
Attack Simulation Engineer – Threat & Attack Simulation
GuidePoint Security
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Tech Stack
About the role
- Deliver CSV services, including, but not limited to Continual and Coordinated penetration testing, Automated Assessments, Hybrid Assessments, Automated Remote Social Engineering Assessments, and Breach & Attack Simulation Assessments
- Assist with technical oversight/quality assurance of CSV assessments as needed
- Author comprehensive assessment deliverables that are proficiently tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies
- Contribute to marketing initiatives via activities such as publishing research, speaking at industry conferences, authoring blog articles and whitepapers, hosting webinars, and developing security tools
- Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry
- Assist in the pre-sales process for both the services and the tools we support, attending and performing demos as required
- Foster strong client relationships and represent GuidePoint well by providing interactive and collaborative support, information, and guidance to ensure delivery of maximum value
- Serve as a Subject Matter Expert over one of the Practice’s main offering areas (Remote Social Engineering, Automated Penetration Testing, or Breach & Attack Simulation), including maintaining vendor certifications as they are available
- Serve as an escalation point for abnormal findings, properly triage, and escalate as needed
- Maintain situational awareness of the client's technology architecture, known weaknesses, solutions used for monitoring and threat intelligence, and any recent security events
- Ensure that identified vulnerabilities are promptly validated and thoroughly investigated
- Devise and document new procedures and runbooks/playbooks as directed
- Maintain established Service Level Agreements (SLAs)
- Attend GuidePoint GPSEC conferences as necessary to meet with account executives and clients regarding our services
Requirements
- Familiarity with offensive security tools used for network, host and application security testing
- Experience in security technologies such as automated penetration testing tools, Breach & Attack Simulation Tools, Security Information and Event Management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint Detection and Response (EDR), Anti-Virus, Sandboxing, network- and host-based firewalls, Threat Intelligence, Virtual Machines, etc.
- Advanced knowledge of at least one security tool from within the following domains: Automated Penetration Testing and Breach & Attack Simulation (i.e. Horizon3, Pentera, SafeBreach, Picus, etc…)
- Experienced in client delivery for high-profile clients (i.e. Fortune 100) with utmost professionalism
- Pentest+ Certification or equivalent, and in pursuit of OSCP (or other lab-based certification)
- Internal security operations experience is strongly preferred
- InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience is strongly preferred
- Minimum of two (2) years of experience in security operations
- Minimum of one (1) year of experience in performing continual and coordinated penetration testing
- Minimum of four (4) years working in an IT or IT Security environment
Benefits
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
penetration testingautomated assessmentshybrid assessmentssocial engineering assessmentsbreach and attack simulationvulnerability validationsecurity operationsincident responseprocedure documentationthreat intelligence
Soft Skills
client relationship managementtechnical oversightquality assurancecommunicationcollaborationmarketing initiativespublic speakingresearch publishingproblem-solvingescalation management
Certifications
Pentest+ CertificationOSCPvendor certifications