
Senior Red Team Consultant
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in North America.
• Become a part of Bishop Fox, where you'll work alongside a curious and committed team to address intricate challenges for some of the world’s most esteemed organizations, safeguarding their networks against real-world threats.
• You will lead red teaming operations, initiating with thorough research that encompasses profiling organizations, establishing attack objectives, and devising attack tree diagrams along with other essential planning activities.
• Execute operations based on strategic planning to meet attack objectives through various potential attack vectors, including network, web applications, physical, social engineering, and more.
• Assist our clients in comprehending their attack surface by effectively communicating their incident response capabilities, detailing actions taken, and reporting on issues identified.
• Offer insightful, customized, and actionable recommendations.
• Tackle complex technical challenges and develop innovative solutions in a client-facing capacity.
• As a trusted advisor, share your expertise to guide our clients through challenging business choices, including the prioritization of critical findings.
• Lead small teams on unique engagements, mentor colleagues, and play a significant role in advancing our consulting practice.
• A minimum of 5 years of offensive security experience, supporting various adversary emulation engagements (red teaming and purple teaming) across diverse industries.
• Proficient understanding of all major operating systems, including Windows, MacOS, Linux, and ChromeOS.
• Expertise in exploiting Windows Active Directory and executing lateral movement.
• Familiarity with cloud platforms (AWS/Azure/GCP and O365/Google Workspace) and container technologies (Kubernetes/Docker).
• Practical experience with command and control frameworks such as Sliver, Nighthawk, Mythic, and others.
• Background in custom tool and payload development, reverse engineering, and evasion techniques.
• Experience in researching and developing EDR evasion techniques.
• Proficient in multiple programming languages, preferably Python, Golang, JavaScript/TypeScript, C#, C/C++, PowerShell, and/or Bash.
• Knowledge of network and web-related protocols (e.g., TCP/IP, HTTP, HTTPS, etc.).
• Proven experience in social engineering, reconnaissance, and the development and delivery of phishing/vishing pretexts, as well as a solid understanding of email security technologies and related countermeasures.
• Exceptional written and verbal communication skills.
• Generous Time Off and Company-Wide Holidays
• Team Events and International Travel Opportunities
• Work From Home Support
• Monthly Allowance for Cell Phone and Internet
• Training Budget
• Retirement; 401k Matching for Traditional and Roth Accounts in the US
• Health Insurance Options Including Medical, Dental, Vision
• Paid Parental Leave
CBIZ
Blueprint Test Prep
Nexthink
Get handpicked remote jobs straight to your inbox weekly.