07 Aug
|
Intact
|
Toronto
About the RoleThe Security Specialist, Offensive Security is responsible for testing the security controls, networks, and threat response for Intact Financial globally across all regions and affiliate companies. The specialist employs techniques, tactics, and protocols to evaluate security controls as part of a global offensive security team. The role reports to the Director of Offensive Security and collaborates with technical advisors in multiple locations and time zones.What You'll Do HereConduct reconnaissance on network environments to build an external landscape using industry‐standard tools, threat intelligence feeds, OSINT and other readily available information sources.Perform offensive security testing to ensure security controls and response actions are effective, transitioning from a red team focus to a purple team approach when detected.Employ attack strategies to simulate real‐world attacks by threat actors and benchmark response capabilities across the enterprise.Identify and exploit vulnerabilities in computer systems, networks and applications to simulate attacks, demonstrating the ability to evade up-to-date EDR solutions and achieve privilege escalation.Analyze and report on assessment results, providing recommendations to improve the security posture of the enterprise.Have in‐depth knowledge of the TCP/IP stack, exploit techniques, covert beacon creation, C2 channels, DNS exfiltration, and routing table exploitation such as BGP.Collaborate with regional cyber governance and risk teams to ensure findings are properly tracked for remediation.Generate metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness.Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark affiliate companies against peers.Consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development,
establishing clear rules of engagement and ensuring compliance with the ROE.Maintain and update all offensive security tools, technologies and processes in line with the company rules of engagement.Provide timely and effective communication to key internal stakeholders in alignment with policy and rules of engagement.What You Bring To The TableAdvanced knowledge of computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, threat intelligence, incident response, technical writing, and information risk.Bachelor's degree in Computer Technology or Information Security is an asset.Minimum of five years of relevant professional experience in information technology.Minimum of three years of experience in information security.Knowledge of offensive security operations, tools and techniques.Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001) is an asset.Proficient in Python scripting and history of using it in blue/red/purple team engagements.Proficiency in manual testing techniques beyond automated scanning.Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.Ability to translate technical vulnerability information into actionable attack plans for critical assets.Ability to communicate highly technical data and results in business‐friendly language to non‐technical stakeholders.Experience with capture‐the‐flag competitions is desirable.Recognized certifications in information security (CEH, CISM, or equivalent) are an asset.Analytical mindset,
pragmatic approach to IT security issues and problems.Strong partnership skills internally and externally to provide secure solutions.Ability to manage stress in high‐pressure and stressful situations.Positive attitude, initiative, strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.Strong written and oral communication skills to convey complex concepts and gain consensus.Ability to work in a energetic environment with multiple objectives.Highly motivated, self‐directed, detail‐oriented.Capable of prioritizing and executing tasks in a high‐pressure setting.Diplomatic and effective at all organizational levels.Capacity to challenge the status quo.Customer‐focused approach.For candidates located in Quebec, bilingualism is required to interact with English‐speaking colleagues across Canada.No Canadian work experience required; eligible to work in Canada.Salary and BenefitsSalary Range (but Not Limited To): $118,700 - $145,100 (based on a 35‐hour workweek). Annual Bonus Target is based on the base salary, with a potential payout of up to double the target subject to personal and company performance. Additional benefits include flexible work arrangements, hybrid work model, the option to purchase up to five extra days off per year, a wellness account, telemedicine, a share plan, ESPP with Intact matching 50% of net shares, and a defined benefit pension plan offering guaranteed income for life.Equal Opportunity Employer StatementWe are an equal opportunity employer. At Intact, we value diversity and strive to create an inclusive workplace where employees feel valued and included. We encourage applications from individuals who are members of equity‐deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community. We have policies to ensure equal access and participation for people with disabilities, including workplace adjustments (accommodations). If you require an adjustment to make the application process more accessible, please let us know. Candidates must be eligible to work in Canada. #J-18808-Ljbffr
📌 Security Advisor Specialist, Offensive Security (Global Red Team) (Toronto)
🏢 Intact
📍 Toronto