The Red Team Consultant is a cybersecurity professional who specializes in identifying vulnerabilities and weaknesses in an organization’s security posture by simulating real-world attacks. They play a crucial role in helping organizations improve their security defenses and protect against potential cyber threats.
Responsibilities:
Perform Web Application, Mobile Application, Wireless Networks, and Infrastructure Penetration Tests both onsite and remotely as needed.
Conduct secure code reviews, identifying vulnerabilities in source code across various programming languages and back-end technologies.
Participate in discussions with clients to understand their environment and applications, define the scope and Rules of Engagement, and organize test schedules.
Create detailed technical reports describing how vulnerabilities were identified, how they were exploited, and how they should be remediated.
Produce executive summary reports that communicate the business risks of identified vulnerabilities and the importance of prioritizing remediation.
Assist customers with questions regarding remediation strategies and implementation.
Participate in internal research projects to explore emerging security threats, tools, and techniques.
Qualifications, Experience and Skills:
2-4 years of experience in the offensive security field.
Experience performing penetration tests against Web Applications, Mobile Applications, Desktop Applications, Wireless Networks, and Infrastructure within Active Directory-based environments.
Experience in secure code reviews, identifying vulnerabilities in source code, and providing recommendations for secure coding practices.
Experience scoping penetration testing engagements.
Experience briefing engagement results to different customer levels.
Proficiency in programming languages such as C++, C, and C#.
Experience with various scripting languages, such as Bash, Python, and PowerShell.
Knowledge of back-end web technologies, including but not limited to server-side programming languages (e.g., Java, .NET, PHP, Node.js) and database systems (e.g., MySQL, MSSQL, PostgreSQL).
One or more recognized industry certifications, such as OSCP, OSWE, OSEP, OSED, GPEN, GWAPT, and GXPN.
Excellent written and verbal communication skills.