HimalayasHimalayas logo
GuidePoint Security LLCGL

Attack Simulation Engineer- Threat & Attack Simulation- Remote (Anywhere in the

We are cybersecurity practitioners who live and breathe security every day.

GuidePoint Security LLC

Employee count: 501-1000

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Brief Description

GuidePoint Security’s Continuous Security Validation (CSV) offerings combine the benefits of the latest in continuous attack simulation technology with our seasoned team of expert penetration testers and red teamers. As an Attack Simulation Engineer, you will be tasked with the effective operation of industry-leading automated penetration testing platforms to ensure our clients benefit from our unique approach. Additionally, you will identify and validate vulnerability at speed and scale to assist our clients in making meaningful and measurable improvements in their risk posture.

Description

As an Attack Simulation Engineer, you will be a technically adept and reliable team member who leverages your knowledge, skills, and experience to deliver exceptional results to clients for all of the Practice’s professional service offerings and assist with shaping the future of the practice. Your primary responsibilities revolve around performing challenging and complex assessments, mentoring less experienced team members, contributing to the practice’s growth and improvement, assist with pre-sales activities, and assisting with evaluating and onboarding new technologies that may be added to the Practice.

As an Attack Simulation Engineer, you are encouraged to interact with the CSV Leadership Team and contribute to the Practice’s future success. GuidePoint Security’s Continuous Security Validation offering operates in perpetuity in response to emerging threats and diverse client needs. Your creativity and expertise will assist the Practice by adapting to this rapidly changing environment.

Role Requirements

  • Deliver CSV services, including, but not limited to Continual and Coordinated penetration testing, Automated Assessments, Hybrid Assessments, Automated Remote Social Engineering Assessments, and Breach & Attack Simulation Assessments
  • Assist with technical oversight/quality assurance of CSV assessments as needed
  • Author comprehensive assessment deliverables that are proficiently tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies
  • Contribute to marketing initiatives via activities such as publishing research, speaking at industry conferences, authoring blog articles and whitepapers, hosting webinars, and developing security tools
  • Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry
  • Assist in the pre-sales process for both the services and the tools we support, attending and performing demos as required
  • Foster strong client relationships and represent GuidePoint well by providing interactive and collaborative support, information, and guidance to ensure delivery of maximum value
  • Serve as a Subject Matter Expert over one of the Practice’s main offering areas (Remote Social Engineering, Automated Penetration Testing, or Breach & Attack Simulation), including maintaining vendor certifications as they are available
  • Serve as an escalation point for abnormal findings, properly triage, and escalate as needed
  • Maintain situational awareness of the client's technology architecture, known weaknesses, solutions used for monitoring and threat intelligence, and any recent security events
  • Ensure that identified vulnerabilities are promptly validated and thoroughly investigated
  • Devise and document new procedures and runbooks/playbooks as directed
  • Maintain established Service Level Agreements (SLAs)
  • Attend GuidePoint GPSEC conferences as necessary to meet with account executives and clients regarding our services

Education, Credentials, and Experience

  • Familiarity with offensive security tools used for network, host and application security testing
  • Experience in security technologies such as automated penetration testing tools, Breach & Attack Simulation Tools, Security Information and Event Management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint Detection and Response (EDR), Anti-Virus, Sandboxing, network- and host-based firewalls, Threat Intelligence, Virtual Machines, etc.
  • Advanced knowledge of at least one security tool from within the following domains: Automated Penetration Testing and Breach & Attack Simulation (i.e. Horizon3, Pentera, SafeBreach, Picus, etc…)
  • Experienced in client delivery for high-profile clients (i.e. Fortune 100) with utmost professionalism
  • Pentest+ Certification or equivalent, and in pursuit of OSCP (or other lab-based certification)
  • Internal security operations experience is strongly preferred
  • InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience is strongly preferred
  • Minimum of two (2) years of experience in security operations
  • Minimum of one (1) year of experience in performing continual and coordinated penetration testing
  • Minimum of four (4) years working in an IT or IT Security environment

Knowledge, Skills, and Abilities

Technical

  • Assess network security postures for enterprise-level infrastructures by utilizing industry-standard approaches for conducting vulnerability assessments and penetration testing
  • Possess in-depth knowledge of formal assessment methodologies, as well as when to use intuition to creatively deviate from established processes
  • Identify common vulnerabilities through the use of automated tools and practical analysis
  • Identify obscure vulnerabilities by leveraging your expertise through manual analysis
  • Perform safe and reliable exploitation (to the extent possible) for exploitable vulnerabilities
  • Understand network, operating system, and application-based detective and preventative controls and evade and/or circumvent such controls effectively
  • Quickly and efficiently perform post-exploitation activities to demonstrate the impact of compromise
  • Knowledge of common open-source tools, such as Nmap, Metasploit, and the Kali Linux Suite (or equivalent)
  • Proficient with scripting languages, such as Ruby, Python, Bash, PowerShell, etc.
  • Proven ability to write code to solve problems and automate tedious and time-consuming tasks during assessments
  • Proficiency with web application attacks (e.g., OWASP Top 10) is strongly preferred
  • Understanding of modern cloud architectures and common cloud service provider services and offerings
  • Possess a solid understanding of TCP/IP, networking technologies, network segmentation, and vendor-specific technologies, such as Cisco and Juniper
  • Possess a solid understanding of firewall concepts and vendor-specific technologies, such as Cisco, Palo Alto, and Checkpoint
  • Possess a solid understanding of operating systems, such as Microsoft, Linux, and various Unix variants
  • Desire to initiate and conduct research projects
  • Familiarity with automation tools such as Ansible

Business/Professional

  • Strong overall practice knowledge and problem-solving abilities (i.e., ability to handle tricky client/project situations with little to no assistance)
  • Ability to think outside the box when presented with complex problems
  • Contributions to the information security community are strongly preferred, such as conference speaking, blog articles/white papers, and/or podcasts.
  • Prizes continuous improvement and desires to aid with practice development as much as personal growth
  • Possess a desire to mentor and manage other team members and have a passion for sharing knowledge
  • Ability to professionally interact with clients and maintain composure while resolving difficult situations
  • Self-motivated and able to work independently, as well as being a reliable addition to team projects
  • Ability to effectively multitask and efficiently manage time when simultaneously working on multiple projects
  • Possess a firm understanding of the concept of risk as it relates to a business
  • Strong verbal communication skills include clearly articulating thoughts, being persuasive, and delivering presentations and training to technical audiences and all management levels
  • Excellent written communication skills for preparing formal deliverables, performing quality assurance reviews, and technical oversight for peers, proposals, training content, and white papers/blog articles
  • Comfortable interacting with executive management and conveying technical findings in an appropriate business context

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.

Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Education

Professional certificate

Experience

4 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About GuidePoint Security LLC

Learn more about GuidePoint Security LLC and their company culture.

View company profile

We are cybersecurity practitioners who live and breathe security every day. Our team of experts includes veterans from the DoD, Intel Communities and Fortune 500 companies, who hold as many industry and product certifications.

We’ve become the trusted advisor for more than 50% of the cabinet-level agencies in the U.S. Federal Government and a third of Fortune 500 companies. We know offensive and defensive security, and understand both security and compliance. Our goal is to deliver results, “wow” you, and be your partner for the long haul.

Our Values

Take Ownership & Complete the Mission! GuidePoint is only as great of a place to work as we make it. We hold ourselves accountable, become experts and take the initiative to get things done.

“Wow Them!” We strive to be a long-term partner and make our customers’ experience a success, enabling and securing their business. We realize that we all have customers, whether they’re our clients, coworkers, vendors or others.

Always Challenge Yourself & Have Fun Doing It! “You miss 100% of the shots you don’t take,” so we always push ourselves to take calculated risks and exceed our own expectations. We do what’s necessary to “Wow Them,” and we have fun doing it. We realize that only we can control whether or not we’re going to have a great day, so we choose to make it one.

No Jerks! Life is too short to work with jerks, so we treat people with respect and dignity. When we have an issue, we pick up the phone and work constructively to address it. We know we need each other to succeed.

Employee benefits

Learn about the employee benefits and perks provided at GuidePoint Security LLC.

View benefits

Retirement benefits

Access to competitive 401k retirement plans.

Phone & Internet

Generous mobile phone and home internet allowance.

Flexible time off

12 corporate holidays and a Flexible Time Off (FTO) program.

Healthcare benefits

100% employer-paid medical premiums (employee only $0 deductible and HSA plans) along with 75% employer-paid family contributions + 100% employer-paid dental premiums (employee only) along with 75% employer-paid family contributions.

View GuidePoint Security LLC's employee benefits
Claim this profileGuidePoint Security LLC logoGL

GuidePoint Security LLC

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

39 remote jobs at GuidePoint Security LLC

Explore the variety of open remote roles at GuidePoint Security LLC, offering flexible work options across multiple disciplines and skill levels.

View all jobs at GuidePoint Security LLC

Remote companies like GuidePoint Security LLC

Find your next opportunity by exploring profiles of companies that are similar to GuidePoint Security LLC. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan