Назад
Company hidden
8 часов назад

Red Team - Sr Security Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Red Team - Sr Security Engineer (Cybersecurity): Designing and executing red team engagements and adversary emulation against enterprise systems, cloud environments, and applications with an accent on offensive security, detection coverage, and AI-assisted security operations. Focus on executing full attack lifecycles, testing cloud and AI-enabled applications, developing security tooling, and translating findings into prioritized remediation guidance.

Location: Overland Park, Kansas, United States; onsite. Applicants for U.S.-based positions must be legally authorized to work in the United States.

Company

hirify.global develops healthcare technology and provides software and services for healthcare organizations.

What you will do

  • Design, scope, and execute red team engagements and adversary emulation exercises across enterprise systems, cloud environments, and web applications.
  • Execute attack lifecycles covering reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
  • Partner with detection engineering to identify gaps and improve SIEM, DLP, EDR, SAST, and SCA configurations and workflows.
  • Implement security controls, system hardening, vulnerability remediation, secure software development practices, and cloud security measures.
  • Support incident response, including detection, containment, resolution, notification, and escalation.
  • Provide actionable security guidance to engineering, IT, and executive stakeholders, including business risk and prioritized remediation.

Requirements

  • Bachelor's degree in a related field or equivalent experience, with 4–6 years of related work experience.
  • At least 2 years of offensive security experience in penetration testing, red teaming, adversary emulation, or purple teaming.
  • Experience with MITRE ATT&CK, Burp Suite, Nmap, Metasploit, BloodHound, Impacket, and at least one command-and-control framework such as Cobalt Strike, Sliver, or Mythic.
  • Cloud attack and defense experience in AWS, Azure, or GCP, including IAM abuse paths, misconfiguration exploitation, logging, and cloud-native controls.
  • Daily experience with AI assistants and agentic coding tools such as Claude Code, GitHub Copilot, or Cursor, plus practical prompt engineering and validation of AI-generated output.
  • Must be legally authorized to work in the United States. Must follow security policies for safeguarding company and client information and be able to work additional or irregular hours when needed.

Nice to have

  • Detection engineering, purple team collaboration, malware analysis, reverse engineering, payload development, or EDR evasion experience.
  • Active Directory and Microsoft Entra ID security, container and Kubernetes security, CI/CD or software supply chain testing, and application security experience.
  • AI and LLM application security testing, including prompt injection, jailbreaks, insecure output handling, data leakage, and agent or tool abuse.
  • Knowledge of OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, HIPAA, HITRUST CSF, SOC 2, NIST 800-53, or the NIST Cybersecurity Framework.
  • Offensive, cloud, or general security certifications such as OSCP, OSEP, OSWE, CRTO, GPEN, GXPN, PNPT, CISSP, GCIH, or GCIA.

Culture & Benefits

  • Collaborative and inclusive work environment focused on innovation and independent thinking.
  • Medical, prescription, dental, and vision benefits for eligible full-time employees.
  • Mental health support through an employee assistance program.
  • Paid time off and 13 paid holidays.
  • 100% vested 401(k) retirement plan and educational assistance of up to $2,500 per year.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →