Remote - Red Team Security Engineer

Job Locations US-FL-Jacksonville
ID
2024-2388
Category
Information Technology
Type
Full Time

Overview

Fidelity National Financial, Inc. (NYSE:FNF) is a leading provider of title insurance and transaction services to the real estate and mortgage industries. FNF is the nation's largest title insurance company through its title insurance underwriters - Fidelity National Title, Chicago Title, Commonwealth Land Title, Alamo Title and National Title of New York - that collectively issue more title insurance policies than any other title company in the United States. More information about FNF can be found at fnf.com. 


FNF is seeking a Red Team Operator to join its Information Security Office (ISO). This position will be reporting to the Offensive Security Manager. 


The ideal candidate will have a strong background in offensive security and bring their results-driven experience to improve the state of security at FNF.  We are seeking a highly skilled and experienced Red Team Operator to join our Offensive Security team. As a Red Team Security Operator, you will be responsible for conducting advanced adversarial simulations and Red Team exercises to assess the security posture of our environment. You will collaborate closely with our internal teams to identify and exploit vulnerabilities, assess security controls, and provide actionable recommendations to enhance our security defenses.


If you are passionate about offensive security and thrive in a fast-paced environment, we invite you to join our team as a red team operator and make a meaningful impact in defending against cyber threats. Apply now to become part of our innovative and dedicated team!

 

Duties

• Design and execute complex red team engagements, including reconnaissance, social engineering, penetration testing, and post-exploitation activities.
• Conduct thorough assessments of our network, systems, and applications to identify weaknesses and potential attack vectors.
• Develop and execute custom attack scenarios to emulate real-world cyber threats and assess the effectiveness of existing security controls.
• Collaborate with cross-functional teams to develop comprehensive remediation strategies and recommendations based on red team findings.
• Provide technical guidance and mentorship to junior team members, fostering their professional growth and development.
• Stay abreast of the latest cybersecurity threats, vulnerabilities, and techniques, and incorporate this knowledge into red team operations.
• Communicate effectively with clients to convey technical findings, recommendations, and risk implications clearly and concisely.
• Ensure all tools and systems the department uses are working and escalate issues to senior management or authorized vendors as needed.
• Maintain strict confidentiality regarding Red Team operations, findings, and engagements.
• Work with the manager of offensive security to develop the red team program further.

Education

Bachelor's or Master's in Computer Science, Information Security, or a related field.

Experience

• Bachelor's or Master's in Computer Science, Information Security, or a related field.
• 5+ years of cybersecurity experience, focusing on offensive security, penetration testing, or red teaming.
• 1+ years of experience with BloodHound or a similar tool. 
• Proven experience leading and executing red team engagements in complex environments.
• Proficiency in common penetration testing tools and frameworks (e.g., Metasploit, Cobalt Strike, Burp Suite, etc.).
• Advanced understanding of network protocols, operating systems, and cloud environments.
• Excellent problem-solving skills and the ability to think creatively to circumvent security controls.
• Effective communication and interpersonal skills, with the ability to interact confidently with technical and non-technical stakeholders.
• Required OSCP, GXPN, or equivalent.
• Experience with scripting or programming languages (e.g., Python, PowerShell, etc.) 
• Active Directory and Azure Active Directory.
• Knowledge of and ability to research TTPs for known APTs.

Additional Information

Preferred Qualifications:


• Proficiency with Docker, Helm, WSL, and Kubernetes
• Proficiency in Amazon Web Services or Google Cloud Platform
• Relevant industry certifications such as SANS 565, OSCE, GPEN, or similar certifications are preferred.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed