Offensive Security Consultant
Sydney, NSW, AU
Deloitte
Insights zu unseren Diensleistungen im Bereich Audit, Consulting, Financial Advisory, Risk Adivisory und Tax sowie unseren zahlreichen Industrien.Job Requisition ID:Â 36732Â
-
Salary packaging â to suit your personal and financial circumstancesÂ
-
Flexible work arrangements â work in a way that suits you bestÂ
-
Rewards platform â your hard work wonât go unnoticed at DeloitteÂ
Â
We currently have multiple vacancies across from Senior Analyst to Senior Manager level in our Offensive Security team!Â
Â
About the roleÂ
Â
As part of the Deloitte Offensive Security team, you'll be responsible for defining, carrying out, and overseeing penetration testing projects to uncover security vulnerabilities in client's IT systems. You will be required to report on the identified vulnerabilities and provide recommendations for their remediation. Additionally, you will play a crucial role in the team, and other members will look to you as a subject matter expert for guidance and mentorship.Â
In this role you will respond to client requests, anticipating and meeting client problems and needs using innovative approaches when applicable. You will be involved in all aspects of security and vulnerability management engagements which include but are not limited to:Â
-
Network and host layer penetration tests and vulnerability assessmentsÂ
-
Firewall, networking, and security device reviewsÂ
-
Web application assessmentsÂ
-
API assessmentsÂ
-
Mobile application assessmentsÂ
-
Red Teaming - targeting technical, physical and human layers of an organisationâs security controls.Â
-
Source code reviews using manual and automated tools.Â
-
Malware reverse engineeringÂ
-
Wireless AssessmentsÂ
-
Closing meetings to present findings to the client.Â
-
Detailed reporting and proposal writingÂ
âŻÂ
About the teamÂ
Â
Positioned first globally in Security Consulting Services for the 6th year in a row. Yep, thatâs Deloitte. The cyberspace is constantly evolving and so are the threats that it brings. Thatâs why our work is more meaningful (and exciting!) than ever. Always one step ahead, we predict risks and safeguard our clients through end-to-end solutions. More importantly, we help clients unlock new opportunities through safer and more secure systems and policies.Â
âŻÂ
Enough about us, letâs talk about you.Â
Â
We are currently looking for experienced Penetration Testers at Senior Analyst, Manager and Senior Manager levels with the following experience and qualifications:âŻÂ
-
Hold a current OSCP or CREST Certified Tester (CCT) in either Infrastructure or Web Applications or similar certification or be in a position and level to pass the exam for the certificationÂ
-
For more senior roles, experience in Red Team engagements. With a capability in line with the CORIE framework or similar (e.g. CBEST, TIBER)Â
Experience in working with applications that perform a wide range of business functions - ideally across multiple industriesÂ
-
Ability to understand and assess applications from both a technical and business function perspectiveÂ
-
Good experience in performing web application penetration testing and development of supporting business and technical-level reportingÂ
-
Innovative and analytical in your approach to performing penetration testing, particularly of novel devices and environmentsÂ
-
Capable of working to strict deadlines and prioritising work appropriatelyÂ
-
The ability to develop scripts or code to automate testing and develop bespoke attacksÂ
-
Good communication skills with an ability to explain complex technical issues to non-technical business clientsÂ
-
Excellent written skills with demonstrated ability to write reports and proposals. Including the ability to discuss findings from a risk perspective with clear remediation advice specific to the clientâs environment.Â
âŻÂ
Experience in one or more of the following:Â
-
Reverse engineeringâŻÂ
-
Web ApplicationsÂ
-
APIâs and MicroservicesÂ
-
Exploit DevelopmentÂ
-
Application vulnerability assessmentÂ
-
Mainframe systemsÂ
-
Mobile platforms (iOS/Android/Windows/etc)Â
-
Social EngineeringÂ
-
Endpoint protectionÂ
-
Practical exposure to security appliances such as firewalls, proxies, NIPS/HIPS and network security applicationsÂ
-
Working knowledge of web concepts such as Ajax, XML, SOAP, and WS-SecurityÂ
-
Familiarity with the Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP) and National Institute of Standards and Technology (NIST) Special Publications.Â
-
Familiarity with penetration testing and vulnerability tools such as Cobalt Strike, Kali Linux, dsniff, nessus, nmap, MetaSploit, CoreImpact, Qualys, tcpdump, wireshark, Nikto, Aircrack-ng, Hailstorm, Burp Suite, etc.Â
-
Strong programming experience with Visual Basic and C/C++ or Java languagesÂ
-
Networking: LAN, WAN, interworking technologiesÂ
-
Good understanding of IaaS environments like Azure, AWS and GCPÂ
Â
Why Deloitte? Â
âŻÂ
At Deloitte, we focus our energy on interesting and impactful work.âŻWeâre always learning, innovating and setting the standard; making a positive difference to our clients and our society. We putâŻcoaching at the heart of what we do, helping our people grow their careers in any direction â whether it be up, moving into something new, or even moving across the world.âŻâŻÂ
âŻÂ
We embrace diversity, equity and inclusion.âŻWe have a diverse collection of people from differentâŻbackgrounds, with different experiences, gender identities, abilitiesâŻandâŻthinking styles. What binds us together is a shared commitment toâŻvalueâŻeveryoneâsâŻperspectiveâŻand to cultivate inclusion; so that our work environment is a safe space we can all belong.âŻÂ
âŻâŻÂ
We prioritise flexibility and choice.âŻAt Deloitte, you get trust on Day 1.âŻWe know our people get their best work done when theyâre in control of where and how they work, designing their work week around their client, team and personal commitments.Â
âŻÂ
We help you live and work well.âŻTo support your personal and professional life, we offer a range ofâŻperks and benefits, including retail discounts, wellbeingâŻleave, paid volunteering days, twelveâŻflexible working options, market-leading parental leave and return to work support package.âŻÂ
Â
Next StepsâŻSound like the sort of role for you? Apply now.Â
Â
Â
Â
By applying for this job, youâll be assessed against the Deloitte Talent Standards. Weâve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: Aircrack Android APIs Application security AWS Azure Burp Suite C Cobalt Strike CORIE CREST Exploit Firewalls GCP IaaS iOS Java Kali Linux Mainframe Malware Metasploit Microservices Nessus Network security NIST Nmap Offensive security Open Source OSCP OWASP Pentesting Qualys Red team Reverse engineering Vulnerabilities Vulnerability management Windows XML
Perks/benefits: Career development Equity / stock options Flex hours Parental leave
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.