Manager, Cyber Resilience & Offensive Security
Toronto
Equitable Bank
At Equitable Bank, we specialize in providing branchless financial services that meet the unique needs of all Canadians. Our range of mortgages, savings accounts and investment options are designed to offer the right solutions to match any...
Purpose of the Job:This role is responsible for the Designing, planning and executing the bank’s Cyber Resilience Testing and offensive security program, commonly referred to as “red team exercises”. This role develops and manages processes that identify continuous red team and infrastructure penetration test objectives through the course of the year while also planning execution of threat simulation activities. This role facilitates the communication and presentation of technical cyber control effectiveness to key stakeholders
Main Activities:
- Design and execute the bank’s Cyber Resilience Testing program e.g. Red team exercises, cyber threat simulations.
- Provides input to the effectiveness testing of EQBank’s Enterprise Cyber Security Controls and cyber roadmap prioritization activities.
- Drive cross-functional collaboration to achieve objectives of the programs in purview.
- Responsible for maintaining the standards, procedures and guidelines for domains under purview.
- Develop and manage measures to ensure effective monitoring control adequacy and compliance for areas under purview
- Developing and Managing means of measured performance of control processes and technologies for areas under purview.
- Provide technical guidance for team and subject matter advise to stakeholders.
Knowledge/Skill Requirements:
- A college diploma or university degree in computer science (or related course) or Industry recognized certifications (e.g. CISSP)
- Minimum of 7 years of technical IT experience with at least 3-5 years specifically focused on offensive security roles.
- Strong knowledge of cyber controls testing frameworks such as MITRE Framework
- One or more of the following certifications are highly preferred: OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), CEH (Certified Ethical
- Hacker), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager)
- Strong engineering and automation experience, prior hands-on Security automation experience is desired.
- Ability to build and maintain strong working relationships with cross-functional teams and stakeholders. Collaboration is key to integrating offensive security insights across the organization.
- Strong analytical and problem-solving skills with the ability to think critically and strategically; this role needs to analyze reports to identify patterns and assess weaknesses.
- People and team management abilities.
- Technical roadmap development and execution.
- Ownership & Accountability
Non-Technical Skills
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Category:
Leadership Jobs
Tags: Automation CEH CISM CISSP Compliance Computer Science Exploit GIAC GPEN GXPN Monitoring Offensive security OSCE OSCP Red team
Region:
North America
Country:
Canada
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsInformation Security Manager jobsSystems Engineer jobsSenior Information Security Analyst jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsSecurity Specialist jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsThreat Intelligence Analyst jobsSenior Software Engineer jobs
Java jobsEncryption jobsEDR jobsBash jobsTS/SCI jobsIDS jobsIPS jobsThreat detection jobsSQL jobsTerraform jobsSDLC jobsSplunk jobsMalware jobsTop Secret jobsFinance jobsDocker jobsForensics jobsSOC 2 jobsRMF jobsActive Directory jobsCompTIA jobsIntrusion detection jobsITIL jobsOWASP jobsGIAC jobs
DoDD 8570 jobsVPN jobsAnsible jobsHIPAA jobsOSCP jobsIT infrastructure jobsData Analytics jobsTCP/IP jobsUNIX jobsCCSP jobsCRISC jobsSAP jobsBanking jobsSANS jobsSOAR jobsSOX jobsJavaScript jobsMITRE ATT&CK jobsSecurity strategy jobsClearance Required jobsMachine Learning jobsZero Trust jobsDNS jobsJira jobsPolygraph jobs