Offensive Security Consultant, Google Cloud , Mandiant Consulting
- Location
- Singapore
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 2,460 approvals (FY2023)
- Posted
- 4h ago
Skills
About this role
Mandiant's offensive security consulting team is responsible for performing Red and Purple Team assessments of customer environments. We breach our customer networks to reveal flaws, test weaknesses, and to exercise defensive teams and capabilities. We take Mandiant's frontline incident response and intelligence knowledge and apply cutting edge techniques and tradecraft being used by threat actors in the wild. Our consultants are offensive security experts who specialize at executing all stages of the attack lifecycle, from initial compromise, privilege escalation, lateral movement, to achieving desired objectives. We adapt to customer technologies, from on-premises networks, to modern cloud architecture, to zero-trust and identity-centric environments, and everything in between. We work together to emulate ransomware, financial, espionage, and other threat actors, and we aim to deliver the most realistic breach scenarios.Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Perform Red and Purple Team assessments, including end-to-end adversarial emulation of cyber attacks against customer organisations, and other technical cyber assessments including external penetration, web application, mobile and wireless security testing. Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share. Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders. Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.
Minimum qualifications: Bachelor's degree in Computer Science, Information Systems, Cybersecurity or a related technical field, or equivalent practical experience. 3 years of experience in offensive security/red teaming functions, including network, web application, mobile, cloud, social engineering, scripting, or tool development. Preferred qualifications: Certifications related to offensive security including OSCE, OSEP, OSEE, OSCP, CISSP, CISA or relevant SANS courses. Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar). Excellent communication skills, with the ability to communicate technical details through reporting and presentations to both technical and executive audiences.