FREE ACCESS
5,000–10,000 jobs/day

See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Principal, Technology Risk & Information Security – Red Team
Northern Trust. Executing objective-driven, threat intelligence–informed Red Team operations using adversary-appropriate attack techniques, including social engineering.
Tech Stack
Tools & technologiesCyber SecurityPythonVoIP
About the role
Key responsibilities & impact- Executing objective-driven, threat intelligence–informed Red Team operations using adversary-appropriate attack techniques, including social engineering.
- Conducting threat intelligence gathering, research, development, and execution of offensive attack techniques in support of Red Team operations.
- Performing technical testing and examinations across application, infrastructure, and enterprise environments.
- Reviewing, documenting, and reporting Red Team findings; including risk implications and recommended remediation actions.
- Supporting validation and closure of Red Team findings in collaboration with control owners and stakeholders.
- Supporting and maintaining Red Team infrastructure and develop automation through DevOps approaches.
- Researching and developing offensive security tools, scripts, and frameworks to enhance testing capabilities.
- Planning, scheduling, and supporting delivery of Red Team engagements, including milestones and reporting.
- Producing meaningful metrics and reporting related to Red Team activities and authored programs.
- Remaining informed on trends in the security industry, emerging technologies, threat actors, and attack techniques, and advise stakeholders on their relevance and impact.
- Executing responsibilities in accordance with applicable industry regulations, standards, and compliance requirements.
- Participating in cyber security incident response as required.
Requirements
What you’ll need- Experience utilising ethical hacking techniques such as social engineering, physical security or customized scanning / scripts / tools is required.
- Knowledge of Red Team and penetration testing methodologies within enterprise environments.
- Knowledge and skill with common offensive security tooling (e.g., Cobalt Strike, Burp Suite, mimikatz, Rubeus).
- Proficiency in performing application security assessments (including source code review, vulnerability scans, web service testing, use of disassemblers/decompilers/debuggers, reverse engineering, binary analysis and disk / memory forensics).
- AV/EDR evasion techniques for well-defended environments.
- Experience with maintaining infrastructure to support testing and developing network level penetration testing measures (including wireless assessments, VoIP security, war dialing, remote pre-texting and use of network analysis tools / vulnerability scanners).
- Prior experience in a security consulting role.
- Prior experience scoping engagements and developing technical proposals.
- Demonstrated ability to work well in an individual contributor and team capacity, in particular multi-national teams.
- Proven ability to effectively manage projects and complete multiple tasks simultaneously and efficiently while maintaining a sense of urgency and attention to detail.
- Possess excellent written and verbal communication skills.
- Able to prepare clearly written, organized documents, reports and communications that demonstrate proper justification and support for any conclusions and assessment results and contain correct grammar, punctuation and spelling.
- Risk management principles and information security disciplines such as security engineering, architecture, and defensive capabilities.
- Able to interact in a professional manner and develop relationships with individuals and teams at any level in Northern Trust or third party service provider.
- Current relevant offensive security certifications with a practical testing element (e.g., OSCP, OSCE, CRTO, CRTP, CRTE) is beneficial.
- Bachelor’s degree in Information Technology, Management Information Systems, Computer Science or a related discipline, or equivalent practical experience.
- Experience developing or modifying offensive security tools using scripting languages such as Python or Bash.
- Financial Services experience a plus.
Benefits
Comp & perks- Reasonable accommodation for individuals with disabilities
- Flexible and collaborative work culture
ATS Keywords
✓ Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
ethical hackingsocial engineeringpenetration testingapplication security assessmentsvulnerability scansreverse engineeringbinary analysisdisk forensicsmemory forensicsoffensive security tooling
Soft Skills
project managementattention to detailwritten communicationverbal communicationteam collaborationrelationship buildingorganizational skillsmulti-taskingsense of urgencyindividual contributor
Certifications
OSCPOSCECRTOCRTPCRTE