Himalayas logo
Rapid7RA

Vector Command Specialist (Penetration Testing)

Rapid7 is a cybersecurity company providing data security and analytics solutions, including vulnerability management, incident detection and response, application security, and cloud security. Founded in 2000, the company aims to help organizations reduce risk and eliminate threats across modern IT environments.

Rapid7

Employee count: 1001-5000

Salary: 89k-121k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

As a Vector Command Specialist, you will work with a team of offensive security consultants to help clients improve their security posture through your technical skills and knowledge of attack surface management strategies. You will serve as an entry-level technical analyst and customer liaison. You will also work with various Managed Services teams to help deliver monthly reports to customers, address customer needs, and assist with other security consultant deliverables.

About the Role

Your primary responsibility will be to support Vector Command customers by conducting external attack surface analysis, exposure reconnaissance, account and tool integrations, preparing monthly red team report deliverables, and prioritizing customer requests. You will work daily with Rapid7’s Vector Command Red Team operators, assisting with ongoing red team exercises and staying up to date on the latest vulnerabilities, customer attack surface changes, and exposures within customer environments.

Customer Facing Responsibilities:

  • Onboard customers to the Vector Command platform and technologies.

  • Oversee and ensure the completeness of customer report deliverables.

  • Serve as the primary point of contact for customer inquiries related to testing operations, alerts, or general Vector Command questions associated with Red Team activities.

  • Coordinate and host monthly Vector Command Red Team update calls in conjunction with a Rapid7 Red Team lead.

  • Translate technical concepts and communicate them effectively to non-security personnel.

  • Coordinate communications between internal Rapid7 services on behalf of customers, including the Managed Detection and Response (MDR) and Managed Vulnerability Management (MVM) teams.

  • Provide monthly written summaries of each customer’s attack surface and Vector Command Red Team operations.

Attack Surface Analyst, Internal Red Team:

  • Analyze each customer’s exposures and attack surface within the Vector Command platform.

  • Conduct manual network and service reconnaissance to identify new exposures.

  • Perform Open-Source Intelligence (OSINT) gathering on customers to identify attack surface elements that extend beyond traditional network services.

  • Keep the Red Team informed of significant changes in customers’ attack surfaces.

  • Coordinate customer requests and prioritizations with the Red Team operators.

  • Develop scripts to query and analyze attack surface data from numerous sources and automated systems.

  • Perform entry level penetration testing activities against external assets, as assigned by the Red Team lead.

The skills and qualities you’ll bring include:

  • 3+ years in an active technical security role.

  • Excellent written and verbal communication skills.

  • Previous technical security consulting experience.

  • Knowledge of modern penetration testing tools and methods.

  • Knowledge of external attack surface reconnaissance techniques to identify customer’s internet facing exposures.

  • Strong knowledge of network, web-based application, and IEEE 802.11 security concepts.

  • Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite.

  • Experience using scripting languages such as Python and PowerShell

  • Experience with social engineering techniques and tactics related to reconnaissance and OSINT gathering.

  • A Bachelor’s degree in Computer Science, MIS, CIS or a related field, or equivalent experience.

  • Certifications such as GPEN, PJPT, PNPT, CPTS, or OSCP are preferred.

  • The ability to ask for help.

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

About Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome.

Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ ve been doing for the past 20 years. If you ’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.

The salary range for this role in the US is:

$89,300.00 - 120,800.00 USD Annual

Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Salary

Salary: 89k-121k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Rapid7

Learn more about Rapid7 and their company culture.

View company profile

Founded in 2000 by Alan Matthews, Tas Giakouminakis, and Chad Loder, Rapid7 embarked on a mission to provide innovative cybersecurity solutions. The company was established with the vision of helping organizations effectively detect and respond to security threats. Alan Matthews brought his extensive cybersecurity expertise, Tas Giakouminakis provided the technical software development knowledge, and Chad Loder contributed his entrepreneurial vision to shape the company's strategic direction. What began as a focused endeavor to address the evolving landscape of cyber threats has grown into a global leader in vulnerability management and incident detection. Over the years, Rapid7 has consistently pushed the boundaries of security technology through innovation and strategic partnerships. A key milestone in their journey was the launch of Nexpose, their flagship vulnerability management solution, in 2007. This was followed by the strategic acquisition of Metasploit, a renowned open-source penetration testing tool, in 2010, significantly expanding their product portfolio. The company's growth trajectory continued, leading to its initial public offering (IPO) on the NASDAQ stock exchange in 2012 (though another source indicates 2015). In 2015, Rapid7 further enhanced its threat detection capabilities by acquiring Logentries, a provider of cloud-based log management and analytics solutions. The introduction of InsightIDR in 2018, a cloud-based SIEM solution, marked another significant step in empowering organizations to detect and respond to security incidents in real-time.

Today, Rapid7 is a leading cybersecurity solutions provider, dedicated to making successful security tools and practices accessible to all. Their Insight Platform technology, expert services, and thought-leading research enable over 9,000 customers worldwide to improve their security programs and innovate safely. As technology continues to advance rapidly, every company has essentially become a technology company, inherently creating new security risks. The migration to the cloud and the proliferation of connected devices present security teams with an increasingly complex and unpredictable attack surface. Rapid7 believes that as cybersecurity challenges escalate, two primary factors hinder organizations from effectively managing their security exposure: the complexity of security tools and the scarcity of qualified cybersecurity professionals to manage them. These challenges are compounded for resource-constrained organizations. Rapid7 aims to bridge this 'Security Achievement Gap' by simplifying complex security problems. Their solutions empower teams to more effectively reduce vulnerabilities, monitor malicious behavior, investigate and shut down attacks, and automate routine tasks. This is all supported by a dedicated team of security researchers and consultants who bring real-world attacker behavior knowledge and emerging vulnerability insights directly to their customers. Headquartered in Boston, Massachusetts, Rapid7 operates globally, serving a diverse range of industries including technology, energy, financial services, healthcare, and government.

Claim this profileRapid7 logoRA

Rapid7

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

10 remote jobs at Rapid7

Explore the variety of open remote roles at Rapid7, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Rapid7

Remote companies like Rapid7

Find your next opportunity by exploring profiles of companies that are similar to Rapid7. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan