Senior Security Consultant

Directdefense, Inc.
Englewood, CO, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $170,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Automation of Tests Cyber Security Information Systems Security Architecture Professional Red Team (Cyber Security) Cyber Threat Analysis Information Technology Vulnerability Analysis

Job description

  • Conduct comprehensive penetration tests to identify security vulnerabilities, assess their impact, and develop actionable remediation strategies.
  • Perform detailed vulnerability assessments and analyses of client networks, systems, servers, and other infrastructure components.
  • Lead Red Team exercises to simulate advanced persistent threats and measure an organization’s readiness to detect, respond, and mitigate attacks.
  • Stay up to date with the latest vulnerabilities, technology trends, threat landscapes, and offensive toolkits used in penetration testing. Apply this knowledge to enhance testing methodologies.
  • Develop and execute proof-of-concept exploits to demonstrate the impact and severity of identified vulnerabilities.
  • Create comprehensive, accurate, and detailed reports and presentations for both technical and executive audiences, clearly communicating findings, risks, and remediation recommendations.
  • Design and develop scripts, tools, and methodologies to improve testing processes and efficiencies.
  • Mentor and guide less experienced penetration testers, fostering a culture of continuous learning and professional development.
  • Assist in scoping prospective engagements, managing client expectations, and lead engagements from kickoff through remediation.
  • Evaluate and recommend improvements to clients’ security architectures, ensuring robust and resilient defenses., We aim to secure organizations across all industries against advanced threats and attacks in today’s world. Acting in partnership with organizations, we will provide unmatched information security services designed to improve your overall security posture, close gaps, and track vulnerabilities on an ongoing basis through continued education and support.

Requirements

Do you have experience in Vuls?, The Senior Security Consultant at DirectDefense will be a crucial member of our cybersecurity team. They are responsible for identifying security vulnerabilities within our clients’ environments and providing technical remediation guidance. This role involves conducting comprehensive penetration tests, performing detailed vulnerability assessments, and leading Red Team engagements to simulate sophisticated attacks. The ideal candidate will possess extensive technical expertise, a deep understanding of both offensive and defensive IT concepts, and the ability to communicate complex security issues effectively. With a focus on staying current with the latest vulnerabilities and technology trends, the Senior Security Consultant will develop and execute proof-of-concept exploits, create detailed reports, and recommend improvements to enhance clients’ security postures. This position also involves mentoring junior testers and contributing to the development of innovative testing tools and, * 5-10 years of hands-on experience in network/infrastructure security and penetration testing.

  • Extensive knowledge of offensive toolkits and techniques used in network/infrastructure penetration testing.
  • Strong grasp of both offensive and defensive IT concepts, including common attack vectors and defense mechanisms.
  • Proven ability to stay current with the latest vulnerabilities, technology trends, and threat landscapes.
  • Exceptional ability to develop proof-of-concept exploits that accurately demonstrate identified vulnerabilities.
  • Excellent written and verbal communication skills, capable of conveying complex security topics in a clear, concise, and understandable manner to diverse audiences.
  • Professional certifications such as OSCP and OSEP are highly preferred.
  • Ability to travel up to 25%

Benefits & conditions

3.83.8 out of 5 stars Englewood, CO 80112 Remote $130,000 - $170,000 a year - Full-time, Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance, Salary range: $130,000 - $170,000

Bonus: Up to 15% Annual Bonus

Benefits include:

  • 401(k)
  • AD&D Insurance
  • Dental Insurance
  • Disability insurance
  • Health insurance
  • Life insurance
  • Vision insurance
  • Flex PTO program
  • Paid certification and continuing education

Career Development:

  • Opportunities for professional growth and development within the company.
  • Access to training programs and certifications.
  • Participation in industry conferences and workshops., In accordance with applicable state laws, we are providing a good-faith estimate of the compensation range for this role. The anticipated salary range for this position is $130,000 to $170,000 per year. Actual compensation will be based on a variety of factors, including but not limited to the candidate’s qualifications, experience, skills, and location. This position may also be eligible for bonus incentives and a comprehensive benefits package.

About the company

Since coming together in 2011 to form DirectDefense, our team has been committed to offering unmatched Cybersecurity defense strategies in the industry. Whether we are performing assessments of networks, platforms, and applications or applying managed services to improve your organization’s security posture, we are focused on providing world-class services that don’t just work-they work for you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

2:56 min

Test automation strategy and following the testing pyramid

Daniel Strmečki +1 · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:06 min

Implementing runtime threat event frameworks for attack telemetry

Tom Tovar · World Congress 2023

3:49 min

Failing at test automation with slow and complex suites

Johannes Stern Johannes Stern · World Congress 2024

Videos

See all

Related articles

See all