Lead Offensive Security Engineer
Early Warning
•
Phoenix – Mesa – Scottsdale, AZ
Company
Early Warning
Location
Phoenix – Mesa – Scottsdale, AZ
Type
Full Time
Job Description
Come build the next-gen fintech at Early Warning, network operator of Zelle®, where we're relentlessly focused on empowering prosperity in all its forms.
From fast money movement for over 100 million people who can access Zelle® directly through their banking app to new account opening and beyond - we make a difference in the lives of consumers and businesses every day and enable them to live their best financial lives. And we're only getting started.
With new state-of the-art offices in Scottsdale, AZ (Headquarters) and Chicago, IL - plus a growing presence in San Francisco - we're entering our next big chapter. We focus all hiring efforts in a few states and within driving distance of an office location to enable in-person collaboration when and where possible. Priority hiring locations are Scottsdale, AZ, Illinois, NY tri-state metro area (New Jersey, New York and Connecticut) and San Francisco, CA. On exception we will hire in secondary locations such as District of Columbia, Florida, Georgia, Maryland, Nevada, North Carolina, South Carolina, Texas and Virginia. We are not actively recruiting in Colorado, Rhode Island or Washington.
People matter to us, so we think our best work is done when we're together, in-person. From informal interactions, to sharing ideas, to mentoring and beyond. We also believe in workplace flexibility and empowering teams to determine the rhythm of work to create an inclusive culture. Through the power of innovative collaboration, we offer hybrid and (when necessary) virtual ("remote") workplace models.
Join us and make your mark on what's next in fintech.
*Applicants must be authorized to work for any employer in the United States. We are unable to sponsor an employment Visa for this position.
Overall Purpose
The Lead Offensive Security Engineer position within the Offensive Security team is responsible for identifying and documenting security vulnerabilities through approved penetration testing activities for the purpose of securing Early Warning's systems, infrastructure, and applications. Additional responsibilities include mentoring junior offensive security engineers, triaging bug bounty submissions, control validation, threat model consultation, emerging threat PoC exploitation, and password cracking and phishing campaigns.
Essential Functions
- Leads internal and external penetration tests focused on web applications, web services, wireless, cloud platforms, and network technologies.
- Leads cloud penetration testing engagements to assess specific services and implementations (i.e. AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weakness.
- Mentor other team members in offensive security testing techniques and approaches.
- Contribute to team strategy, direction, and process development.
- Work with Security and Technology partners to scope engagements by clearly articulating penetration testing approach and methodology to technical and non-technical audiences.
- Report generation that clearly communicates testing and assessment details, results, and remediation recommendations to internal teams.
- Occasionally supports 3rd party PTaaS vendor penetration tests by provisioning Kali Linux VMs and AMIs within the environment.
- Facilitates ticket creation for tracking remediation of vulnerabilities and issues found during penetration tests.
- Work with external third parties and researchers through Bug Bounty and Responsible Disclosure programs to reproduce submissions, assess organizational risk impact (CVSS, CWE, Enterprise Risk Ranking Impact/Likelihood), and further investigate reported issues.
- Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements.
- Performs ad hoc security control testing as needed, including remediation testing of previous penetration test findings.
- Leads and enhances monthly security campaign audits for phishing, password reuse, and password complexity.
- Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
- The above job description is not intended to be an all-inclusive list of duties and standards of the position. Qualified candidates will follow instructions and perform other related duties as assigned by their supervisor.
Minimum Qualifications
- Bachelor's degree in Computer Science, Computer Information Systems, Information Security, Engineering, Math, or related field or equivalent years of professional experience to meet job requirements and expectations.
- 6+ years of professional experience with risk assessment tools, technologies, and methods focused on Information Assurance, Information Systems/Network Security, Infrastructure Design, or Vulnerability Assessments.
- Advanced knowledge of tools and techniques used to conduct network, wireless, or web application penetration testing.
- Advanced application penetration testing and source code review experience.
- Knowledge of open security testing standards and projects, including OWASP, PCI, & MITRE ATT&CK.
- Experience with scripting, editing existing code, and programming (e.g., Python, Bash, Powershell, Golang, .NET, Java, etc.)
- Proven ability to use, configure, troubleshoot, and administer *nix, Mac OSX, and Windows operating systems.
- Experience with vulnerability scanners and Kali Linux associated toolsets included but not limited to InsightVM, Burp Suite Pro/Enterprise, hashcat, nmap, and/or Bloodhound.
- Knowledge of application, database, and web server secure design and implementation.
- Knowledge of network, web, and cloud application security testing. Red teaming or security operations experience is a plus.
- Strong and professional communication skills (written and verbal).
- Ability to present findings and recommendations to technical and non-technical audiences.
- Background and drug screen
Preferred Qualifications
- Hands-on practical Offensive Cybersecurity certifications (Sec+, OSCP, OSWE, eJPT, Pentest+, eCPPT, eWPT, GIAC, etc.) or equivalent.
- Cloud certifications (CCP, SAA, SAP, AWS Security Specialty, etc.) or equivalent.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
Candidates responding to this posting must independently possess the eligibility to work in the United States at the date of hire.
Some of the Ways We Prioritize Your Health and Happiness
• Healthcare Coverage - Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
• 401(k) Retirement Plan - Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
• Paid Time Off - Unlimited Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
• 12 weeks of Paid Parental Leave
• Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!
Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
Date Posted
04/30/2023
Views
12
Neutral
Subjectivity Score: 0.7
Similar Jobs
Spine Programmatic Leader, Neurosurgery, Phoenix, Arizona, West Valley - Barrow Brain & Spine
Views in the last 30 days - 0
View Details