Google تعلن عن وظيفة مستشار أول في فريق Red Team (Google Cloud) بمدينة الرياض
تفاصيل الوظيفة
تعلن شركة Google عن فرصة وظيفية بمسمى Senior Consultant, Red Team ضمن قسم Google Cloud / Mandiant Consulting، في الرياض، المملكة العربية السعودية (مع إمكانية العمل في دبي أو الدوحة).
نبذة عن الوظيفة
انضم إلى فريق Red Team في Mandiant، حيث نخطط وننفذ تقييمات أمنية هجومية لعملاء Google Cloud وMandiant. تشمل المهام محاكاة الهجمات السيبرانية من طرف إلى طرف، واختبار الاختراق الخارجي، وتطوير أدوات القيادة والتحكم، وحملات الهندسة الاجتماعية، والتصعيد، والحركة الجانبية، واستخراج البيانات مع تجنب اكتشاف فرق الأمن. نحن نبحث عن مستشار Red Team ذو خبرة عالية لتقديم خدمات استشارية في مجال الأمن السيبراني، وتقييم الضوابط الفنية والإجرائية، والعمل كمستشار موثوق للعملاء.
المهام والمسؤوليات
- إجراء تقييمات Red Team وPurple Team، بما في ذلك محاكاة الهجمات السيبرانية ضد المؤسسات، وتقييمات أمنية تقنية أخرى مثل اختبار الاختراق الخارجي، واختبار تطبيقات الويب والجوال، واختبار الأمان اللاسلكي.
- توسيع قدرات الفريق من خلال إنشاء الأدوات، والبحث في التقنيات الهجومية، ودمج معلومات التهديدات، والعروض التقديمية الداخلية، ومشاركة المعرفة.
- إعداد تقارير وعروض تقديمية شاملة ودقيقة للجمهور الفني والتنفيذي، والعمل كمستشار موثوق لكبار المسؤولين التنفيذيين وقادة الأمن وأصحاب المصلحة الآخرين.
- المساعدة في تحديد نطاق المشاريع المحتملة، وقيادة الفرق من البداية حتى مرحلة المعالجة، بالإضافة إلى توجيه الموظفين الآخرين.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني مع التركيز على الأمن الهجومي، أو خبرة عملية معادلة.
- خبرة لا تقل عن 5 سنوات في ثلاثة من المجالات الأمنية التالية: أمن التطبيقات، تقييمات Red Team، تجنب اكتشاف نقطة النهاية والاستجابة (EDR)، تطوير الاستغلالات، السحابة، الهندسة الاجتماعية، البرمجة النصية، تطوير الأدوات.
- خبرة في تقديم التقارير والعروض التقديمية للجمهور الفني والتنفيذي.
- خبرة في أمن أنظمة التشغيل عبر أنظمة التشغيل أو Linux.
المهارات المطلوبة
يفضل أن يكون لدى المتقدم شهادات متعلقة بالأمن الهجومي مثل OSCE, OSEP, OSEE, OSCP, CCSAS, CCT INF أو دورات SANS ذات الصلة. كما يفضل خبرة في أربعة أو أكثر من المجالات التالية: بروتوكولات الشبكات، تحليل استخبارات التهديدات، إدارة الأنظمة والشبكات، إدارة المشاريع، تطوير التطبيقات، عمليات الاستجابة للحوادث التقنية، مراجعة كود المصدر، الهندسة العكسية. بالإضافة إلى خبرة في اكتشاف ثغرات 0-day في تطبيقات الويب أو الجوال، خبرة في إنشاء أدوات أمنية وفهم لغات البرمجة الأساسية (مثل Python, C#, C/C++, Rust, Nim أو ما شابه)، خبرة في مراجعة كود مصدر التطبيقات، وخبرة في تطوير الحمولات، الحركة الجانبية، تصعيد الامتيازات، وتجنب EDR.
عرض النص الأصلي للإعلان
- Bachelor's degree in cybersecurity, with a focus on offensive security or equivalent practical experience.
- 5 years of experience in three of the following security areas: application security, red team assessments, endpoint detection and response (EDR) evasion, exploit development, cloud, social engineering, scripting, tool development.
- Experience delivering reporting and presentations to both technical and executive audiences.
- Experience with operating system security across operating systems or Linux.
- Certifications related to offensive security including OSCE, OSEP, OSEE, OSCP, CCSAS, CCT INF or relevant SANS courses.
- Experience in four or more of the following: network protocols, threat intelligence analysis, system and network administration, project management, developing applications, technical incident response processes, source code review, reverse engineering.
- Experience in finding 0-day vulnerabilities in web or mobile applications.
- Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar).
- Experience in performing application source code review.
- Experience in payload development, lateral movement, privilege escalation and EDR evasion.
The mission of the team is to scope, plan, and execute offensive security assessments for Google Cloud and Mandiant customers.
Mandiant's Red Team delivers offensive security engagements. This may involve delivering a Red Team for a large enterprise, breaching external perimeter through application compromise, preparing command and control infrastructure, developing social engineering campaigns and the associated collateral, executing phishing campaigns and attempting to compromise internet-facing systems, conducting privilege escalation and lateral movement within customer networks, hunting for objectives with little-to-no information provided by the customer and exfiltrating data from the network all while avoiding detection from the customer security operations teams.
To always operate in the true hacker spirit - be curious, learn, tinker and evolve.
We are seeking a highly skilled and experienced Red Team Consultant to join our team. In this role, you will be responsible for providing cybersecurity consulting services and support to our clients, including assessing and advising clients on both technical and process-based controls for all manner of environments.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Responsibilities
- Perform Red and Purple Team assessments, including end-to-end adversarial emulation of cyber attacks against customer organizations, and other technical cyber assessments including external penetration, web application, mobile and wireless security testing.
- Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders.
- Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.