Talent.com
Intact Financial Corporation
Security Advisor Specialist, Offensive Security (Global Red Team)Intact Financial Corporation • Mississauga, Ontario, CAN
Security Advisor Specialist, Offensive Security (Global Red Team)

Security Advisor Specialist, Offensive Security (Global Red Team)

Intact Financial Corporation • Mississauga, Ontario, CAN
Il y a plus de 30 jours
Salaire
118 700,00 $CA par an
Type de contrat
  • Temps plein
Description de poste

Pay at Intact is about much more than just salary.

  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.


About the role

The Security Specialist, Offensive Security is responsible for testing the security controls, the network, and threat response for Intact Financial globally (All regions and all affiliate companies). He/she works as a specialist employing techniques, tactics and protocols to test security controls, working as part of a global offensive security team.

The Specialist, Offensive Security reports to the Director, Offensive Security and works with a team of technical advisors across multiple locations and time zones.

If you can think outside of the Kali box, and love to think like an attacker (with a track record to prove your capabilities) we want to talk to you about joining our team!


What you'll do here:

  • Conduct reconnaissance on network environment to build external landscape using industry standard tools, threat intelligence feeds, OSINT and other readily available information sources

  • Conduct offensive security testing to ensure security controls and response actions are effective. If you are detected, shifting from a red team focus to a purple team approach – your purpose isn’t to create a “Gotcha!” moment – our mission is to strengthen our controls throughout the entire attack chain across the enterprise.

  • Employ attack strategies to simulate real-world attacks by threat actors and benchmark response capabilities across the enterprise.

  • Ability to identify and exploiting vulnerabilities in computer systems, networks and applications to simulate attacks by threat actors – you have a proven track record of evading modern EDR (eg. Crowdstrike, MDE, SentinelOne) while elevating privileges/hitting your target.

  • Analyze and report on the results of security assessments and make recommendations to improve the security posture of the enterprise.

  • You understand the TCP/IP stack in depth and know how to exploit it to create covert beacons, C2 channels, exfiltrate data across DNS. Understanding how routing tables work (eg. BGP) and how they can be exploited is an asset.

  • Work with regional cyber governance and risk teams to ensure that findings are properly tracked for remediation

  • Generate the required metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness

  • Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark regions and affiliate companies to peers.

  • Able to consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development, proposing clear rules of engagement for testing activities (either one time or perpetual) and ensuring compliance to the ROE through all phases of testing.

  • Maintain and update all offensive security tools, technologies and processes in line with company rules of engagement

  • Provide timely and effective communications to key internal stakeholders in alignment with policy and rules of engagement.


What you bring to the table:

  • Advanced knowledge in the following areas: computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, Threat intelligence, Incident Response, technical writing, information risk.

  • Bachelor's degree in Computer Technology, Information Security, an asset.

  • A minimum of five (5) years of relevant professional experience in information technology.

  • A minimum of three (3) years of experience in information security.

  • Knowledge of offensive security operations, tools and techniques.

  • Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001), an asset.

  • Python scripting comes naturally, and have a history of using it in blue/red/purple team engagements

  • Proficiency in manual testing techniques beyond automated scanning.

  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.

  • You can take many vectors of technical vulnerability information (Pentest reports, vulnerability scanning data, SAST/DAST reports) and build an attack plan on critical assets.

  • You must have the ability to take highly technical data and results and translate them to business-friendly language to help non-technical stakeholders understand the approach, impact and outcome from offensive security operations.

  • If you’ve joined capture the flag competitions (even better if you won) we want to hear about it!

  • Recognized certification in information security (CEH, CISM or other), an asset.

  • Analytical mind, pragmatic approach to IT security issues and problems.

  • Strong partner in all areas, internally and externally, to provide a secure solution.

  • Ability to reduce stress in situations that are stressful to you and others.

  • Positive attitude, initiative with strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.

  • Ability to write and present material to communicate difficult concepts and gain consensus.

  • Ability to work in a dynamic environment with multiple objectives.

  • Highly motivated and self-directed, with attention to detail.

  • Ability to prioritize and execute tasks in a high-pressure environment.

  • Ability to deal diplomatically and effectively at all levels of the organization.

  • Ability to challenge the status quo.

  • Customer focused approach.

  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country.

  • No Canadian work experience required however must be eligible to work in Canada.

#LI-Hybrid

Il s'agit d'un nouveau rôle au sein de notre équipe en plein croissance | This role is a new member of our growing team.
Créer une alerte emploi pour cette recherche

Security Advisor Specialist, Offensive Security (Global Red Team) • Mississauga, Ontario, CAN

Offres similaires

Senior Offensive Security Consultant & Red Team Lead

CDW CanadaVaughan, York Region, CA
Temps plein

A leading technology solutions provider in Vaughan, Ontario is seeking a Cyber Security Consultant to conduct penetration testing and provide clients with security insights.Candidates should have o... Voir plus

 • Offre sponsorisée

Cloud Security Advisor Manager Role

BDO CanadaOakville
Temps plein

Join BDO as a Cloud Security Manager and lead transformative security practices across cloud ecosystems.Oversee technical delivery and team performance for high-impact client engagements.As a Cloud... Voir plus

 • Offre sponsorisée

40104: Advisor-Security

FedEx-FreightMississauga, Peel region, Canada
Temps plein

Responsible for safeguarding company employees, assets, property and customers’ freight while in the possession of FedEx Freight Canada (FFC).Reduce losses attributed to theft by proactive preventi... Voir plus

 • Offre sponsorisée

Av Security Solutions Sales Specialist

CanadiansmartsystemsMississauga, Canada
Temps plein +1

At Canadian Smart Systems, we take pride in being at the forefront of innovation, bringing the latest in AV-IT technology to some of the finest homes and businesses in the Greater Toronto Area.Our ... Voir plus

 • Offre sponsorisée

Security Specialist - Siem Technologies

CDWMississauga, Canada
Temps plein

Description The Specialist provides second-level Cybersecurity Incident Response, client support and upholds defined service level agreements (SLA) and customer service excellence for Information S... Voir plus

 • Offre sponsorisée

Product Owner - Security Team

Intact Financial CorporationMississauga
Temps plein

Pay at Intact is about much more than just salary.Multiple benefits offered to support.Wellness account and much more.Share plan & other savings: up to.Employee Share Purchase Plan (ESPP) – with In... Voir plus

 • Offre sponsorisée

Offensive Security Lead

Software SecuredMississauga, Peel Region, CA
Temps plein

This role sits at the intersection of.You’ll work closely with Sales, Product, and Leadership to support scoping, improve delivery processes, and help evolve our service offerings as the business s... Voir plus

 • Offre sponsorisée

Professional Services Specialist (Enterprise Physical Security Systems) - oakville

SOLOSQUIDoakville, on, ca
Temps plein

Professional Services Specialist (Enterprise Security Systems).SoloSquid is a professional services firm that works with enterprise clients to deploy, optimize, and maintain advanced security syste... Voir plus

 • Offre sponsorisée

Security Risk Advisor - Insight Global

Insight Globalmississauga, on, ca
Temporaire

Month Contract + High Possibility of extensions.Onsite: 2 Days/week Toronto, Ontario - 3 Days Remote.I am reaching out because I am hiring for a security risk advisor for the Information Security t... Voir plus

 • Offre sponsorisée

Global Trade Director, Defence & Security

Export Development Canada | Exportation et développement CanadaMississauga, Peel region, Canada
Permanent

At EDC, we support Canadian businesses to succeed globally.We provide the financial tools and expertise they need to explore new markets, reduce risks, all towards the goal of making Canada and the... Voir plus

 • Offre sponsorisée

Sr Security Professional

Honeywell Aerospace TechnologiesMississauga
Temps plein

Join a team recognized for leadership, innovation, and diversity.When you join Honeywell Aerospace, you become a member of our global team of thinkers, innovators, dreamers, and doers who make the ... Voir plus

 • Offre sponsorisée

Workday Security Specialist in Hybrid Role

EllisDon CorporationMississauga
Temps plein

Secure sensitive data as a Workday Security Specialist at EllisDon with a hybrid work model.You'll implement advanced security configurations and monitor for potential threats.At EllisDon, we are l... Voir plus

 • Offre sponsorisée

Cyber Security Specialist - XSOAR

TryApplyNowMississauga, Ontario, Canada
Temps plein

Cyber Security Specialist - XSOARBell CyberFull TimemidMississauga, Ontario, CAPosted 19 days ago## Job DescriptionWe are looking for an experiencedCybersecurity Specialist - XSOAR to join our team... Voir plus

 • Offre sponsorisée

Principal Cybersecurity Advisor - Remote Opportunity

NerdleveltechMississauga, Peel Region, CA
Télétravail
Temps plein

Elevate your career at Optiv as a remote Principal Cybersecurity Advisor, focusing on Offensive Security strategies tailored for each client.Your expertise will help drive transformational security... Voir plus

 • Offre sponsorisée

CTPAT/PIP Security Specialist

McCain FoodsBrampton, Ontario, Canada
Temps plein

CPAT/PIP Security Specialist Full-time Winnipeg, MB OR Brampton, ON As a.CTPAT/PIP Security Specialist , your responsibility will be to create and implement supply chain security programs that meet... Voir plus

 • Offre sponsorisée

Security Associate, M&A & Partnerships

KrakenMississauga, Peel region, Canada
Temps plein

Our Krakenites are a world‑class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission‑focused company roote... Voir plus

 • Offre sponsorisée

Oakville Outside Sales Advisor

Blue-Pencil Business Services Inc.Oakville, ON, CA
Temps plein

Drive local sales as an Outside Sales Advisor at Blue-Pencil Inc.This hybrid role empowers you to be a trusted resource for businesses while earning a competitive salary and commission.Ontario, and... Voir plus

 • Offre sponsorisée

Senior SAP Authorization Specialist for Remote Security Management

Cpus Engineering Staffing Solutions Inc.Mississauga, Peel Region, CA
Télétravail
Temps plein

Drive secure access management as a Senior SAP Authorization Specialist in a fully remote environment.Leverage extensive SAP security expertise to implement user roles and ensure compliance effecti... Voir plus

 • Offre sponsorisée

Security Systems Field Technical Lead

ConvergintMississauga, Ontario, Canada
Temps plein

Convergint is currently looking for a Security Field Technical Lead to join our amazing culture in our Toronto location.As a Security Field Technical Lead, you will be responsible for installation,... Voir plus

 • Offre sponsorisée

Senior Specialist in Digital Workplace Security

PSP’s Private Debt & Credit Investment (PDCI) groupMississauga, Peel Region, CA
Temps plein

Advance your expertise as a Senior Specialist in Digital Workplace Security, focusing on GenAI.Ensure compliance while leveraging Microsoft 365 technologies to improve service quality.In this strat... Voir plus