Wells Fargo - Charlotte, NC

posted 2 months ago

Full-time - Senior
Charlotte, NC
Credit Intermediation and Related Activities

About the position

Wells Fargo is seeking a Senior Lead Cyber Security Research Consultant who will play a pivotal role in investigating existing types of malware, analyzing their capabilities, and predicting new forms of malware to develop appropriate security responses. This position is critical in enhancing the organization's security posture by overseeing the development of red teaming methods and solutions across various domains, including business continuity, emergency management, supply chain security, information security, personnel security, operations security, and facilities security. In this role, you will be responsible for building a mentoring program for the red team and its partners, aimed at developing capabilities around threat emulation, malware and tool creation, and tradecraft. You will act as a senior contributor to the Offensive Security Research Team, providing subject matter expertise on offensive operations, operationalizing threat intelligence, tool development, and tradecraft. Collaboration is key, as you will work closely with blue and purple team partners to trigger incidents and enhance detection effectiveness, fostering relationships among different security groups. Your responsibilities will also include building and maintaining a comprehensive model of relevant, feasible threats to the enterprise, educating senior management on the strengths, weaknesses, opportunities, and threats associated with strategic red teaming, and providing regular threat/risk briefings to senior management. You will present findings within the context of overall risk to the enterprise and adjust red team activities based on senior management input. Additionally, you will work closely with existing infrastructure and security teams to provide practical and actionable intelligence, acting as an adversarial counterpoint to security strategy proposals.

Responsibilities

  • Oversee the development of red teaming methods and solutions across the enterprise.
  • Build a mentoring program for the red team and its partners.
  • Act as a senior contributor to the Offensive Security Research Team.
  • Work closely with blue and purple team partners to trigger incidents and enhance detection effectiveness.
  • Build and maintain a comprehensive model of relevant, feasible threats to the enterprise.
  • Educate senior management on the strengths, weaknesses, opportunities, and threats associated with strategic red teaming.
  • Provide regular threat/risk briefings to senior management regarding issues raised by the red team.
  • Work closely with existing infrastructure and security teams to provide practical and actionable intelligence.
  • Act as an adversarial counterpoint to security strategy proposals.

Requirements

  • 7+ years of Cyber Security Research experience, or equivalent demonstrated through work experience, training, military experience, or education.
  • 7+ years of experience in briefing senior level executives and key stakeholders around red team activities.
  • 7+ years of information security reporting and analysis experience.
  • 5+ years of experience in reporting, analytics, or modeling in an information security environment, information technology environment, or a combination of both.

Nice-to-haves

  • 7 years of experience conducting red team assessments of high-consequence systems.
  • Understanding of MITRE ATT&CK framework.
  • Experience with Burp Suite, Crowdstrike, Splunk, Chronicle, EDR solutions.
  • Thorough understanding of concepts and principles related to security, strategy, management, and intelligence analysis.
  • Ability to work productively with a variety of stakeholders within the enterprise.
  • Ability to work with and against internal resistance and build consensus for red teaming within the enterprise.
  • Ability to think and act both strategically and tactically, theoretically, and pragmatically.
  • OSCP certification or other similar related security certifications.
  • Google Cloud Platform and Azure certifications.

Benefits

  • Hybrid work schedule
  • Diversity, equity, and inclusion initiatives
  • Employee support programs
  • Risk and compliance training
  • Professional development opportunities
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service