Senior Offensive Security Consultant (Cloud Pentester)
Soteria
Job Description
Established in 2014 and based in Charleston, South Carolina, Soteria's expertise in the cybersecurity domain is predicated upon the accumulated practical experience across all team members. Soteria's security professionals have held leading positions in private industries, state governments, and federal intelligence communities.
Driven by this combined pool of knowledge as well as the belief that “Security is for Everyone,” Soteria offers advisory services and solutions which are significantly differentiated from the security status quo. Soteria treats each client as a unique case deserving of individualized security insights and specialized hands-on assistance.
About the role
As a senior member of Soteria’s Offensive Security team, you will be focused on leading and performing red team assessments, penetration tests, vulnerability assessments in a variety of cloud-based environments. You will play a key role on the OffSec team as the cloud security assessment subject-matter expert, leading engagements and working with clients to help them identify and solve security challenges.
What you'll do
- As a senior member of Soteria’s Offensive Security team, you will be focused on leading and performing red team assessments, penetration tests, vulnerability assessments in a variety of cloud-based environments. You will play a key role on the OffSec team as the cloud security assessment subject-matter expert, leading engagements and working with clients to help them identify and solve security challenges.
- Perform cloud penetration testing, red teaming, application testing, and vulnerability assessments.
- Engage with prospective clients in pre-sales meetings and provide technical input for scoping engagements.
- Drive Soteria’s Offensive Security cloud offerings.
- Support the OffSec team as needed on traditional network penetration testing, web and mobile application security testing, source code reviews, vulnerability analysis, wireless network assessments, red team exercises, physical testing, and social engineering assessments.
- Communicate with prospective and existing clients to understand their cloud security needs, business requirements, and other motivating factors.
- Develop tailored tactical and strategic recommendations to address findings.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
- Effectively communicate findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel.
- Lead offensive security engagements through the entirety of project lifecycles, including kickoff, delivery, and closeout.
- Research and incorporate attacker tools, tactics, techniques, and procedures.
- Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements.
- Perform quality assurance peer reviews of Advisory and Offensive Security assessment reports and deliverables.
- Assist Soteria Leadership in the development of security standards and best practices for the organization and recommend security enhancements as needed.
- Manage relationships with client’s post-engagement as a trusted security partner.
- Maintain competence in security trends, technologies, and practices through self-study and participation in the security community.
- Collaborate with Soteria's Detection and Response Team (DART) to develop new capabilities for detecting bleeding edge offensive techniques.
- Coach and mentor offensive security team members.
- Provide continual improvement to offensive security team processes and documentation.
- Along with billable consulting, this role will require strong soft skills.
Qualifications
- 5-7 years of experience in at least three of the following:
- Previous experience working for internal or external customers in a consultant capacity
- Strong knowledge of tools used for network, cloud, web application, and wireless security testing.
- Thorough understanding of network protocols and data on the wire.
- Experience with automation of tasks using languages such as Powershell, Perl, Python, Ruby, etc.
- Ability to successfully interface with clients (internal and external).
- Ability to document and explain technical details in a concise, understandable manner.
- Ability to manage and balance time among multiple competing tasks.
- Mastery of *nix/Mac/Windows operating systems GUI and terminal.
- Practical cloud testing certifications like HackTricks Training AWS Red Team Expert (ARTE) are valued and considered a plus
Candidates must be legally authorized to work full time within the United States and able to pass a background check. Some candidates may require more extensive background checks based on the project. Soteria is an Equal Opportunity Employer. Soteria does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need.