Northern Trust is seeking a Principal, Technology Risk & Information Security – Red Team to lead their Red Team operations, conducting cyber threat and penetration testing to simulate and identify potential threats to their systems and platforms. The selected candidate will be responsible for executing Red Team operations, conducting threat intelligence gathering, and performing technical testing and examinations across application, infrastructure, and enterprise environments.
Requirements
- Experience utilising ethical hacking techniques such as social engineering, physical security or customized scanning / scripts / tools
- Knowledge of Red Team and penetration testing methodologies within enterprise environments
- Knowledge and skill with common offensive security tooling (e.g., Cobalt Strike, Burp Suite, mimikatz, Rubeus)
- Proficiency in performing application security assessments (including source code review, vulnerability scans, web service testing, use of disassemblers/decompilers/debuggers, reverse engineering, binary analysis and disk / memory forensics)
- Prior experience in a security consulting role
- Prior experience scoping engagements and developing technical proposals
- Demonstrated ability to work well in an individual contributor and team capacity, in particular multi-national teams
- Proven ability to effectively manage projects and complete multiple tasks simultaneously and efficiently while maintaining a sense of urgency and attention to detail
- Possess excellent written and verbal communication skills
- Risk management principles and information security disciplines such as security engineering, architecture, and defensive capabilities
- Current relevant offensive security certifications with a practical testing element (e.g., OSCP, OSCE, CRTO, CRTP, CRTE)
- Bachelor’s degree in Information Technology, Management Information Systems, Computer Science or a related discipline, or equivalent practical experience
- Experience developing or modifying offensive security tools using scripting languages such as Python or Bash