Senior Security Engineer - Red Team
Ohio - Columbus
Full Time Senior-level / Expert USD 107K - 149K *
Veeva [NYSE: VEEV] is the leader in cloud-based software for the global life sciences industry. Committed to innovation, product excellence, and customer success, our customers range from the world’s largest pharmaceutical companies to emerging biotechs. Veeva’s software helps our customers bring medicines and therapies to patients faster.
We are the first public company to become a Public Benefit Corporation. As a PBC, we are committed to making the industries we serve more productive, and we are committed to creating high-quality employment opportunities.
Veeva is a Work Anywhere company which means that you can choose to work in the environment that works best for you - on any given day. Whether you choose to work remotely from home or work in an office - it’s up to you.
Veeva was recently named the #1 Best Place to Work in Central Ohio by Columbus Business First.
The Role
Veeva’s Security Engineering Team is seeking Red Teamers to help keep Veeva secure and safe from attackers. Our team in Columbus is growing, and we want you to join us! This role has a broad scope, ranging from attacking Veeva’s AWS infrastructure, processes, products, and discovering weaknesses in Veeva’s architecture. You’ll also be working with product and platform teams to perform penetration tests on new products. Working with external third-party testers and researchers to sharpen our detective and preventative capabilities.
A Security Engineer at Veeva is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Security, such as the Threat Intelligence, Application Security and Security Operations teams, as well as provide technical leadership and advice to teams and leaders throughout Veeva. You will be in direct contact with numerous teams in a variety of business platforms, giving you firsthand knowledge about how Veeva is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Veeva to find new ways to break software and processes throughout the company. Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Individuals in this role will be expected to provide thought leadership for the organization as they discover, invent and innovate throughout the course of their duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Veeva and its customers secure.
This role can be Work Anywhere +/- 1-time zone from the Veeva Columbus, OH office (EST).
Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.
Veeva is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin or ancestry, age, disability, marital status, pregnancy, protected veteran status, protected genetic information, political affiliation, or any other characteristics protected by local laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us at talent_accommodations@veeva.com.
We are the first public company to become a Public Benefit Corporation. As a PBC, we are committed to making the industries we serve more productive, and we are committed to creating high-quality employment opportunities.
Veeva is a Work Anywhere company which means that you can choose to work in the environment that works best for you - on any given day. Whether you choose to work remotely from home or work in an office - it’s up to you.
Veeva was recently named the #1 Best Place to Work in Central Ohio by Columbus Business First.
The Role
Veeva’s Security Engineering Team is seeking Red Teamers to help keep Veeva secure and safe from attackers. Our team in Columbus is growing, and we want you to join us! This role has a broad scope, ranging from attacking Veeva’s AWS infrastructure, processes, products, and discovering weaknesses in Veeva’s architecture. You’ll also be working with product and platform teams to perform penetration tests on new products. Working with external third-party testers and researchers to sharpen our detective and preventative capabilities.
A Security Engineer at Veeva is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Security, such as the Threat Intelligence, Application Security and Security Operations teams, as well as provide technical leadership and advice to teams and leaders throughout Veeva. You will be in direct contact with numerous teams in a variety of business platforms, giving you firsthand knowledge about how Veeva is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Veeva to find new ways to break software and processes throughout the company. Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Individuals in this role will be expected to provide thought leadership for the organization as they discover, invent and innovate throughout the course of their duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Veeva and its customers secure.
This role can be Work Anywhere +/- 1-time zone from the Veeva Columbus, OH office (EST).
What You'll Do
- Participate in Red Team engagements throughout Veeva with few limits and restrictions.
- Conduct full cycle engagements with business units independently, or as part of a team.
- Perform manual examination of client systems, web sites and networks to discover weaknesses.
- Thoroughly document exploit chain/proof of concept scenarios for client consumption.
- Communicate findings and discoveries prioritize and execute remediation plans.
- Train other members of the Red Team, developers or engineers in the exploits and fixes
- Assist in Security Incident Response and Cyber Forensics during and post an incident and assist in reverse engineering the attack and designing security controls
- Coordinate find remediation from third party penetration testers
- Review and validate findings from Veeva’s bug bounty program
- Maintain AWS VPC and related testing systems for our third-party testers and bug bounty programs
Requirements
- BS in Computer Science or related field, or equivalent work experience
- 4+ years in an Information Security role, preferably in red teaming, penetration testing, reverse engineering, incident response or vulnerability management
- Advanced knowledge and understanding in various disciplines such as security engineering, system and network security, authentication and security protocols, cryptography, and application security
- Experience with interpreted or compiled languages: Python, Ruby, Perl, PHP, C/C++, Java, C#
- Experience with cloud service providers and their offerings, preferably AWS and its various technologies and APIs
- Experience with various testing tools, such as Netspaker, Kali Linux, Metasploit, Nmap, Nessus, Burp Suite, etc.
- Familiar with offensive TTPs (Tactics, Techniques and Procedures) including post-exploitation and lateral movement
- Experience with Redhat, AWS Linux, AWS Linux 2, Windows Server 2008, 2012, 2016 and 2019 etc.
- Understanding of OSWAP Top 10, SANS Top 20, NIST 800-53, CIS, CSC or other security standards
- Knowledge of the MITRE ATT&CK Framework
- Industry penetration certifications such as OSCP, GPEN, GXPN, GWAPT, etc
Nice to Have
- Master of Science in Cyber Security, Information Security, MIS or equivalent
- Industry security certifications such as CISSP, CEH or others
- Experience in conducting social engineering-focused assessments
- Experience in CTF competitions, CVE research and/or Bug Bounty recognition
- Experience in Web and Mobile (Android/iOS) based application/service assessment
- Experience in Wireless and Network assessment in enterprise infrastructure
- Experience in reverse engineering and associated tooling such as IDA
- Experience in Advanced Persistent Threat exploits
- Experience with Web Application Firewalls (WAF), IDS/IPS or other security platforms
- Knowledge of fuzzing, memory corruption and exploit development
- Knowledge about hardware hacking
- Intermediate to advanced communication and presentation skills
- Experience providing training and mentorship
- Demonstrable teamwork skills and resourcefulness
- Ability to make concrete progress in the face of ambiguity and imperfect knowledge
Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.
Veeva is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin or ancestry, age, disability, marital status, pregnancy, protected veteran status, protected genetic information, political affiliation, or any other characteristics protected by local laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us at talent_accommodations@veeva.com.
* Salary range is an estimate based on our salary survey at salaries.infosec-jobs.com
Job tags:
Android
Application security
AWS
Burp Suite
C
CEH
CISSP
Cryptography
CTF
Exploit
Exploits
Forensics
GPEN
GWAPT
GXPN
IDS
Incident response
iOS
IPS
Java
Kali
Linux
Metasploit
MITRE ATT&CK
Nessus
Network security
NIST
Nmap
OSCP
Penetration testing
Perl
PHP
Python
Red team
Ruby
SANS
Threat intelligence
TTPs
Vulnerability management
Windows
Job region:
North America
Job country:
United States
Job stats:
6
0
0
Other jobs like this
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Application Security Engineer/Architect jobs
- Open Lead Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Cybersecurity Engineer jobs
- Open Head of Information Security jobs
- Open Staff Security Engineer jobs
- Open Security Operations Analyst jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Operations Engineer jobs
- Open Offensive Security Engineer jobs
- Open Senior Security Analyst jobs
- Open Senior DevSecOps Engineer jobs
- Open SOC Analyst jobs
- Open Senior Information Security Engineer jobs
- Open Information System Security Officer (ISSO) jobs
- Open Senior Information Security Analyst jobs
- Open Sr. Security Engineer jobs
- Open Security Officer 3 jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Cloud Security Operations Lead jobs
- Open Cloud Security Automation Specialist jobs
- Open Information Security Officer jobs
- Open Security Researcher jobs
- Open Security Officer 2 jobs
- Open Senior Cyber Security Infrastructure Architect jobs
- Open Analytics-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open Audits-related jobs
- Open PCI-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open OWASP-related jobs
- Open Agile-related jobs
- Open Forensics-related jobs
- Open IDS-related jobs
- Open Ruby-related jobs
- Open CISM-related jobs
- Open Open Source-related jobs
- Open JavaScript-related jobs
- Open Security assessments-related jobs
- Open Encryption-related jobs
- Open Splunk-related jobs
- Open CISA-related jobs
- Open DevSecOps-related jobs
- Open GDPR-related jobs
- Open ISO 27001-related jobs
- Open Docker-related jobs
- Open Governance-related jobs
- Open Threat detection-related jobs