Senior Cyber Operator (Red Team)

Posted about 2 months agoViewed
120000 - 150000 USD per year
USFull-TimeCybersecurity
Company:SixGen, Inc.
Location:US, EST, PST
Languages:English
Seniority level:Senior, 2+ years leadership, 2+ years independent red team exercises, 5+ years web application penetration testing
Experience:2+ years leadership, 2+ years independent red team exercises, 5+ years web application penetration testing
Skills:
LeadershipPythonBashCybersecurityAPI testingManual testingRESTful APIsTerraformMentoringComplianceAnsible
Requirements:
2 years leadership experience directly leading a team Minimum 2 years of independently conducting every phase of a red team exercise on their own without guidance or supervision. Minimum 2 years mentoring junior and mid-level operators on red team tradecraft and Advanced Knowledge Requirements (that they possess). Minimum 2 years of hands-on experience in network mapping, vulnerability scanning, and penetration and web application testing using software frameworks (including but not limited to: Cobalt Strike, Kali, burpsuite, etc.) to meet operational requirements. Strong communication skills for interfacing with clients and documenting findings Demonstrated experience working both collaboratively and independently with minimal supervision. Script writing and crafting of payloads that bypass A/V and EDR solutions for use in various phases of a red team exercise. In- depth Experience pen testing on internal and external networks Minimum 5 years of hands-on web application penetration testing experience, with a strong preference for OSCP or equivalent hands-on certifications (e.g. CBBH, CWEE, OSWA, OSWE, GWAPT). Experience developing actionable intelligence based on open source intelligence (OSINT) gathering. Experience building offensive capabilities or tools to enhance operations with programming languages such as, but not limited to, Python, Bash, terraform, ansible, etc. Experience in testing web-based APIs (i.e. REST, SOAP, XML, JSON). Advanced knowledge of manual testing techniques and automated tools (e.g., Burp Suite, OWASP ZAP) to assess application security. Familiarity with FISMA and NIST 800-series frameworks; experienced in applying formal testing protocols and methodologies to assess networks, web apps, and cloud environments. CRTO certification required (or ability to obtain within 90 days of start date) Willing and able to travel as needed. Up to 50% during periods of high workload
Responsibilities:
Provide recommendations for technical oversight of activities aligned to command priorities. Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies. Perform phishing assessments. Perform vulnerability risk assessment. Participate in the testing phase of security controls assessments using specialized knowledge of network protocols, operating systems, architectures, equipment, services, and standards. Conduct comprehensive, black-box penetration testing of web applications to identify critical vulnerabilities such as SQL injection, XSS, CSRF, XXE, deserialization attacks, RCE, etc. Utilize a bug bounty-style approach to independently enumerate and assess targets, simulating real-world attack scenarios. Analyze application architecture and source code (when available) to uncover deeper, logic-based or systemic vulnerabilities. Document and communicate findings with clear risk assessments, reproduction steps, and actionable remediation recommendations. Stay up to date with evolving web technologies, threat trends, and security tools to ensure cutting-edge testing practices.
About the Company
SixGen, Inc.
10-50 employees
View Company Profile
Similar Jobs:
Posted about 2 months ago
USFull-TimeCybersecurity
Senior Internal Red Team Engineer
Company:Horizon3 AI
Posted 4 months ago
USAFull-TimeSoftware Development
Senior Security Engineer (Red Team)
Company:Glean
Posted about 2 months ago
United StatesFull-TimeCybersecurity
Cyber Threat Intelligence Team Lead