Pentesting / Purple Team Lead

Pentesting / Purple Team Lead

04 May 2024
Massachusetts, Dorchester, 02121 Dorchester USA

Pentesting / Purple Team Lead

Pentesting / Purple Team LeadDorchester, United States of AmericaThis role is the lead for the Purple Team program within Santander North America, covering both the US and Mexico. The Purple Team Head coordinates, designs and matures services within the Purple Team and mentors other members. A successful candidate will have verifiable experience in offensive security, threat hunting, attack simulation and leadership. Strong technical capabilities and an understanding of the application to the organization while recognizing operational impact is important as this is a key function of the role to work closely with defensive partners. This senior role is key to us maturing and growing our overall program and will have a lot of external visibility.Responsibilities :

Provide knowledge leadership in the coordination of third parties for Pentesting exercises.

Provide deep subject matter expertise for Purple / Red Team & Ethical Hacking Techniques.

Analyze test results and providing feedback to the owners of services / infrastructure & stakeholders

Advanced knowledge of threat intelligence & vulnerability management

Collaborate with various groups and individuals to follow up remediation plans for vulnerabilities identified during automated Pentesting exercises.

Assist in incident response efforts by providing expertise and insights gained from ethical hacking activities to mitigate and remediate security incidents effectively.

Maintain detailed documentation of processes, methodologies, and findings related to ethical hacking activities.

Provides advisory support for regulatory examinations and audits by defining the how and why for all implemented decisions; ensures all requested documentation is provided.

Supports owner team members in the resolution of Risk related issues.

Qualifications :

10+ years of relevant experience with most of the requirements below:

Extensive experience working with Offensive Security Methodologies and Attack Simulation Techniques.

Offensive Security testing tools. e.g., Cobalt Strike, Bloodhound, Red Team Toolkit.

Experience leveraging the MITRE ATT&CK Framework.

Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7

Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact

Social Engineering campaigns. e.g. email phishing, phone calls, SET

Deep understanding of OSI model

Security devices, i.e. Firewalls, VPN, AAA systems

OS Security. e.g. Unix/Linux, Windows, OSX

Understanding of common protocols. e.g. HTTP, LDAP, SMTP, DNS

Web application infrastructure. e.g. Application Servers, Web Servers, Databases

Web development and programming languages. e.g. Python, Perl, Ruby, Java, .Net

Proven experience with attack simulation and threat hunting is a must

Advanced Microsoft Office skills preferred

Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations

Advanced analytical and problem-solving skills

Consistently demonstrates clear and concise written and verbal communication

Preferred Certifications: PNPT, OSCP, OSCE, GXPN, GPEN, GCIH, GWAPT, GCFA, or CISSP.

Proficient in interpreting and applying policies, standards and procedures.

Diversity & EEO Statements: At Santander, we value and respect differences in our workforce and strive to increase the diversity of our teams. We actively encourage everyone to apply.Santander is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law.Working Conditions: Frequent Minimal physical effort such as sitting, standing, and walking. Occasional moving and lifting equipment and furniture is required to support onsite and offsite meeting setup and teardown. Physically capable of lifting to fifty pounds, able to bend, kneel, climb ladders.Employer Rights: This job description does not list all the job duties of the job. You may be asked by your supervisors or managers to perform other duties. You may be evaluated in part based upon your performance of the tasks listed in this job description. The employer has the right to revise this job description at any time. This job description is not a contract for employment and either you or the employer may terminate at any time for any reason.Bachelor of Science (BS) EnglishPrimary Location: Dorchester, MA, DorchesterOther Locations: Massachusetts-DorchesterOrganization: Santander Holdings USA, Inc.AN EQUAL OPPORTUNITY EMPLOYER M/F/Vet/Disabled/SO

Job Details

Jocancy Online Job Portal by jobSearchi.