Назад
Company hidden
обновлено 2 дня назад

Information Security Specialist - Red Team Operator (Cybersecurity)

96 900 - 136 800CAD
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Specialist - Red Team Operator (Cybersecurity): Executing end-to-end red team engagements that emulate real-world threat actors, validate security controls, and improve detection and response with an accent on Active Directory abuse, phishing, custom tooling, and enterprise attack paths. Focus on planning adversary emulation, developing payloads and command-and-control infrastructure, identifying telemetry gaps, and operating safely within regulated environments.

Location: Toronto, Ontario, Canada

Salary: CAD 96,900–136,800 per year, plus discretionary variable compensation based on business and individual performance.

Company

TD is a major financial institution serving households and businesses in Canada, the United States, and other markets.

What you will do

  • Plan and execute full-scope red team engagements covering reconnaissance, initial access, lateral movement, privilege escalation, command-and-control, and objective completion.
  • Emulate real-world threat actors using established tactics, techniques, and procedures, including MITRE ATT&CK.
  • Conduct phishing and social engineering campaigns within approved legal, ethical, and operational boundaries.
  • Develop and maintain custom tooling, payloads, red team infrastructure, and operational domains.
  • Partner with Blue Team, Purple Team, Threat Intelligence, and Incident Response functions to improve defensive capabilities.
  • Write technically accurate engagement reports and executive summaries, identify detection gaps, and mentor junior operators.

Requirements

  • University degree and 7+ years of experience in offensive security, red teaming, penetration testing, or equivalent hands-on security roles.
  • Strong knowledge of Windows Active Directory, identity abuse, enterprise authentication flows, network protocols, operating systems, and endpoint security controls.
  • Hands-on experience with C2 frameworks, phishing platforms, custom payloads, and adversarial activities in regulated environments with strict scope and approval processes.
  • Strong written and verbal communication skills, including report writing and technical walkthroughs.
  • Ability to work independently and collaborate effectively with cross-functional teams.

Nice to have

  • Experience with EDR, SIEM, and cloud security controls from an attacker’s perspective.
  • Custom tooling development experience with C#, Python, or PowerShell.
  • Knowledge of red team infrastructure, domain management, and OPSEC best practices.
  • Relevant certifications such as CRTO, OSCP, or GXPN.
  • Experience in financial services, large enterprises, or highly regulated environments.

Culture & Benefits

  • Base salary, variable compensation, health and well-being benefits, savings and retirement programs, and paid time off.
  • Banking benefits, discounts, career development, and recognition programs.
  • Regular development and performance conversations, online learning, mentoring programs, and training.
  • Training and onboarding sessions are provided for the role.
  • Respectful and inclusive workplace with support for accessibility accommodations during the interview process.

Hiring process

  • Selected candidates will be contacted to schedule an interview.
  • Application outcomes are communicated by email or phone where possible.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →