor's perspective.
  • Proficiency with tools associated with red teaming, penetration testing, and vulnerability assessments (Metasploit, Burp Suite, Cobalt Strike, Kali, etc.).
  • Solid understanding of voice and data networks, major operating systems, active directory, and associated peripherals.
  • Knowledge of tactics, techniques, and procedures associated with malicious insider activity, organized crime/fraud groups, and state and non-state sponsored threat actors.
  • Ability to effectively code in a scripting language (Python, Perl, etc.).
  • Strong advisory and innovative thinking skills.
  • Technical documentation and technology system assessment skills.
  • Threat analysis capabilities.

Nice To Haves

  • Certifications: OSCP, GPEN, GXPN, OSCE, GWAPT.
  • Ability to work remotely if/when necessary.
  • Previous experience working in the financial industry.
  • Typically has 5-10 years of experience in technology and offensive security assessments.

Responsibilities

  • Lead and perform assessments of the bank's technologies, applications, and cyber security controls.
  • Adapt testing methods to evolving and emerging threats.
  • Conduct research and understand the bank's security policy.
  • Work with appropriate partners to complete assessments and simulations.
  • Identify misconfigurations and vulnerabilities and report on associated risk.
  • Mentor junior engineers and share knowledge and experience.
  • Coordinate with senior leadership on development projects.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Industry

Credit Intermediation and Related Activities

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service