Sr. Red Team Engineer (Remote)

Company: CrowdStrike
Company: CrowdStrike
Location: USA - Remote
Commitment: Full time
Posted on: 2024-04-24 05:30
#WeAreCrowdStrike and our mission is to stop breaches. As a global leader in cybersecurity, our team changed the game. Since our inception, our market leading cloud-native platform has offered unparalleled protection against the most sophisticated cyberattacks. We’re looking for people with limitless passion, a relentless focus on innovation and a fanatical commitment to the customer to join us in shaping the future of cybersecurity. Consistently recognized as a top workplace, CrowdStrike is committed to cultivating an inclusive, remote-first culture that offers people the autonomy and flexibility to balance the needs of work and life while taking their career to the next level. Interested in working for a company that sets the standard and leads with integrity? Join us on a mission that matters - one team, one fight.About the Role: The Senior Red Team Engineer will assist in developing an Adversary Simulation program under the Information Security organization which covers security throughout all of CrowdStrike’s business and products. This position will lead Red Team activities simulating known threat actors, to help CrowdStrike determine the impact and likelihood of a threat actor to accomplish objectives across the Kill Chain and MITRE ATT&CK Framework. Outside of leading impactful Adversary Simulation exercises, the Sr. Red Team Engineer will work closely with the Red Team Manager to build the program, develop tools, techniques and processes (TTPs) for operations, and deliver results to defensive teams to ultimately maintain CrowdStrike’s secure environment.What You’ll Do:Act as a point of contact for CrowdStrike’s Adversary Simulation program, leading Red Team activities and a Subject Matter Expert (SME) in adversary tacticsMust be able to effectively communicate at all levels (executive leadership and technical support teams) within CrowdStrike.Develop and lead planning meetings to ensure all exercises have well defined goals and training objectives for defensive teamsDevelop reporting with mitigation strategies from the results of Adversary Simulation exercises for both management and technical audiencesProvide guidance using specialized knowledge and toolsets to operational teams during enterprise wide crisis scenarios, e.g. 0-day vulnerability released (Log4j)What You'll Need:3+ years of experience in Red Team activities is highly preferredMinimum 1 year of experience in a senior or leadership role is highly preferredSecurity community participation (conference speaker, tool development contributor, …) is highly preferredExperience using both commercial and open source tools to achieve the objectiveExperience in planning and executing Red Team activities that evaded both network and endpoint security controlsExperience emulating known threat actors and their respective tradecraftExperience planning both phishing and assumed breach exercises and understand the OPSEC ramifications throughout the Red Team operationAbility to develop, extend or modify Red Team toolingExperience building secure red team infrastructureAbility to evaluate threat intelligence and understand potential impact to CrowdStrikeComprehensive understanding of the security methodologies, technologies, and best practicesWindows / Linux / Mac operating systemsComprehensive knowledge of firewalls, proxies, mail servers and web serversAdvanced experience in automation and scripting of applications and systemsRelevant certifications and trainings a plusBonus Points:Familiarity with infrastructure-as-code, such as Terraform or AnsibleAdvanced knowledge with cloud environments, Identity Providers, common security concerns with SaaS applicationsExperience conducting Red Team activities in a macOS environmentExperience targeting CI/CD or software supply chain in a Red Team operationFamiliarity with the Red Team Maturity Model#LI-Remote#LI-RC1Benefits of Working at CrowdStrike:Remote-first cultureMarket leader in compensation and equity awardsCompetitive vacation and flexible working arrangements Comprehensive and inclusive health benefitsPhysical and mental wellness programsPaid parental leave, including adoption A variety of professional development and mentorship opportunitiesOffices with stocked kitchens when you need to fuel innovation and collaborationWe are committed to fostering a culture of belonging where everyone feels seen, heard, valued for who they are and empowered to succeed. Our approach to cultivating a diverse, equitable, and inclusive culture is rooted in listening, learning and collective action. By embracing the diversity of our people, we achieve our best work and fuel innovation - generating the best possible outcomes for our customers and the communities they serve.CrowdStrike is committed to maintaining an environment of Equal Opportunity and Affirmative Action. If you need reasonable accommodation to access the information provided on this website, please contact Recruiting@crowdstrike.com​, for further assistance.CrowdStrike participates in the E-Verify program. Notice of E-Verify ParticipationRight to WorkCrowdStrike, Inc. is committed to fair and equitable compensation practices. The base salary range for this position in the U.S. is $90,000 - $150,000 per year + variable/incentive compensation + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, certifications and location.Expected Close Date of Job Posting is:06-23-2024
View Original Job Posting