Talent.com
Security Advisor Specialist, Offensive Security (Global Red Team)
Security Advisor Specialist, Offensive Security (Global Red Team)Intact Financial Corporation • Ottawa, Ontario, CAN
Security Advisor Specialist, Offensive Security (Global Red Team)

Security Advisor Specialist, Offensive Security (Global Red Team)

Intact Financial Corporation • Ottawa, Ontario, CAN
30+ days ago
Job type
  • Full-time
Job description

Pay at Intact is about much more than just salary.

  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.


About the role

The Security Specialist, Offensive Security is responsible for testing the security controls, the network, and threat response for Intact Financial globally (All regions and all affiliate companies). He/she works as a specialist employing techniques, tactics and protocols to test security controls, working as part of a global offensive security team.

The Specialist, Offensive Security reports to the Director, Offensive Security and works with a team of technical advisors across multiple locations and time zones.

If you can think outside of the Kali box, and love to think like an attacker (with a track record to prove your capabilities) we want to talk to you about joining our team!


What you'll do here:

  • Conduct reconnaissance on network environment to build external landscape using industry standard tools, threat intelligence feeds, OSINT and other readily available information sources

  • Conduct offensive security testing to ensure security controls and response actions are effective. If you are detected, shifting from a red team focus to a purple team approach – your purpose isn’t to create a “Gotcha!” moment – our mission is to strengthen our controls throughout the entire attack chain across the enterprise.

  • Employ attack strategies to simulate real-world attacks by threat actors and benchmark response capabilities across the enterprise.

  • Ability to identify and exploiting vulnerabilities in computer systems, networks and applications to simulate attacks by threat actors – you have a proven track record of evading modern EDR (eg. Crowdstrike, MDE, SentinelOne) while elevating privileges/hitting your target.

  • Analyze and report on the results of security assessments and make recommendations to improve the security posture of the enterprise.

  • You understand the TCP/IP stack in depth and know how to exploit it to create covert beacons, C2 channels, exfiltrate data across DNS. Understanding how routing tables work (eg. BGP) and how they can be exploited is an asset.

  • Work with regional cyber governance and risk teams to ensure that findings are properly tracked for remediation

  • Generate the required metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness

  • Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark regions and affiliate companies to peers.

  • Able to consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development, proposing clear rules of engagement for testing activities (either one time or perpetual) and ensuring compliance to the ROE through all phases of testing.

  • Maintain and update all offensive security tools, technologies and processes in line with company rules of engagement

  • Provide timely and effective communications to key internal stakeholders in alignment with policy and rules of engagement.


What you bring to the table:

  • Advanced knowledge in the following areas: computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, Threat intelligence, Incident Response, technical writing, information risk.

  • Bachelor's degree in Computer Technology, Information Security, an asset.

  • A minimum of five (5) years of relevant professional experience in information technology.

  • A minimum of three (3) years of experience in information security.

  • Knowledge of offensive security operations, tools and techniques.

  • Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001), an asset.

  • Python scripting comes naturally, and have a history of using it in blue/red/purple team engagements

  • Proficiency in manual testing techniques beyond automated scanning.

  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.

  • You can take many vectors of technical vulnerability information (Pentest reports, vulnerability scanning data, SAST/DAST reports) and build an attack plan on critical assets.

  • You must have the ability to take highly technical data and results and translate them to business-friendly language to help non-technical stakeholders understand the approach, impact and outcome from offensive security operations.

  • If you’ve joined capture the flag competitions (even better if you won) we want to hear about it!

  • Recognized certification in information security (CEH, CISM or other), an asset.

  • Analytical mind, pragmatic approach to IT security issues and problems.

  • Strong partner in all areas, internally and externally, to provide a secure solution.

  • Ability to reduce stress in situations that are stressful to you and others.

  • Positive attitude, initiative with strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.

  • Ability to write and present material to communicate difficult concepts and gain consensus.

  • Ability to work in a dynamic environment with multiple objectives.

  • Highly motivated and self-directed, with attention to detail.

  • Ability to prioritize and execute tasks in a high-pressure environment.

  • Ability to deal diplomatically and effectively at all levels of the organization.

  • Ability to challenge the status quo.

  • Customer focused approach.

  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country.

  • No Canadian work experience required however must be eligible to work in Canada.

#LI-Hybrid

Il s'agit d'un nouveau rôle au sein de notre équipe en plein croissance | This role is a new member of our growing team.
Create a job alert for this search

Security Advisor Specialist Offensive Security Global Red Team • Ottawa, Ontario, CAN

Similar jobs
Senior Offensive Security Consultant - Pen Test & Red Team

Senior Offensive Security Consultant - Pen Test & Red Team

MNP • Ottawa
Full-time
A leading consulting organization in Canada is seeking a Senior Consultant in the Cyber Security & Privacy team.The candidate will conduct penetration tests, vulnerability assessments, and support ...Show more
Last updated: 1 day ago • Promoted
National Sector Lead, Security & Defense

National Sector Lead, Security & Defense

WSP • Ottawa
Full-time
National Sector Lead, Security & Defense.NATIONAL MARKET SECTOR LEAD Security & Defence.Location: Preference for Ottawa based.Architecture has the power to transform, to unite and to inspire.It is ...Show more
Last updated: 30+ days ago • Promoted
COMSEC and Security Specialist

COMSEC and Security Specialist

Telesat • Ottawa
Full-time
Telesat (Nasdaq and TSX: TSAT) is a leading global satellite operator, providing reliable and secure satellite-delivered communications solutions worldwide to broadcast, telecommunications, corpora...Show more
Last updated: 7 days ago • Promoted
Financial Security Advisor

Financial Security Advisor

Desjardins • Outaouais
Full-time
Our network of more than 200 financial security advisors working at different Desjardins caisses plays a key role in the industry.We're currently expanding this great team and have many opportuniti...Show more
Last updated: 1 day ago • Promoted
Security Operations Manager - ottawa

Security Operations Manager - ottawa

Orion Innovation • ottawa, on, ca
Full-time
Must be eligible for up to a Top-Secret Security Clearance.We are seeking a strategic and hands-on.Trust & Security operational functions.You will be responsible for the vision, governance, and per...Show more
Last updated: 12 hours ago • Promoted • New!
Security Specialist - Threat Risk Assessment - Senior - Russell Tobin

Security Specialist - Threat Risk Assessment - Senior - Russell Tobin

Russell Tobin • ottawa, on, ca
Full-time
Job Title: Security Specialist - Threat Risk Assessment - Senior.Location: Toronto, Onsite 56 Wellesley.Duration: 12+ Months (Possible Extension).Senior Information Security and Privacy Specialist ...Show more
Last updated: 21 days ago • Promoted
Senior Security Systems Lead: CCure, Genetec & Avigilon

Senior Security Systems Lead: CCure, Genetec & Avigilon

Convergint • Ottawa
Full-time
A leading security solutions firm in Ottawa is seeking a Senior Security Systems Specialist.This role focuses on analyzing, operating, and maintaining IT-based Physical Security Systems, requiring ...Show more
Last updated: 30+ days ago • Promoted
Professional Services Specialist (Enterprise Physical Security Systems)

Professional Services Specialist (Enterprise Physical Security Systems)

SOLOSQUID • ottawa, on, ca
Full-time
Professional Services Specialist (Enterprise Security Systems).SoloSquid is a professional services firm that works with enterprise clients to deploy, optimize, and maintain advanced security syste...Show more
Last updated: 12 hours ago • Promoted • New!
Financial Crimes Risk Advisor - Global Trade

Financial Crimes Risk Advisor - Global Trade

Export Development Canada | Exportation et développement Canada • Ottawa
Full-time +1
A leading Canadian financial institution is seeking a Risk Advisor specializing in Financial Crimes to join their team in Ottawa.The role involves applying a risk-based approach to identify and mit...Show more
Last updated: 1 day ago • Promoted
Senior Network Security Engineer – HPE Aruba SSE - ottawa

Senior Network Security Engineer – HPE Aruba SSE - ottawa

Ateko, backed by Bell Canada • ottawa, on, ca
Temporary
Job Title: Senior Network Security Engineer – HPE Aruba SSE.We are looking for a Senior Network Security Engineer with strong hands-on expertise in HPE Aruba Secure Service Edge (SSE) deployments.T...Show more
Last updated: 21 days ago • Promoted
Site Security Lead – Ottawa

Site Security Lead – Ottawa

EBC Inc. • Ottawa
Full-time
For more than 50 years, the building team has given life to countless construction projects, distinguished by the high quality of their work, meeting the highest standards in the industry and seeki...Show more
Last updated: 24 days ago • Promoted
Strategic Industry Advisor

Strategic Industry Advisor

Softchoice • Ottawa
Full-time
A leading IT solutions provider in Ottawa is looking for an Industry Advisor to support Shared Services Canada.In this hybrid role, you will empower sales teams through strategic guidance and clien...Show more
Last updated: 1 day ago • Promoted
Junior Network Security Consultant

Junior Network Security Consultant

ROSS • Ottawa
Full-time +1
It is possible that this contract will be extended.Minimum one year Network Security Experience.Comfortable working with Lotus Notes.Certified Security Professional.Firewall Certification (one of t...Show more
Last updated: 30+ days ago • Promoted
Security Site Manager (Mon-Fri) – Lead Team & Service

Security Site Manager (Mon-Fri) – Lead Team & Service

Paladin Security Group Ltd • Ottawa
Full-time
A security services company in Ottawa is seeking a full-time Site Manager to oversee security operations at Minto Place.Responsibilities include liaising with clients, managing the security team, a...Show more
Last updated: 1 day ago • Promoted
Security Specialist - Threat Risk Assessment - Senior - ottawa

Security Specialist - Threat Risk Assessment - Senior - ottawa

Russell Tobin • ottawa, on, ca
Full-time
Job Title: Security Specialist - Threat Risk Assessment - Senior.Location: Toronto, Onsite 56 Wellesley.Duration: 12+ Months (Possible Extension).Senior Information Security and Privacy Specialist ...Show more
Last updated: 21 days ago • Promoted
Project Security Advisor

Project Security Advisor

Thales • Ottawa
Full-time
Location: Ottawa, Canada In fast changing markets, customers worldwide rely on Thales.Thales is a business where brilliant people from all over the world come together to share ideas and inspire ea...Show more
Last updated: 11 hours ago • Promoted • New!
Strategic DND Industry Advisor | Hybrid, Ottawa

Strategic DND Industry Advisor | Hybrid, Ottawa

World Wide Technology • Ottawa
Full-time
A leading technology solutions provider is seeking an Industry Advisor located in Ottawa, Canada, to support the Department of National Defence.This role requires a seasoned professional with a min...Show more
Last updated: 14 days ago • Promoted
Professional Services Specialist (Enterprise Physical Security Systems) - ottawa

Professional Services Specialist (Enterprise Physical Security Systems) - ottawa

SOLOSQUID • ottawa, on, ca
Full-time
Professional Services Specialist (Enterprise Security Systems).SoloSquid is a professional services firm that works with enterprise clients to deploy, optimize, and maintain advanced security syste...Show more
Last updated: 12 hours ago • Promoted • New!