
Security Consultant – Threat & Attack Simulation
Posted Jul 19

Posted Jul 19
This is a fully remote position, open to applicants in United States.
• Deliver professional services in Threat & Attack Simulation, encompassing Vulnerability Assessments, both Internal and External Penetration Tests, Wireless Security Assessments, Onsite and Remote Social Engineering, along with various custom assessments.
• Create thorough assessment deliverables that are expertly customized for both technical and managerial audiences, detailing the technical execution, core deficiencies, business impacts, and practical remediation strategies.
• Leverage automation, orchestration, and scripting to minimize manual processes, enhancing overall efficiency while also introducing new capabilities to address the evolving needs of our clients.
• Participate in marketing efforts through activities such as publishing research, speaking at industry conferences, writing blog articles and whitepapers, hosting webinars, and developing security tools.
• Support Practice development efforts, including enhancements to existing service offerings.
• Continuously enhance relevant skills, knowledge, and capabilities to remain at the forefront of the information security sector.
• Cultivate client relationships by providing support, information, and guidance.
• Set up, operate, and manage a Breach and Attack Simulation (BAS) or continuous penetration testing platform and promptly report results to pertinent stakeholders.
• Maintain a strong eagerness to learn, adapt, and grow alongside a rapidly expanding company.
• Carry out additional responsibilities as assigned.
• Lab-based certifications such as OSCP, OSCE, OSEE, and GSE are highly preferred.
• Other relevant industry certifications like GPEN and GCIH are also desirable.
• Experience with various public cloud components and architectures, including AWS, Azure, and GCP.
• Active involvement in the InfoSec community, such as conference speaking, authoring blogs/whitepapers, and podcast speaking/producing experience, is strongly preferred.
• At least two (2) years of experience conducting offensive/attack-oriented security assessments.
• A minimum of one (1) year of experience in an enterprise-level consulting services role.
• More than four (4) years of combined IT and information security experience is preferred.
• Internal operational (non-consulting) experience is strongly preferred.
• Experience with continuous penetration testing or Breach and Attack Simulation (BAS) platforms is an advantage but not mandatory.
• Embraces emerging technologies, including AI tools, to enhance work efficiency, address problems, and achieve better business outcomes.
• Primarily remote workforce (U.S. based only, some travel may be necessary for certain positions, on-site work may be required for Federal roles).
• Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint covers 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint covers 100% of employee premiums and 75% for family plans (spouse/children/family). If opting for the High Deductible / HSA plan, GPS will contribute in four equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options).
• Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% for family plans.
• 12 corporate holidays and a Flexible Time Off (FTO) program.
• Healthy mobile phone and home internet allowance.
• Eligibility for retirement plan after 2 months at open enrollment.
• Pet Benefit Option.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.