Offensive Security Engineer
United States
The Nielsen Legal Team supports the company globally, protecting Nielsen’s business, products, intellectual property and reputation. The team places a focus on developing excellence and agility as we minimize risk and move the business forward. The team comprises attorneys, paralegals and legal assistants. Whether we’re solving a problem or averting a crisis, we are focused on creating the best environment possible to advance Nielsen’s reputation, preserve business opportunities, and help business to flourish.
About the JobNielsen, the leading company in advertising measurement and outcomes, is searching for an exceptional candidate to lead service delivery as an Offensive Security Engineer. As Nielsen constantly innovates to maintain its leadership in an ever-changing marketplace, this leader will ensure that Nielsen's platforms and applications are built securely.
The Offensive Security Engineer supports secure software development and cloud security through application of ethical hacking techniques to validate product security posture. This role will lead engagements with product teams focused on identifying component and system level technical risks and evaluating critical failure points. They will determine technical security controls to mitigate risks and work with cross functional teams to implement features according to product road maps.A strong candidate for this role will need to maintain an understanding of dynamic business needs, laser-focus on clear, tangible outcomes, and partner with DevOps teams to productize scalable security controls.
About the JobNielsen, the leading company in advertising measurement and outcomes, is searching for an exceptional candidate to lead service delivery as an Offensive Security Engineer. As Nielsen constantly innovates to maintain its leadership in an ever-changing marketplace, this leader will ensure that Nielsen's platforms and applications are built securely.
The Offensive Security Engineer supports secure software development and cloud security through application of ethical hacking techniques to validate product security posture. This role will lead engagements with product teams focused on identifying component and system level technical risks and evaluating critical failure points. They will determine technical security controls to mitigate risks and work with cross functional teams to implement features according to product road maps.A strong candidate for this role will need to maintain an understanding of dynamic business needs, laser-focus on clear, tangible outcomes, and partner with DevOps teams to productize scalable security controls.
Responsibilities
- Product and Platform Security The Offensive Security Engineer will serve in a significant role to identify security blind spots in product designs. In joint collaboration with Product Leadership, DevOps, Engineering, and Data Science teams, the Engineer is accountable for delivering high quality ethical hacking capability including:
- Conducts application and network vulnerability assessments and penetration testing
- Perform vulnerability analysis of applications, operating systems or networks
- Identifies, documents, and communicates intrusion or incident path and method
- Develop and use malware, pivoting, escalating privileges to test the organization’s security effectiveness
- Plan, communicate, coordinate, and perform penetration tests and security assessments at application, system and enterprise levels
- Assist with reconnaissance, threat modeling, vulnerability identification, authorized exploitation, and post-exploitation cleanup
- Perform information technology security research to remain current on emerging technology trends and develop exploits for disclosed and undisclosed vulnerabilities
- Cybersecurity as a Product Nielsen is committed to a DevOps culture where best security practices are integrated, understood, and thrive--resulting in true DevSecOps. This is achieved through the utilization of modern technologies to automate security controls. As a Cloud-first organization, we operate and develop in an ecosystem where deployment and CI/CD pipelines can embed security measures that can achieve speed and scalability through technology. The Offensive Security Engineer will play a significant role in delivering superior services and collaborate with teams to:
- Support a service delivery strategy for product security testing including continuous improvement, quality, and customer satisfaction
- Providing expert cybersecurity consulting to internal Nielsen teams
- Engineering & Developer Partnership To effect and maintain a culture of security within Nielsen’s engineering, technology, software development, business and operations teams, the Offensive Security Engineer must:
- Maintain an open, collaborative, and consultative culture supported by outreach and education
- Partner with teams early and proactively
- Share knowledge and actively bridge relationships into other verticals in the Cybersecurity organization
QUALIFICATIONS
- 2+ years experience in security Demonstrated expertise in software development, DevOps, incident response, digital forensics, reverse engineering, and/or automation
- Experience with utilizing penetration testing methodologies
- Understanding of threat attacks, exploitation and data exfiltration
- In-depth experience identifying and exploiting web application and web service security vulnerabilities including those found in the OWASP Top 10, IoT Top 10, and Sans Top 25
- Understanding of application and product architectures, programming languages, web application stacks, and S-SDLC
- Excellent written and verbal communication skills, with the ability to communicate security objectives and concepts to engineering and business teams
- Strong interpersonal skills; capable of understanding business needs and translating them into architectural standards/diagrams; able to translate complex data and architectural concepts and principles into easily-understanding information by LOBs; ability to design and deliver architectural presentations to IT, senior leadership, and business partners
- Action-oriented with the ability to set priorities and direction
Preferred qualifications
- 1+ years working in product security
- Service delivery experience in a large product organization
- Demonstrated experience in product/application security architecture, network security, application security, cloud SaaS/PaaS/IaaS
- Relevant certifications including CEH, PenTest+, CPT, GPEN, OSCP General cyber security expertise with sufficient knowledge of modern DevSecOps technologies such as:
- Containers (Docker, Kubernetes, etc.)
- Infrastructure as code (Docker, Ansible, Chef, Terraform, etc.)
- Continuous integration / Continuous Deployment (Jenkins, etc.)
- Integration of Security testing tools into pipeline
- Defect and Issue tracking (Jira, ServiceNow etc.)
- Source code management (GitLab, Github, BitBucket, etc.)
- QA Testing tools (nUnit, jUnit, Selenium, Cucumber, etc.)
- Application security testing tools (SAST, DAST, IAST, OSA, SCA etc.)
- Cloud Posture Assessment Tools
- Cloud configuration Drift Detection
- Unix, Linux, and Windows
- Cloud environment (AWS, Azure, GCP, etc)
Job tags:
Ansible
Application security
Automation
AWS
Azure
CEH
DAST
DevOps
DevSecOps
Docker
Ethical hacking
Exploits
Forensics
GCP
GPEN
IaaS
Incident response
Kubernetes
Linux
Malware
Network security
Offensive Security
OSCP
OWASP
PaaS
Penetration testing
Product security
SaaS
SANS
SAST
SDLC
Security assessments
Strategy
Terraform
Unix
Vulnerabilities
Windows
Job region:
North America
Job country:
United States
Job stats:
10
1
0
Other jobs like this
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Staff Security Engineer jobs
- Open Head of Information Security jobs
- Open Lead Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cybersecurity Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Sr. Security Engineer jobs
- Open Cloud Security Automation Specialist jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Offensive Security Engineer jobs
- Open Information Security Officer jobs
- Open Cloud Security Operations Lead jobs
- Open Azure Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open DevOps-related jobs
- Open Application security-related jobs
- Open Analytics-related jobs
- Open Audits-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open JavaScript-related jobs
- Open Splunk-related jobs
- Open Ruby-related jobs
- Open CEH-related jobs
- Open Encryption-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Agile-related jobs
- Open Open Source-related jobs
- Open Threat detection-related jobs
- Open OSCP-related jobs
- Open Intrusion detection-related jobs
- Open Machine Learning-related jobs
- Open DevSecOps-related jobs