Senior Security Engineer & Workday
Job Description
Hudson Manpower is seeking a Senior Security Engineer in Harrisburg, PA, onsite, with a focus on Red Team offensive security. The role leads red and purple team exercises, builds attack infrastructure, and delivers risk-based findings across hybrid environments.
Responsibilities
- Participate in executing Red Team cyber exercises across internal and internet-facing information systems to identify misconfigurations and vulnerabilities that could be exploited to gain unauthorized access.
- Contribute to Purple Team activities to help the Blue Team enhance detection capabilities.
- Lead red team engagements against a hybrid environment utilizing threat intelligence and the MITRE ATT&CK Framework.
- Engage in intelligence-driven Purple Team exercises to test detections.
- Build and maintain Red and Purple team infrastructure and automate functions where feasible.
- Continuously research new offensive security tactics, techniques, and procedures and share knowledge with team members.
- Perform ad-hoc offensive security testing using industry standard tools or internally developed tools.
- Lead report creation, including compromise narratives, detailed technical findings with risk severity ratings, and both tactical and strategic remediation recommendations, along with peer reviews of deliverables.
- Assist cyber defense teams during incident investigations by providing subject matter expertise on attacker tradecraft and mindset.
- Collaborate with information security, technology, and business stakeholders to raise security awareness and share remediation guidance.
- Actively contribute to Red and Purple Team activities for internal presentations and conferences.
Requirements
- Experience with industry standard Red Team testing tools such as Cobalt Strike, Mythic C2, Rubeus, BloodHound, Covenant, or demonstrated equivalent knowledge.
- Advanced understanding of how an Advanced Persistent Threat could compromise a financial institution without using phishing.
- Deep knowledge of Red Team concepts, tooling, and automation strategies.
- Extensive familiarity with the MITRE ATT&CK framework, including tactics, techniques, and procedures.
- Advanced ability to measure and rate vulnerabilities based on core characteristics.
- In-depth knowledge of Windows and Linux system hardening concepts and techniques.
- Expertise in modifying payloads to bypass detections such as EDR.
- Proven capability to compromise a company without phishing in engagement scenarios.
- Strong proficiency in at least one scripting language (Python, Ruby, PowerShell, Bash, etc.).
- Experience with at least one cloud environment (AWS, GCP, Azure).
- Experience attacking cloud, on-prem and/or hybrid environments from initial access through to objective completion.
- Past Red Team project delivery experience, including creating and executing statements of work, risk mitigation, and remediation with stakeholders.
- Experience using multi operating system command and control tools.
- Experience developing custom attack tradecraft or modifying existing tools.
- Experience using automated configuration management such as Chef.
- Experience discovering and exploiting vulnerabilities in AI systems.
- Experience conducting Offensive Security or Red Team exercises against macOS, iOS, or ChromeOS.
- Industry certifications such as GPEN, GXPN, GREM, eCPTX, eCPPT, OSCP, OSWE, CISSP, CPSA, CRT, among others.
- Knowledgeable in security standards such as TIBER-EU, CBEST, NIST CSF, ISO27002, and similar frameworks.
- Familiarity with Agile project management practices.
Technologies
- Cobalt Strike
- Mythic C2
- Rubeus
- BloodHound
- Covenant
- MITRE ATT&CK
- Windows
- Linux
- Python
- Ruby
- PowerShell
- Bash
- AWS
- GCP
- Azure
- Chef
- macOS
- iOS
- ChromeOS
Job Description
The role centers on leading offensive security engagements, developing and refining red and purple team capabilities, and producing comprehensive risk-based findings. Candidates should demonstrate a track record of delivering Red Team projects, maintaining and evolving attack tradecraft, and collaborating with cross-functional teams to remediate security issues. A strong background in cloud, on-prem, or hybrid environments, scripting proficiency, and knowledge of security standards are essential.