Intact Financial Corporation

Security Advisor Specialist, Offensive Security (Global Red Team)

Intact Financial Corporation$118K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Technology or Information Security preferred.
  • 5+ years of experience in information technology.
  • 3+ years of experience specifically in information security.
  • Advanced knowledge of TCP/IP, DNS, BGP, and operational security platforms.
  • Proficiency in Python scripting and manual testing techniques.
  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Ability to communicate complex technical concepts to non-technical stakeholders.

Responsibilities

  • Conduct reconnaissance on network environments using standard tools and information sources.
  • Perform offensive security testing to evaluate security controls and response actions.
  • Simulate real-world attacks to assess response capabilities of the enterprise.
  • Identify and exploit vulnerabilities in systems and networks.
  • Analyze security assessment results and provide recommendations for improvement.
  • Collaborate with regional governance teams for proper tracking of findings.
  • Generate metrics and reports to support CISO in enterprise security effectiveness.

Benefits

  • Flexible work environment with hybrid options.
  • Collaboration with a global team across multiple locations and time zones.
  • Opportunity to leverage industry-standard and emerging tools.
  • Professional development opportunities in a cutting-edge field.
  • Engagement in meaningful work to strengthen security across the enterprise.
Full Job Description

About the role

The Security Specialist, Offensive Security is responsible for testing the security controls, the network, and threat response for Intact Financial globally (All regions and all affiliate companies). He/she works as a specialist employing techniques, tactics and protocols to test security controls, working as part of a global offensive security team.

The Specialist, Offensive Security reports to the Director, Offensive Security and works with a team of technical advisors across multiple locations and time zones.

If you can think outside of the Kali box, and love to think like an attacker (with a track record to prove your capabilities) we want to talk to you about joining our team!


What you'll do here:

  • Conduct reconnaissance on network environment to build external landscape using industry standard tools, threat intelligence feeds, OSINT and other readily available information sources

  • Conduct offensive security testing to ensure security controls and response actions are effective. If you are detected, shifting from a red team focus to a purple team approach – your purpose isn’t to create a “Gotcha!” moment – our mission is to strengthen our controls throughout the entire attack chain across the enterprise.

  • Employ attack strategies to simulate real-world attacks by threat actors and benchmark response capabilities across the enterprise.

  • Ability to identify and exploiting vulnerabilities in computer systems, networks and applications to simulate attacks by threat actors – you have a proven track record of evading modern EDR (eg. Crowdstrike, MDE, SentinelOne) while elevating privileges/hitting your target.

  • Analyze and report on the results of security assessments and make recommendations to improve the security posture of the enterprise.

  • You understand the TCP/IP stack in depth and know how to exploit it to create covert beacons, C2 channels, exfiltrate data across DNS. Understanding how routing tables work (eg. BGP) and how they can be exploited is an asset.

  • Work with regional cyber governance and risk teams to ensure that findings are properly tracked for remediation

  • Generate the required metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness

  • Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark regions and affiliate companies to peers.

  • Able to consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development, proposing clear rules of engagement for testing activities (either one time or perpetual) and ensuring compliance to the ROE through all phases of testing.

  • Maintain and update all offensive security tools, technologies and processes in line with company rules of engagement

  • Provide timely and effective communications to key internal stakeholders in alignment with policy and rules of engagement.


What you bring to the table:

  • Advanced knowledge in the following areas: computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, Threat intelligence, Incident Response, technical writing, information risk.

  • Bachelor's degree in Computer Technology, Information Security, an asset.

  • A minimum of five (5) years of relevant professional experience in information technology.

  • A minimum of three (3) years of experience in information security.

  • Knowledge of offensive security operations, tools and techniques.

  • Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001), an asset.

  • Python scripting comes naturally, and have a history of using it in blue/red/purple team engagements

  • Proficiency in manual testing techniques beyond automated scanning.

  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.

  • You can take many vectors of technical vulnerability information (Pentest reports, vulnerability scanning data, SAST/DAST reports) and build an attack plan on critical assets.

  • You must have the ability to take highly technical data and results and translate them to business-friendly language to help non-technical stakeholders understand the approach, impact and outcome from offensive security operations.

  • If you’ve joined capture the flag competitions (even better if you won) we want to hear about it!

  • Recognized certification in information security (CEH, CISM or other), an asset.

  • Analytical mind, pragmatic approach to IT security issues and problems.

  • Strong partner in all areas, internally and externally, to provide a secure solution.

  • Ability to reduce stress in situations that are stressful to you and others.

  • Positive attitude, initiative with strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.

  • Ability to write and present material to communicate difficult concepts and gain consensus.

  • Ability to work in a dynamic environment with multiple objectives.

  • Highly motivated and self-directed, with attention to detail.

  • Ability to prioritize and execute tasks in a high-pressure environment.

  • Ability to deal diplomatically and effectively at all levels of the organization.

  • Ability to challenge the status quo.

  • Customer focused approach.

  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country. 

  • No Canadian work experience required however must be eligible to work in Canada.

#LI-Hybrid

Ce poste jouera un rôle essentiel au sein de notre équipe. | This position will fill an essential role in our team.

About Intact Financial Corporation

Intact Financial Corporation is a Canadian insurance company that provides property and casualty insurance to individuals and businesses. The company operates in Canada and the United States and offers a range of insurance products, including auto, home, and commercial insurance. Intact Financial Corporation was founded in 1809 and is headquartered in Toronto, Canada.
Learn more about Intact Financial Corporation
Size
16,000 employees
Industry

Similar Jobs

More Jobs at Intact Financial Corporation

More Information Technology Jobs

Find similar Security Advisor Specialist, Offensive Security (Global Red Team) jobs: