Job Summary:
As a Red Team Analyst, you will support Red Team engagements and proactively uncover security risks, equipping the Global Fusion Center (GFC), and Tokio Marine Group Companies with advanced offensive capabilities to remediate cyber risks. You will rapidly grow to understand the Group Companies’ business priorities and create ways Red Team engagements can help to uncover and mitigate their cyber risks.
You will assist with adversary simulation activities, security research, engagement infrastructure, and the development of offensive security tools and techniques to further the Red Team’s capabilities.
Essential Job Functions:
- Assist with Red Team engagements throughout the engagement lifecycle, including planning, scoping, execution, documentation, cleanup, and reporting
- Conduct hands-on adversary simulation and offensive security testing under the guidance of experienced Red Team members
- Assist in developing tools, methodologies, and infrastructure to support Red Team engagements
- Deliver well-written technical and executive-level Red Team reports and briefings
- Align with counterparts globally to build and enforce standards and frameworks pertaining to Red Team engagements and findings
Qualifications:
- 1-3 years Red Team (Adversary Simulation), Penetration Testing, or similar experience in a technical role
- Exposure to Tokio Marine systems and policies preferred
- Foundational knowledge of Red Team engagement concepts, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, credential access, and command and control
- Experience conducting hands-on technical Red Team and/or government computer network exploitation/attack operations experience, including (but not limited to) familiarity with using, modifying, and customizing red teaming post exploitation frameworks and Command & Control (C2) frameworks
- Ability to use scripting or programming languages such as Bash, PowerShell, Python, C#, or similar languages to automate tasks and support offensive security tooling
- Experience in software development, including red teaming tools, custom malware, trojans, shellcode, etc., using low-level languages (C, C++, assembly, etc.)
- Working knowledge of Windows & Linux internals, system calls, and other operating systems internals and how to leverage them for offensive security purposes
- Experience in professionally delivering technical and executive-level red team reports and briefings
- Knowledge of common bugs or misconfigurations in software and cloud infrastructure (AWS, GCP, and Azure). Industry security certification (GPEN, GXPN, OSCE, OSCP, OSEP, CRTO) preferred.
- Fluency in a foreign language is highly desirable, but not required
Salary range$95,000 to $105,000. Ultimate salary offered will be based on factors such as applicant experience and geographic location. Our company offers a competitive benefits package and bonus eligibility on top of base.