Senior Defensive Security Consultant

27 Minutes ago • All levels • $145,000 PA - $170,000 PA

Job Summary

Job Description

SpecterOps is seeking senior defensive security consultants to join their Consulting Services team. Responsibilities include acting as analysts, detection engineers, and program developers, providing strategic advisory to enhance customer detection capabilities. This involves conducting independent assessments to gauge detection program maturity, proactively identifying threats, and developing course content for training offerings. The ideal candidate will possess strong technical and soft skills, be well-organized, and self-directed. The role involves creating evasion-resilient detections, evaluating and improving client detection content, assessing security operations functions, utilizing security tools like EDR and SIEM, and guiding telemetry sources. Consultants will build tools to enhance investigations, serve as subject matter experts, communicate effectively with team members and clients, and develop reports for technical and executive audiences. Senior Consultants are responsible for the entire lifecycle of significant projects and may lead small teams.
Must have:
  • Create evasion-resilient detections
  • Evaluate existing detection content
  • Assess security operations maturity
  • Utilize EDR, SIEM, and live response tools
  • Guide telemetry sources (EDR, Sysmon, etc.)
  • Build scripts/tools for investigations
  • Serve as SME in detection engineering/forensics/malware
  • Communicate effectively with team and clients
  • Develop reports and presentations
  • Mentor less experienced staff
  • Contribute to training content
  • Ability to travel up to 25%
  • Pass a criminal background check
Good to have:
  • Foundational knowledge of defensive security
  • Knowledge of security principles and best practices
  • Working knowledge of Windows/NIX OS
  • Working knowledge of networking
  • Working knowledge of Active Directory
  • Working knowledge of programming/scripting languages
  • Aptitude for technical writing
  • Strong written/verbal communication
  • Determination to improve security community
  • Support delivery of training
  • Foundational knowledge of offensive security
  • Knowledge of regulatory requirements
  • Knowledge of attacker techniques/tools
  • Proficient with Windows/NIX OS and controls
  • Proficient with networking and controls
  • Proficient with Active Directory and controls
  • Proficient with defensive security concepts
  • Lead small to medium services/projects
  • Communicate with customers and management
  • Contribute to defensive service offerings
  • Strong analytical skills
  • Expert in service lines/technical areas
  • Lead and execute defensive service offerings
  • Experience leading small teams
  • Experience managing multiple projects
  • Experience communicating with clients
  • Experience managing client projects
  • Develop and deliver training as lead instructor
  • Mentor and train consultants
  • Bachelor's degree in a technical field
  • Experience with Fortune 1000/Federal security assessments
  • Public community contributions
  • Experience administering/attacking/defending Windows/Linux/macOS
  • Experience in a SOC environment
  • Experience in technical writing
  • Experience in malware analysis/reverse engineering
  • Experience executing offensive techniques
  • Experience documenting detections
  • Experience developing/providing technical training
  • Desire to teach defensive techniques
  • Desire to travel internationally/domestically >50%
Perks:
  • Health, Dental, Vision, Life Insurance (100% covered for employee and family)
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Stock Options & bonuses
  • Remote work: $1,500 new hire allowance for home office setup
  • $500 annual home office allowance
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual lifestyle, wellness, pet insurance allowance
  • $10,000 one-time benefit towards family planning
  • In-person and virtual employee events
  • Company swag

Job Details

 

SpecterOps is looking for senior defensive security consultants to serve on the Consulting Services team as analysts, detection engineers, and program developers. The SpecterOps Adversary Detection service line provides strategic advisory positions to mature our customer’s internal detection capabilities. They often perform independent assessments to determine the overall state of a customer's detection program or to proactively identify adversaries operating silently in a customer’s environment. Additionally, our consultants frequently support SpecterOps training offerings by developing course content and delivering training during public and private events.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.  

  • Associate Consultant - $100,000 - $125,000
  • Consultant - $125,000 - $145,000
  • Senior Consultant - $145,000 - $170,000

Location: This position is remote, based in the U.S. with optional travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Create evasion-resilient detections based on independent research alongside supporting resources, documentation, and automation
  • Evaluate existing detection content in client environments and make improvements as necessary
  • Evaluate the maturity of common security operations roles and functions, including: threat intelligence, threat hunting, detection engineering, SOC operations, incident response, and security engineering
  • Utilize common security tooling, including: EDR, SIEM, and live response tools
  • Utilize and provide guidance regarding common telemetry sources, including: EDR, Sysmon, Windows Event Logging, SIEM, WAF, IDS/IPS, cloud platforms (Azure, AWS, GCP), and others
  • Build scripts, tools, or methodologies to enhance investigation processes
  • Serve as a subject matter expert (SME) in one of the following areas: detection engineering, network, memory, and/or disk forensics, log analysis, malware triage, or reverse engineering
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
  • Effectively communicate investigative findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel
  • Assist with scoping prospective engagements, participating in investigations from kickoff through remediation, and mentoring less experienced staff
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, student support, etc.)
  • (Senior Consultant) Create and deliver at least two pieces of content a year (e.g., blog post, conference presentation, workshop, or webinar)

Requirements (All Positions)

  • Ability to travel domestically and internationally up to an average of 25% over the course of one year
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency 

As an Associate Consultant, your primarily responsibility will be to learn. You will engage, participate, and contribute to the execution of a variety of services and projects. In doing so, you will actively develop a basic understanding of the SpecterOps Adversary Simulation service line and develop skills in one or more technical areas.

Desired Qualifications (Associate Consultant)

  • Foundational knowledge of defensive security concepts and assessments
  • Foundational knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations, and operating procedures
  • Strong written/verbal communication and interpersonal skills
  • Determination to better self and the overall information security community through research efforts and release through blog posts, conference talk delivery, open-source tool release, and white paper publication
  • Willingness to support delivery of public and private training offerings (e.g., providing lab support, fielding student questions, etc.) 

As a Consultant, you will independently contribute to significant services and projects. You will be responsible for the entire lifecycle of small to medium services and projects.

Desired Qualifications (Consultant)

  • Meets desired qualifications for an Associate Consultant, plus the following
  • Foundational knowledge of offensive security concepts and assessments
  • Working knowledge of common regulatory requirements and governance frameworks
  • Working knowledge of attacker techniques and commonly used offensive tools
  • Working knowledge of Windows and NIX disk and memory forensics
  • Proficient with Windows and NIX-based operating systems and related defensive controls
  • Proficient with networking concepts and related defensive controls
  • Proficient with Active Directory and related defensive controls
  • Proficient with defensive security concepts and assessments
  • Ability to lead small to medium sized services and projects
  • Ability to communicate effectively with customers, team members and upper management for project delivery
  • Ability to contribute to most defensive service offerings (e.g., detection engineering, maturity assessment, purple team assessment, program development, etc.) as part of a team for the full project lifecycle
  • Strong analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with attention to detail and accuracy

As a Senior Consultant, you will be responsible for the entire lifecycle of significant services and projects.

Desired Qualifications (Senior Consultant)

  • Meets desired qualifications for a Consultant, plus the following
  • A clear expert in one or more service lines and/or technical areas
  • Ability to lead and execute most defensive service offerings (e.g., detection engineering, maturity assessment, purple team assessment, program development, etc.) 
  • Experience leading small teams and engagements
  • Experience managing multiple projects at once
  • Experience communicating with clients and delivering presentations
  • Experience independently managing client projects
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves (All Positions)

  • Bachelor's degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience working in a Security Operations Center (SOC) environment
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience in malware analysis and reverse engineering
  • Experience in executing offensive techniques (red teaming, pentesting, etc)
  • Experience documenting detections via the Alerting and Detection Strategy framework
  • Experience developing and/or providing technical training
  • Desire to teach and train students in defensive techniques
  • Desire to travel internationally and domestically on a more frequent basis (more than 50%)

What We Offer:   

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family    
  • Flexible time off policy    
  • 13 paid holidays annually    
  • 401(k) with up to 4% company match    
  • Stock Options & bonuses 
  • Remote work: $1,500 new hire allowance to set up home office    
  • $500 annual home office allowance after first year 
  • $150 monthly cell phone and internet reimbursement   
  • $5,000 annual professional development allowance   
  • $5,250 towards continuing education or student loan repayment    
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more 
  • A one-time $10,000 benefit towards family planning     
  • In person and virtual employee events throughout the year    
  • And of course, company swag!    

 All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.  To request reasonable accommodations, please contact us at careers@specterops.io  

Unsolicited resumes are not accepted   

#LI-REMOTE 

 

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in United States

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Washington, District Of Columbia, United States (On-Site)

United States (Remote)

United States (Remote)

United States (Remote)

United States (Remote)

View All Jobs

Get notified when new jobs are added by SpecterOps

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug