Offensive Security Sr Cyber Security Research Consultant - WellsFargo

  • 20 Apr 2022 5:21 PM
    Message # 12716434
    James Walters (Administrator)

    Offensive Security Sr Cyber Security Research Consultant - Wells Fargo Bank (Richmond)

    About this role:

    Wells Fargo is seeking a Senior Cyber Security Research Consultant professional to join our Offensive Security Research Team (Red Team) - Threat Simulation group. This role will involve the execution of Tactics, Techniques, Procedures (TTPs) that will simulate or emulate financial threat actors. The position involves collaborating with other members of the Cyber Security Defense and Monitoring team to collaborate on enhancing the detection capabilities to protect the bank. After a successful operation, work with Blue Team members to identify opportunities to break the attack chain. This team member must be able to utilize complex hacking tools, create proof of concept exploits, and document attack chains so they can be re-created and defensive tactics developed for them. This position reports to the Cyber Threat Management and works closely with our defense partners in a purple team capacity.

    In this role, you will:

    • Lead or participate in the research, analysis, design, testing and implementation of complex computer network security and protection technologies for company information and network systems and applications
    • Act as professional ethical penetration tester utilizing hacking tools to modify or create proof of concept exploits that mimic techniques of attackers to identify vulnerabilities and associate with a severity rating by deriving impact and ease of exploit
    • Review and analyze advanced computer security incident response activities and technical investigations of information security related incidents or breach related activates
    • Perform tests on networking devices, appliance products and web based application
    • Implement and develop custom penetration testing techniques and tools
    • Perform security risk assessments to ensure compliance with corporate information security policies and adherence to best practices
    • Provide guidance and leadership to more experienced Information Security Engineers and act as a mentor for these engineers interested in penetration testing and offensive security
    • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
    Required Qualifications, US:
    • 3+ years of information security experience in converged testing (red teaming) demonstrated through work or military experience
    • 3+ years of experience in one or a combination of the following: creating proof of concepts, creating exploits, or reverse engineering demonstrated through work or military experience
    • 3+ years of automated information security penetration tools experience
    • 3+ years of experience with Linux operating system engineering or automation
    Desired Qualifications:
    • Advanced Information Security technical skills
    • Proficient in working with systems, networks, and application vulnerability testing
    • Ability to manage complex security scenarios and develop innovative solutions to address the most recent cyber threats
    • Security engineering experience that includes knowledge and understanding of recent research and industrial advances in one or more of the following areas: computer and communication networks, cyber security threat detection, cyber security experimentation and testing, innovative research in cyber security, physical security controls and their weaknesses, debugging, hardware and device hacking, or electronics security
    • Experience working in a large enterprise environment
    • Strong analytical skills with high attention to detail and accuracy
    • Knowledge and understanding of system/application architecture and design concepts
    • 2+ years of experience with scripting languages such as Bash, PowerShell, Python, Shell, VBScript, or JavaScript
    Job Expectations:
    • Ability to travel up to 5% of the time
    We Value Diversity

    At Wells Fargo, we believe in diversity, equity and inclusion in the workplace; accordingly, we welcome applications for employment from all qualified candidates, regardless of race, color, gender, national origin, religion, age, sexual orientation, gender identity, gender expression, genetic information, individuals with disabilities, pregnancy, marital status, status as a protected veteran or any other status protected by applicable law.

    Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

    Candidates applying to job openings posted in US: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

    Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

    To apply to this job, click Apply Now

Copyright 2022, International Information Systems Security Certification Consortium, Inc. (“(ISC)²), in website format and trade dress only. All Rights Reserved. (ISC)², CISSP, SSCP, CAP, ISSAP, ISSEP, ISSMP, CSSLP, and CBK are registered certification, service, and trademarks of (ISC)². Disclaimer: (ISC)²” does not own, operate, or moderate this website. All content of this site, exclusive of licensed trademarks or copyright, is the property of the designated (ISC)² Chapter organization, which is not owned, managed, or controlled by (ISC)² and operates independent of (ISC)².  

(ISC)2RVA is a 501(c)3 nonprofit organization.  EIN: 83-4655968

P.O. Box 2566, Glen Allen, VA 23058-2566

Powered by Wild Apricot Membership Software