Cyber Defense - Red Team Operator / Security Tester at UBS Group AG
UBS Group AG · Raleigh, United States Of America · Onsite
- Professional
- Office in Raleigh
Your role
We are looking for a Cyber Defense Operational Security Testing Red Team Operator / Security Tester to:
• join a growing in-house red teaming and offensive security capability
• execute all phases of offensive security operations participating in both red and purple team testing
• develop scripts, tooling, and methodologies to support offensive security capabilities.
• assist in providing risk appropriate and pragmatic recommendations to correct identified findings, vulnerabilities, and misconfigurations
• understand and adhere to regulatory, compliance, and legal requirements that impact business operations
• document and capture detail at the right level of abstraction while creating process/dataflow/architecture diagrams, or documenting instructions
City
Job Type
Country / State
Function Category
Join us
We’re committed to disability inclusion and if you need reasonable accommodation/adjustments throughout our recruitment process, you can always contact us.
Contact Details
UBS Recruiting
Disclaimer / Policy statements
Your team
Operational Security Testing is a global team with a presence in Switzerland, Poland, and the USA. The team works across TS TISO and other security control areas to conduct red teaming, purple teaming, and other forms of offensive security testing to identify and help remediate gaps across all aspects of the Cyber Security protect, detect and response capabilities of our Firm. Your role will be based in Raleigh, NC.
Your expertise
• experience and proficiency in the day-to-day operations of a Red Team with knowledge of offensive security tools, such as Metasploit, Nessus, Burp, Kali Linux / CommandoVM or C2 frameworks (e.g. Cobalt Strike, Brute Ratel, Sliver, Nighthawk)
• experience in setting up infrastructure for Red Teaming operations and techniques utilized in reconnaissance, exploitation, persistence, lateral movement, command & control, etc.
• experience in automation using Python, Bash, or other scripting language ideally coupled with the ability to experiment and tweak newly developed open-source tools written in scripting language
• knowledge and understanding of MITRE ATT&CK framework and TTPs of cyber-attacks at a conceptual level as well as knowledge and understanding of OPSEC concepts in attack emulation
• experience in a blue team role investigating cyber security incidents in a modern enterprise security environment (including SIEM, EDR, etc) or experience in system administration or engineering experience with Linux and Windows operating systems are pluses,
• experience with OSINT, phishing / social engineering, vulnerability research, reverse engineering , exploit development and experience with cloud (Azure, AWS) technologies and experience programming in C, C++, C#, Rust, Nim or in Assembly are pluses
• Offensive Security certifications (such as OSCP or OSEP), SANS certifications (such as GXPN, GPEN, GWAPT, GREM), or other training in red teaming operations are a plus
“At UBS, we appreciate our Veterans and are committed to providing opportunities in Financial Services.”
*LI-UBS
*UBS-MOGUL
About us
We have a presence in all major financial centers in more than 50 countries.