Konijn Jobs

Open role

Security Mgt Specialist

HNM Solutions B.V.

IND sponsorAmsterdam

About the role

Languages*

English

Description

Performs ethical hacking, Red Team engagements, and purple teaming activities under supervision with a degree of independence, emphasizing on delivering technical findings, recommending remediation plans, documenting results, and evolving existing tactics.

Do you stay up late at night wondering how organizations actually get hacked in real life?

Do you read about real world breaches and think to yourself, "If that would have been me, I would have done this instead"?

Is it in your nature to think about security controls and how you could find a way around them?

If you answered yes to any of those questions, please continue!

We are seeking an Adversary Emulation Operator to join Swift's Red Team to plan and execute intelligence driven Red Team operations to simulate criminal, nation state and insider threats.

This role goes beyond using automated tools and following typical penetration testing checklists, instead we are seeking a candidate who understands how an attacker thinks and can translate this into repeatable, outcome focused, emulation campaigns designed to identify weaknesses early and improve existing defensive capabilities.

What you'll do

•Develop and execute exploitation scenarios against network, application, mobile, and wireless environments per scoped engagements with little to no supervision.

•Translate threat intelligence into realistic attack scenarios, mapping campaigns to specific threat actor groups•Stay current on emerging offensive security techniques

•Continually evolve existing Tactics, Techniques and Procedures (TTPs) in use by the Red Team to match TTPs used by real world adversaries

•Conduct phishing and OSINT driven social engineering campaigns.

•Develop and refine payloads and attack paths across Swift infrastructure.

•Link technical exploitation to risks associated with the business.

•Conduct physical security assessments to include RF site surveys and attempts to circumvent physical security controls•Share techniques, lessons learned, and tool improvements with peers.

•Support Purple Teaming activities by working closely with the Security Operations Centre (SOC) to identify and help remediate detection gaps.

Competency Profile:

•Deep sense of belonging to and contributing to a team yet can operate independently when necessary across phases of a campaign within different

environments.

•Can chain vulnerabilities to achieve privilege escalation and lateral movement.

•Able to document technical details clearly for senior review.

•Strong knowledge of common technologies within an enterprise environment (e.g. Windows, Active Directory (AD), Linux, cloud environments, etc)

Skills

Able to document technical details clearly for senior review.

Yes

AI tooling usage for Pentesting / Red Teaming

Professional (4-5)

Certified Red Team Operator (CRTO)

Yes

knowledge of common technologies within an enterprise environment (e.g. Windows, Active Directory (AD), Linux, cloud environments, etc).

Professional (4-5)

OffSec Certified Professional (OSCP)

Yes

Penetration Testing

Professional (4-5)

Red Teaming

Professional (4-5)

More open roles at HNM Solutions B.V.