Senior Red Team Engineer
US Remote
Box
The intelligent Content Cloud makes it easy to automate workflows, collaborate internally and externally, and protect your sensitive data, all on one platform.WHAT IS BOX?
Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers 100,000+ businesses, including many top Fortune 500 companies who trust our secure collaboration platform to manage the entire content lifecycle.
WHY BOX NEEDS YOU
The Red Team Engineer will provide adversarial services including engaging in various operations of different complexity and length to test security architecture, security tools, configurations and SIRT response to incidents. The Red Team Engineer will also partner with Blue Team members to Purple Team test security tools and detections. This role will have the opportunity to collaborate across Box as a whole, providing expertise and real world adversarial group experience to product, architecture and operational teams at Box.
WHAT YOU'LL DO
- Consult on, design, and execute security testing engagements
- Conduct research into real-world threat actor tactics, techniques, and procedures to develop playbooks
- Partner with the SIRT and other stakeholders in the organization to identify security posture improvement opportunities
- Collaborate with the Threat Operations Team (Threat Intelligence, Detection, and Threat Hunting) on threat analysis and research
- Present findings and operational work to groups in a clear and professional manner
- Study the techniques of Threat Actors, and apply that lens to operational work
WHO YOU ARE
- 3+ years of experience of operating in a technical red team or pen tester capacity
- Bachelor's degree in Information Technology, related discipline or relevant work experience
- Relevant Technical Security Certifications (GIAC, EC-Council, Offensive Security, etc)
- Familiarity with MITRE ATT&CK and how it’s applied by both Red and Blue Teams
- Project management, cross-team coordination and driving organizational change
- 3+ years experience in the following areas:
- Network penetration testing and manipulation of network infrastructure
- Mobile and/or web application assessments
- Email, phone, or physical social-engineering assessments
- Shell scripting or automation of simple tasks using Perl, Python, or Ruby
- Developing, extending, or modifying exploits, shellcode or exploit tools
- Source code review for control flow and security flaws
- Bypassing preventative and detective security controls to accomplish operational goals
- Strong knowledge of tools used for wireless, web application, and network security testing
- Experience participating in Purple Team programs is a plus
- Remote friendly
Nice to Haves
- High level of proficiency of Linux/Mac/Windows operating systems, including Bash and PowerShell
- Detailed understanding of the TCP/IP networking stack, network technologies and covert channels
- Working knowledge of full packet capture PCAP analysis and accompanying tools (Wireshark, etc.)
- Nominal understanding of regular expression and proficient in programming (.NET, C/C++) and scripting languages (e.g. Perl, Java, or Python)
- Familiarity with common C2 frameworks such as Cobalt Strike, Mythic, and Metasploit
- Strong collaborative skills and proven ability to work in a diverse global team of security professionals
- Strong organizational skills and mentoring
- Comfortable with presenting technical talks
- Strong verbal and written skills
- Excellent interpersonal skills
Head-over-heels about this role — but not sure you meet all the requirements? Apply anyway! Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Box, we take a big-picture approach to hiring that fosters authenticity, diversity, and inclusion. If you're passionate about this opportunity, chances are, you shine pretty bright.
EQUAL OPPORTUNITY
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and independence of people with disabilities and is committed to giving them the same opportunity to succeed as all other employees. Inclusiveness is core to our culture at Box, and we strive to ensure you get the most from your interview experience. Box makes reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please complete this form Reasonable accommodations may include scheduling adjustments, document dictation and beyond.
Notice to applicants in Los Angeles: Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the Los Angeles Fair Chair Ordinance. The Fair Chance Ordinance is provided here.
Notice to applicants in San Francisco: Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chair Ordinance. The Fair Chance Ordinance is provided here.
For details on how we protect your information when you apply, please see our cloud.app.box.com/v/BoxPersonnelPrivacyNotice" target="_blank">Personnel Privacy Notice. If you are a California-resident, please read our California Applicant & Candidate Privacy Notice here.
Box is committed to fair and equitable compensation practices. Actual base salary is dependent upon factors such as: knowledge, skill level, experience, and work location. This role is also eligible for equity and benefits. For more information on benefits, check out our healthcare benefits and additional Box Benefits + Perks.
In accordance with OFCCP compliance, here is the Pay Transparency Provision.
United States Pay Range$132,500—$194,500 USDTags: Automation Bash Blue team C Cloud Cobalt Strike Compliance Exploit Exploits GIAC Java Linux Metasploit MITRE ATT&CK Network security Offensive security PCAP Pentesting Perl PowerShell Privacy Python Red team Ruby Scripting TCP/IP Threat intelligence Windows
Perks/benefits: Equity / stock options Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.