UBS
Red Team Operator/ Security Tester
UBS, Nashville, North Carolina, United States, 27856
Your role
Are you passionate about the offensive side of cyber security and research? Are you curious and self-driven to continuously learn, explore, and try harder, as well as share your knowledge and experience to complement the rest of the team? Are you someone who likes to bridge the gap between the technical aspects of emulating attacker TTPs and how this will strengthen the security posture of your business? Are you self-driven, motivated and have experience working on a global security team?
Then we are looking for someone like you to:• join a growing in-house red teaming and offensive security capability• execute all phases of offensive security operations participating in both red and purple team testing• develop scripts, tooling, and methodologies to support offensive security capabilities• assist in providing risk appropriate and pragmatic recommendations to correct identified findings, vulnerabilities, and misconfigurations• understand and adhere to regulatory, compliance, and legal requirements that impact business operations
Your team
You will be working in the Cyber Defense Organization within Technology Services, Technology Information Security Office (TS TISO). The TS TISO Vision is to protect, preserve, and prolong the value of UBS data and digital services, and enhance UBS's brand and competitiveness in a digitized world. The Cyber Defense organization within TISO leads the management of all cyber threats and cyber risk across our Firm. To "protect the foundations and secure the future," Cyber Defense serves two mission areas: cyber threat management and defense (understanding, detecting, and responding to threats), and cyber risk management and governance (setting priorities and preventing threats).
Operational Security Testing is a global team with a presence in Switzerland, Poland, and the USA. Our team works across TS TISO and other security control areas to conduct red teaming, purple teaming, and other forms of offensive security testing to identify and help remediate gaps across all aspects of the Cyber Security protect, detect and response capabilities of our Firm.
Diversity helps us grow, together. That's why we are committed to fostering and advancing diversity, equity, and inclusion. It strengthens our business and brings value to our clients.
Your expertise
• ideally 3 years or more of experience as part of an offensive security team responsible for an organizations threat emulation and/or Red Team capabilities• experience and proficiency in the day-to-day operations of a Red Team with knowledge of offensive security tools, such as Metasploit, Nessus, Burp, Kali Linux / CommandoVM or C2 frameworks (e.g. Cobalt Strike, Brute Ratel, Sliver, Nighthawk)• experience in setting up infrastructure for Red Teaming operations and techniques utilized in reconnaissance, exploitation, persistence, lateral movement, command & control, etc.• knowledge and understanding of techniques evading detection across the defensive technology stack such as: networking, firewalls, IDS/IPS, EDR, Web Proxies, DLP, etc.• efficient documentation skills to capture the right level of detail at the right level of abstraction while creating process/dataflow/architecture diagrams, or documenting instructions• experience in exploit writing, evaluation of proof-of-concept exploit code, malware packing, payload encoding, obfuscation and delivery techniques, is a plus• experience in automation, ability to experiment and tweak newly developed open-source tools written in scripting languages (Bash, Perl, Python, Ruby, etc.), or other languages (C#, Java, C/C++, Rust, Nim, Assembly), is a plus• experience with cloud (Azure, AWS) technologies and offensive Security certifications (such as OSCP or OSEP), SANS certifications (such as GXPN, GPEN, GWAPT, GREM), or other training in red teaming operations are pluses
"At UBS, we appreciate our Veterans and are committed to providing opportunities in Financial Services."
*LI-UBS*UBS-MOGUL
About us
UBS is the world's largest and the only truly global wealth manager. We operate through four business divisions: Global Wealth Management, Personal & Corporate Banking, Asset Management and the Investment Bank. Our global reach and the breadth of our expertise set us apart from our competitors..
We have a presence in all major financial centers in more than 50 countries.
Join us
At UBS, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.
From gaining new experiences in different roles to acquiring fresh knowledge and skills, we know that great work is never done alone. We know that it's our people, with their unique backgrounds, skills, experience levels and interests, who drive our ongoing success. Together we're more than ourselves. Ready to be part of #teamUBS and make an impact?
Are you passionate about the offensive side of cyber security and research? Are you curious and self-driven to continuously learn, explore, and try harder, as well as share your knowledge and experience to complement the rest of the team? Are you someone who likes to bridge the gap between the technical aspects of emulating attacker TTPs and how this will strengthen the security posture of your business? Are you self-driven, motivated and have experience working on a global security team?
Then we are looking for someone like you to:• join a growing in-house red teaming and offensive security capability• execute all phases of offensive security operations participating in both red and purple team testing• develop scripts, tooling, and methodologies to support offensive security capabilities• assist in providing risk appropriate and pragmatic recommendations to correct identified findings, vulnerabilities, and misconfigurations• understand and adhere to regulatory, compliance, and legal requirements that impact business operations
Your team
You will be working in the Cyber Defense Organization within Technology Services, Technology Information Security Office (TS TISO). The TS TISO Vision is to protect, preserve, and prolong the value of UBS data and digital services, and enhance UBS's brand and competitiveness in a digitized world. The Cyber Defense organization within TISO leads the management of all cyber threats and cyber risk across our Firm. To "protect the foundations and secure the future," Cyber Defense serves two mission areas: cyber threat management and defense (understanding, detecting, and responding to threats), and cyber risk management and governance (setting priorities and preventing threats).
Operational Security Testing is a global team with a presence in Switzerland, Poland, and the USA. Our team works across TS TISO and other security control areas to conduct red teaming, purple teaming, and other forms of offensive security testing to identify and help remediate gaps across all aspects of the Cyber Security protect, detect and response capabilities of our Firm.
Diversity helps us grow, together. That's why we are committed to fostering and advancing diversity, equity, and inclusion. It strengthens our business and brings value to our clients.
Your expertise
• ideally 3 years or more of experience as part of an offensive security team responsible for an organizations threat emulation and/or Red Team capabilities• experience and proficiency in the day-to-day operations of a Red Team with knowledge of offensive security tools, such as Metasploit, Nessus, Burp, Kali Linux / CommandoVM or C2 frameworks (e.g. Cobalt Strike, Brute Ratel, Sliver, Nighthawk)• experience in setting up infrastructure for Red Teaming operations and techniques utilized in reconnaissance, exploitation, persistence, lateral movement, command & control, etc.• knowledge and understanding of techniques evading detection across the defensive technology stack such as: networking, firewalls, IDS/IPS, EDR, Web Proxies, DLP, etc.• efficient documentation skills to capture the right level of detail at the right level of abstraction while creating process/dataflow/architecture diagrams, or documenting instructions• experience in exploit writing, evaluation of proof-of-concept exploit code, malware packing, payload encoding, obfuscation and delivery techniques, is a plus• experience in automation, ability to experiment and tweak newly developed open-source tools written in scripting languages (Bash, Perl, Python, Ruby, etc.), or other languages (C#, Java, C/C++, Rust, Nim, Assembly), is a plus• experience with cloud (Azure, AWS) technologies and offensive Security certifications (such as OSCP or OSEP), SANS certifications (such as GXPN, GPEN, GWAPT, GREM), or other training in red teaming operations are pluses
"At UBS, we appreciate our Veterans and are committed to providing opportunities in Financial Services."
*LI-UBS*UBS-MOGUL
About us
UBS is the world's largest and the only truly global wealth manager. We operate through four business divisions: Global Wealth Management, Personal & Corporate Banking, Asset Management and the Investment Bank. Our global reach and the breadth of our expertise set us apart from our competitors..
We have a presence in all major financial centers in more than 50 countries.
Join us
At UBS, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.
From gaining new experiences in different roles to acquiring fresh knowledge and skills, we know that great work is never done alone. We know that it's our people, with their unique backgrounds, skills, experience levels and interests, who drive our ongoing success. Together we're more than ourselves. Ready to be part of #teamUBS and make an impact?