Your role and responsibilities
Passionate about breaking into applications, networks, systems, databases, devices and other technologies to uncover security vulnerabilities and help fix them? Are you interested in joining a team of like-minded passionate experts, many of whom have decades of experience breaking into anything and everything to help organizations strengthen their security? If so, X-Force Red, IBM Security's team of veteran hackers, is looking for a Global Security Consultant, and you may be the perfect fit.
The Global Security Consultant will be part of the X-Force Red Offensive Security team. The consultant's primary duty is to perform penetration tests against clients' applications including web, mobile and thick-client.
Engagements typically range from two to four weeks. Secondary duties include assisting in the sales process with potential or existing clients, and acting as a client's primary technical contact for projects delivered by other consultants. X-Force Red consultants provide subject matter expertise in the form of research, tooling, and consulting engagements.
You should have in-depth of knowledge and experience in testing modern enterprise applications across a variety of frameworks and platforms. Identifying vulnerabilities in these applications and exploiting them to gain access to sensitive data or systems.
The consultant must be able to rapidly learn new technologies and processes with minimal assistance. There is a potential for 20% travel, including international travel. Travel depends on project requirements.
Current active clearance level or ability to obtain one is beneficial.
Required education
High School Diploma/GED
Preferred education
Bachelor's Degree
Required technical and professional expertise
Technical / Professional Experience:
• 10+ years of penetration testing experience
• 10+ years of consulting experience
• Ability to perform penetration tests against web applications plus at least one of the following: internal networks, wireless networks, mobile applications, thick-client applications, embedded applications, hardware
• Programming experience in one or more of the following: Java, .Net, Python, or Ruby
• Strong understanding of networks, firewalls, protocols, routing, and security technologies
• History of presenting at regional or major security conferences
• History of published research, blog posts, or other publications
• Experience coordinating security testing projects with multiple consultants
Consulting Qualifications:
• Effective communication and presentation skills
• The ability to lead large groups and be a primary facilitator
• Demonstrated written skills
• Drive to do research, publications, blogs, presentations, etc.
• Comfortable working in a project based / client serving model
• Ability to lead and shape client expectations
• Help drive pursuits and engage in complex deals, matching outcomes to expectations
• Ability to work easily with diverse and dynamic teams
• Ability to self-start, and work independently on projects
Preferred technical and professional experience
• Experience testing GenAI applications and LLM models
• Experience with testing SaaS platforms and applications - SAP, Salesforce, Oracle
• OSCP, OSEP, OSWE, OSED, OSEE, Burp Suite Certified Practitioner, or other technical certifications
• Experience in reverse engineering software or hardware
OTHER RELEVANT JOB DETAILS
Must have the ability to work in Canada without sponsorship. For additional information about location requirements, please discuss with the recruiter following submission of your application.
The salary range for the position is based on a full-time schedule. Your ultimate salary within this range may vary depending on your job-related skills and experience for this position.