Job Information
Prudential Ins Co of America Lead Offensive Security Engineer in Newark, New Jersey
Job Classification:
Technology - Information Security
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, youll unlock an exciting and impactful career all while growing your skills and advancing your profession at one of the worlds leading financial services institutions.
Your Team & Role
As a Lead Offensive Security Engineer on the Attack Surface Management team, you will be at the forefront of our efforts to identify and mitigate security risks. Your responsibilities will include conducting sophisticated red team and purple team exercises to challenge and refine our defensive strategies. You will conduct a variety of penetration testing activities, focusing on diverse targets such as web applications, AI systems, and Active Directory environments, in order to uncover and address vulnerabilities. Beyond traditional offensive security operations, you will also play a key role in supporting and advancing our bug bounty program, ensuring that any potential threats are swiftly identified and resolved.
Here is What You Can Expect on a Typical Day
Plan and Execute Red Team Exercises: Design and carry out advanced red team operations to simulate real-world attacks, identifying and exploiting vulnerabilities within client environments.
Conduct Purple Team Assessments: Collaborate with the defensive (blue) team to run combined exercises that enhance detection and response capabilities, fostering a stronger overall security posture.
Perform Penetration Testing: Execute comprehensive penetration tests on various systems, including web applications, mobile applications, external networks, AI/ML systems, and SaaS environments.
Adversary Emulation: Emulate tactics, techniques, and procedures (TTPs) of known threat actors to test the effectiveness of security controls and incident response processes.
Vulnerability Identification and Exploitation: Identify and exploit weaknesses in systems and applications to demonstrate potential risks and impact.
Support Bug Bounty Programs: Participate in and enhance the bug bounty program by validating submissions, providing detailed analysis, and collaborating with researchers and internal stakeholders to address vulnerabilities.
STRIDE Threat Modeling: As an SME in attack and vulnerability exploitation techniques, assist stakeholders in comprehensive Threat Modeling exercises to identify potential weaknesses and harden systems.
Develop Offensive Security Tools: Create and maintain tools and scripts to assist with red team operations and penetration testing efforts.
Conduct Security Research: Regularly research and learn new TTPs in public and closed forums. Work with teammates to assess Prudentials risk and work with teams to implement and validate controls as necessary.
Threat Intelligence Integration: Utilize threat intelligence to inform red team scenarios and improve the realism and relevance of simulations.
Reporting and Documentation: Produce detailed reports of findings, including technical descriptions of vulnerabilities, potential impacts, and recommended remediation steps.
Engage with Stakeholders: Communicate effectively with internal and external stakeholders to present findings, provide recommendations, and support remediation efforts.
Knowledge Sharing and Training: Conduct internal training sessions, workshops, and presentations to share insights and improve the overall skill level of the security team. Mentor and knowledge share with other Offensive Security engineers on the team.
Continuous Improvement: Regularly review and refine testing methodologies, tools, and processes to ensure cutting-edge offensive security practices.
Provide Remediation Guidance: Offer expert recommendations to internal stakeholders on how to address and mitigate identified security vulnerabilities, ensuring they adopt best practices for enhanced protection.
The Skills & Expertise You Bring
Bachelor of Computer Science or Engineering or experience in related fields
Ability to coach others with minimal guidance and effectively leverage diverse ideas, experiences, thoughts and perspectives to the benefit of the organization
Experience with agile development methodologies and Test-Driven Development (TDD)
Knowledge of business concepts tools and processes that are needed for making sound decisions in the context of the company's business
Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges
Excellent problem solving, communication and collaboration skills
Advanced experience and/or expertise with several of the following:
Proven experience conducting a variety of offensive security operations, including red teaming and penetration testing across multiple domains such as network, web applications, mobile platforms, cloud environments, social engineering tactics, and scripting or tool creation.
Expertise in Active Directory red teaming, with a deep understanding of advanced offensive tactics, techniques, and procedures (TTPs) used to exploit Active Directory environments.
Experience performing security reviews of existing infrastructure and demonstrating vulnerabilities
Building, deploying, and maintaining red team infrastructure
Knowledge of adversarial TTPs
Proficiency rating vulnerabilities using the CVSS scoring system
Experience with Threat Modeling, preferably using the STRIDE methodology
Competent with testing frameworks and tools such as Burp Suite, Metasploit, VECTR, Cobalt Strike,...
Equal Opportunity Employer - minorities/females/veterans/individuals with disabilities/sexual orientation/gender identity