远程工作雷达

高级红队操作员

Senior Red Team Operator

开发工程职能支持限定地区(需当地身份)日间重叠仅 1 小时,需熬夜配合
公司Barclays
薪资未公开
工作地点United Kingdom
地域资格限定地区(需当地身份)
时区要求日间重叠仅 1 小时,需熬夜配合
用工类型Full Time
发布时间2 天前
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United Kingdom 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠仅 1 小时,需熬夜配合。

职位描述
职位目的
使用渗透测试工具和技术,识别银行IT系统中的潜在漏洞,以确保计算机系统、应用程序、服务器和网络的安全性。

职责

  • 开发并执行评估、审计和威胁模型,使用渗透测试工具和技术识别银行系统、应用程序和服务器中的漏洞,并向相关方传达关键发现和建议。
  • 与相关方和IT团队合作,识别新兴的网络攻击技术、工具和新技术,并支持渗透测试方法的开发。
  • 编写和维护全面的文档和报告,向高级相关方汇报渗透测试结果及修复指导。
  • 与相关方合作,了解其在业务流程、应用/服务中的安全需求和控制措施,以提升整体安全态势和保障。
  • 识别新兴漏洞、利用代码和网络攻击,以开发测试方法和保障活动。

副总裁期望

  • 贡献或制定战略,推动需求并提出改进建议。规划资源、预算和政策;管理并维护政策/流程;推动持续改进,并上报政策/流程违规情况。
  • 如果管理团队,他们将定义岗位和职责,规划部门未来的需求和运营,对员工绩效进行辅导,并参与员工薪酬决策/变更。他们还可能领导多名专家,以影响部门的运营,在符合战略和战术优先事项的同时,平衡短期和长期目标,并确保预算和进度符合公司要求。
  • 如果该职位有领导职责,人员领导者需要展示明确的领导行为,为同事创造一个能够茁壮成长并持续达到优秀标准的环境。四个LEAD行为是:L – 倾听并保持真实,E – 激励并鼓舞,A – 在企业范围内保持一致,D – 培养他人。
  • 或者对于个人贡献者,他们将在自己的专业领域内成为专家,并指导技术方向。他们将主导协作性的多年项目,并指导团队成员通过结构化的方式完成任务。
查看英文原文

Job Description
Purpose of the role
To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities

  • Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
  • Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
  • Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
  • Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
  • Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.

Vice President Expectations

  • To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and escalate breaches of policies/procedures..
  • If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others..
  • OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
  • Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
  • Manage and mitigate risks through assessment, in support of the control and governance agenda.
  • Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
  • Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies.
  • Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
  • Adopt and include the outcomes of extensive research in problem solving processes.
  • Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
We’re looking for a Senior Red Team Operator to join a skilled, close-knit team that genuinely loves this work. You’ll plan and lead full-scope Red Team operations – cyber, physical, social engineering, and everything in between – emulating real-world adversaries to test how our defences actually hold up under pressure. When you find the gaps, you’ll help close them.
This is a hands-on role for someone who’s happiest with a shell, a payload, and a hard target. You’ll have real autonomy over how you approach engagements, time to research new tradecraft, and a team of talented operators who’ll look to you to set the technical standard, pressure-test their thinking, and lead from the front.
What you’ll be doing

  • Scoping and leading full-scope Red Team engagements against well-defined adversarial objectives across cyber, physical, social engineering, and process attack surfaces.
  • Leading on methodology: shaping how the team scopes, runs and reports engagements and driving continuous improvement in how you all operate.
  • Designing and delivering phishing and social engineering campaigns end to end – standing up the supporting infrastructure (domains, redirectors, mail and landing-page servers), crafting convincing pretexts, and developing the accompanying payloads to emulate realistic threat-actor delivery.
  • Operating and tuning Command and Control frameworks (e.g. Cobalt Strike, Nighthawk, or equivalent) through initial access, post-exploitation, and lateral movement.
  • Developing custom tooling, tradecraft, and EDR / defence-evasion techniques to emulate realistic threat actors.
  • Turning engagements into clear, compelling attack narratives – the kind that land with both the engineers who’ll fix the issues and the executives who need to understand the risk.
  • Contributing to detection and resilience improvements through close collaboration with defensive teams.
  • Researching emerging TTPs. Threats, and tooling, and bringing new techniques into the team’s methodology.
  • Setting the technical bar and mentoring across the team – coaching operators, reviewing tradecraft, and helping develop the next generation of Red Team talent.

Some other highly valued skills may include:

  • Certifications like CRTO, OSCP / OSEP, CRTP or CREST (CCSAS / CCRTS) welcome, but your hands-on ability matters far more than acronyms.
  • Proficiency in at least one coding language.
  • Demonstrated ability to solve complex and challenging technical problems.

You will be assessed on key critical skills relevant for success in role, such as job-specific technical skills.
This role is fully remote role with occasional travel required.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

红队操作员

BarclaysUnited KingdomFull Time2 天前
开发工程职能支持限定地区(需当地身份)日间重叠仅 1 小时,需熬夜配合

← 返回全部职位