Full-Time Cybersecurity Analyst - Sr. Consultant - Red Team
Visa is hiring a remote Full-Time Cybersecurity Analyst - Sr. Consultant - Red Team. The career level for this job opening is Expert and is accepting Ashburn, VA based applicants remotely. Read complete job description before applying.
Visa
Job Title
Posted
Career Level
Career Level
Locations Accepted
Salary
Share
Job Details
Visa's Red Team proactively identifies weaknesses in Visa's security posture and recommends necessary controls and procedures to cost-effectively protect Visa services from intentional or inadvertent modification, disclosure or destruction. With this mission in mind, Visa's internal Red Team experts are engaged in covert operations that simulate adversarial threats and attacks in a timely manner. This is accomplished by performing internal and external ethical hacks of Visa applications and systems.
Red members also help with design, development, and recommendation of security solutions to protect Visa proprietary/confidential data and systems. Assist with compliance objective. Provide guidance and direction for the logical protection of information systems assets to other functional units. Prepare reports regarding effectiveness of information security adherence and make recommendations for the adoption of new policies and procedures for Visa services. As a member of Visa's Red team, provide technical expertise required to carry out internal and external ethical hacking exercises. Coordinate with other departments and teams to evolve information security alignment with company goals and objectives.
Contribute and participate in all stages of a Red Team exercise including planning, reconnaissance, exploitation, post-exploitation, clean up, and remediation. Champion security research activities and teamwork required to carry out successful Red Team operations. Create and provide presentations to executive management highlighting outcomes of Red Team exercise and recommendations and timelines for remediation.
Essential Functions:
- Conduct high risk and sensitive ethical hacks of internally and externally hosted applications globally according to scope defined by Red Team.
- Co-ordinate and execute system/network level advanced Red Team and ethical hacking exercises.
- Design and develop scripts, frameworks, and tools required for facilitating and executing complex undetectable attacks.
- Reviews results of network and application ethical hacks to determine severity of findings and to ensure proper remedies are applied.
- Performs penetration and remediation testing and reporting through the application of expert ethical hacking and penetration techniques in a fast-paced, highly technical environment.
- Identify network and system vulnerabilities and provide recommended counter measures or mitigating controls to reduce risk to an acceptable and manageable level.
- Provide accurate and timely reporting of findings and proposed remediation and mitigations.
- Coordinate Red team operational briefings and presentations to non-technical audience and executive management, as required.
- Provide technical support to Business Leader in identifying and streamlining new/existing protocols and tools used by the Red Team.
- Define and develop agenda for training and educating security professionals on advanced exploits, tools, and frameworks
- Perform research of emerging technologies and design frameworks and capabilities required to perform Red Team exercises of new technologies adopted by Visa.
Basic Qualifications:
- 8+ years of relevant work experience with a Bachelor’s Degree or at least 5 years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 2 years of work experience with a PhD, OR 11+ years of relevant work experience.
Preferred Qualifications:
- Expertise performing advanced exploitation and post-exploitation attacks as part of ethical hacking exercises.
- Prior experience or expertise performing Red Team exercises.
- Experience in writing proof-of-concept exploits and creating custom payloads and modules for common ethical hacking frameworks and tools.