Security Advisor Specialist, Offensive Security; Global Red Team
Job Description & How to Apply Below
About the Role
The Security Specialist, Offensive Security is responsible for testing the security controls, networks, and threat response for Intact Financial globally across all regions and affiliate companies. The specialist employs techniques, tactics, and protocols to evaluate security controls as part of a global offensive security team. The role reports to the Director of Offensive Security and collaborates with technical advisors in multiple locations and time zones.
WhatYou'll Do Here
- Conduct reconnaissance on network environments to build an external landscape using industry‑standard tools, threat intelligence feeds, OSINT and other readily available information sources.
- Perform offensive security testing to ensure security controls and response actions are effective, transitioning from a red team focus to a purple team approach when detected.
- Employ attack strategies to simulate real‑world attacks by threat actors and benchmark response capabilities across the enterprise.
- Identify and exploit vulnerabilities in computer systems, networks and applications to simulate attacks, demonstrating the ability to evade modern EDR solutions and achieve privilege escalation.
- Analyze and report on assessment results, providing recommendations to improve the security posture of the enterprise.
- Have in‑depth knowledge of the TCP/IP stack, exploit techniques, covert beacon creation, C2 channels, DNS exfiltration, and routing table exploitation such as BGP.
- Collaborate with regional cyber governance and risk teams to ensure findings are properly tracked for remediation.
- Generate metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness.
- Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark affiliate companies against peers.
- Consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development, establishing clear rules of engagement and ensuring compliance with the ROE.
- Maintain and update all offensive security tools, technologies and processes in line with the company rules of engagement.
- Provide timely and effective communication to key internal stakeholders in alignment with policy and rules of engagement.
- Advanced knowledge of computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, threat intelligence, incident response, technical writing, and information risk.
- Bachelor’s degree in Computer Technology or Information Security is an asset.
- Minimum of five years of relevant professional experience in information technology.
- Minimum of three years of experience in information security.
- Knowledge of offensive security operations, tools and techniques.
- Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001) is an asset.
- Proficient in Python scripting and history of using it in blue/red/purple team engagements.
- Proficiency in manual testing techniques beyond automated scanning.
- Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
- Ability to translate technical vulnerability information into actionable attack plans for critical assets.
- Ability to communicate highly technical data and results in business‑friendly language to non‑technical stakeholders.
- Experience with capture‑the‑flag competitions is desirable.
- Recognized certifications in information security (CEH, CISM, or equivalent) are an asset.
- Analytical mindset, pragmatic approach to IT security issues and problems.
- Strong partnership skills internally and externally to provide secure solutions.
- Ability to manage stress in high‑pressure and stressful situations.
- Positive attitude, initiative, strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.
- Strong written and oral communication skills to convey complex concepts and gain consensus.
- Ability to work in a dynamic environment with multiple objectives.
- Highly motivated, self‑directed, detail‑oriented.
- Capable of prioritizing and executing tasks in a high‑pressure…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×