Senior Red Team Engineer

US Remote

Applications have closed

Box

Box empowers your teams by making it easy to work with people inside and outside your organization, protect your valuable content, and connect all your apps.

View all jobs at Box

WHAT IS BOX?

Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers 100,000+ businesses, including many top Fortune 500 companies who trust our secure collaboration platform to manage the entire content lifecycle.

WHY BOX NEEDS YOU

The Red Team Engineer will provide adversarial services including engaging in various operations of different complexity and length to test security architecture, security tools, configurations and SIRT response to incidents. The Red Team Engineer will also partner with Blue Team members to Purple Team test security tools and detections. This role will have the opportunity to collaborate across Box as a whole, providing expertise and real world adversarial group experience to product, architecture and operational teams at Box.

WHAT YOU'LL DO

  • Consult on, design, and execute security testing engagements
  • Conduct research into real-world threat actor tactics, techniques, and procedures to develop playbooks
  • Partner with the SIRT and other stakeholders in the organization to identify security posture improvement opportunities
  • Collaborate with the Threat Operations Team (Threat Intelligence, Detection, and Threat Hunting) on threat analysis and research
  • Present findings and operational work to groups in a clear and professional manner
  • Study the techniques of Threat Actors, and apply that lens to operational work

WHO YOU ARE

  • 3+ years of experience of operating in a technical red team or pen tester capacity
  • Bachelor's degree in Information Technology, related discipline or relevant work experience 
  • Relevant Technical Security Certifications (GIAC, EC-Council, Offensive Security, etc) 
  • Familiarity with MITRE ATT&CK and how it’s applied by both Red and Blue Teams
  • Project management, cross-team coordination and driving organizational change
  • 3+ years experience in the following areas:
    • Network penetration testing and manipulation of network infrastructure
    • Mobile and/or web application assessments
    • Email, phone, or physical social-engineering assessments
    • Shell scripting or automation of simple tasks using Perl, Python, or Ruby
    • Developing, extending, or modifying exploits, shellcode or exploit tools
    • Source code review for control flow and security flaws
    • Bypassing preventative and detective security controls to accomplish operational goals
  • Strong knowledge of tools used for wireless, web application, and network security testing
  • Experience participating in Purple Team programs is a plus
  • Remote friendly 

Nice to Haves

  • High level of proficiency of Linux/Mac/Windows operating systems, including Bash and PowerShell
  • Detailed understanding of the TCP/IP networking stack, network technologies and covert channels
  • Working knowledge of full packet capture PCAP analysis and accompanying tools (Wireshark, etc.) 
  • Nominal understanding of regular expression and proficient in programming (.NET, C/C++) and scripting languages (e.g. Perl, Java, or Python) 
  • Familiarity with common C2 frameworks such as Cobalt Strike, Mythic, and Metasploit
  • Strong collaborative skills and proven ability to work in a diverse global team of security professionals 
  • Strong organizational skills and mentoring 
  • Comfortable with presenting technical talks
  • Strong verbal and written skills 
  • Excellent interpersonal skills 

Head-over-heels about this role — but not sure you meet all the requirements? Apply anyway! Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Box, we take a big-picture approach to hiring that fosters authenticity, diversity, and inclusion. If you're passionate about this opportunity, chances are, you shine pretty bright.

EQUAL OPPORTUNITY 

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and ‎‎independence of people with disabilities and is committed to giving them the same ‎‎opportunity to succeed as all other employees. Inclusiveness is core to our culture at Box, and we strive to ensure you get the most from your interview experience. Box makes reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please complete this form Reasonable accommodations may include scheduling adjustments, document dictation and beyond.

Notice to applicants in Los Angeles: Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the Los Angeles Fair Chair Ordinance.  The Fair Chance Ordinance is provided here

Notice to applicants in San Francisco:  Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chair Ordinance.  The Fair Chance Ordinance is provided here

For details on how we protect your information when you apply, please see our cloud.app.box.com/v/BoxPersonnelPrivacyNotice" target="_blank">Personnel Privacy Notice. If you are a California-resident, please read our California Applicant & Candidate Privacy Notice here.

Box is committed to fair and equitable compensation practices. Actual base salary is dependent upon factors such as: knowledge, skill level, experience, and work location. This role is also eligible for equity and benefits. For more information on benefits, check out our healthcare benefits and additional Box Benefits + Perks.

In accordance with OFCCP compliance, here is the Pay Transparency Provision

United States Pay Range$132,500—$194,500 USD
Job stats:  66  14  1

Tags: Automation Bash Blue team C Cloud Cobalt Strike Compliance Exploit Exploits GIAC Java Linux Metasploit MITRE ATT&CK Network security Offensive security PCAP Pentesting Perl PowerShell Privacy Python Red team Ruby Scripting TCP/IP Threat intelligence Windows

Perks/benefits: Equity / stock options Transparency

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.