Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.
- 3 years of experience in one of the following security areas: network security, web application/mobile security, and cloud security.
- 2 years of experience with techniques and tools used for wireless, web application, and network security testing.
- Ability to travel up to 40% of the time.
Preferred qualifications:
- Certifications related to offensive security, including OSCE, OSEP, OSEE, OSCP, CCSAS, CCT INF, or relevant SANS courses.
- Experience in four or more of the following: network protocols, threat intelligence analysis, system and network administration, project management, developing applications, technical incident response processes, source code review, reverse developing.
- Experience implementing or assessing information security implementation or assessment of security controls.
- Excellent communication, collaboration, and relationship management skills.
About the job:
As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.
As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.
Mandiant’s Offensive Security team delivers pen testing, adversarial emulation, network security, and application security assessments. In this role, you will execute threat intelligence-led Red team engagements for large enterprises, build command-and-control infrastructure, compromise perimeter systems, perform lateral movement and privilege escalation, and covertly exfiltrate data.
As an Offensive Security Consultant, you will deliver Red and Purple team assessments across networks, cloud, web, and mobile environments. You will develop offensive tools, researching exploit techniques, and mentoring team members. You will author clear technical reports and executive presentations for C-level leaders. You will lead engagements from scoping through remediation while safely utilizing threat actor tactics.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
Canada: $134000 - $137000 (CAD) + 15% bonus target + equity + benefits
Learn more about
benefits at Google.
Responsibilities:
- Support red and purple team assessments, assumed breach assessments (e.g., Red team engagements with a pre-deployed implant) and similar engagements. Take an active role in web, cloud and mobile application testing.
- Conduct external/internal/wireless network assessments, web and mobile application testing.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
- Recognize and safely utilize attacker tools, tactics, and procedures.
- Communicate findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel.