Senior Offensive Security Specialist
Deloitte — Netherlands · Posted ~21 hours ago
🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.
Log in to add to target listDescription
This job in a nutshell:
Help improving cyber resilience of our clients by engineering, hacking and emulating real-world threats against challenging IT environments.
At Deloitte.
Benefits:
You’ll receive a profit-sharing bonus, on top of your fixed salary.
Continuous professional growth.
Join our development program.
A work-from-home office setup allowance to make sure you have everything you need for an ergonomically designed workstation and internet allowance.
Work part-time (32 hours a week) or full-time (40 hours a week).
Flexible and hybrid working, in accordance with team and client commitments.
26 days of paid annual leave, and the opportunity to purchase additional leave.
A good mobility scheme: the choice of various options such as a lease car, travel by public transport, a cash option or a combination of these.
A laptop and iPhone.
The iPhone can also be used for personal purposes.
A time for time arrangement that creates flexibility for personal moments that matter.
A good pension scheme with a personal contribution of only 2%.
An opportunity to take part in our collective health insurance scheme.
An opportunity to benefit from tax-efficient facilities such as company fitness, a bicycle scheme or the opportunity to lease a bicycle.
The opportunity to use 55 hours of babysitting service per calendar year if your child is 12 years old or younger.
A flexible budget, which you can use to make choices in flexible benefits, for example purchasing extra leave days or financing a bicycle plan.
Various leave options tailored to meet your individual needs, from parental leave (also for rainbow families) to the flexibility of exchanging three national holidays for non-national holidays.
Qualifications:
You have a passion for offensive security, finding creative ways to break into highly secured environments identifying ways around defenses.
Moreover, in case you run into new types of environments or technologies you are able to develop new tools and techniques to reach your objective.
For the role of Senior Offensive Security specialist, you also have:a Computer Science degree or similar;a passion for offensive security and a drive to stay up-to-date with current exploits, attack techniques and new vulnerabilities;experience with the protocols at the various layers of the OSI model, think of: ARP, PPP, IPsec, IP, TCP, UDP, ICMP, TLS, SOCKS, ASCII, UTF-8, Base64, CRC, HTTP, QUIC, SMB, etc.;experience with web application security testing, using Burp exploiting SQL injection, file inclusion and HTTP request smuggling vulnerabilities, including experience with scripting to automate repetitive tasks;experience with complex infrastructures, both from an engineering and offensive perspective, evaluating possible entry points at the different layers of the protocol stack and exploiting those to get a foothold in the client's network and laterally move;experience evaluating the security of Windows and Linux operating systems and [Azure] Active Directory environments identifying possible escalation paths and security misconfigurations;relevant security certifications are preferred, some examples: OSCP, OSEP, OSWE, eCPTX, eWPTX, GXPN, etc.;excellent communication skills and fluency in written and spoken English.
What impact will you make?:
As a Senior Offensive Security Specialist, you will work in a highly skilled team to perform challenging security tests for our international clients.
Using your offensive and engineering skills you will exploit our clients’ networks, perform tactical network exploitation (TNE) and provide hands-on support to strengthen the client’s security posture.
To sharpen your skills, you will join the periodic Deloitte Global Offensive Security community knowledge exchange sessions, follow trainings and perform research on the latest techniques and tools.
How do you do this?:
finding creative ways to exploit the client's applications and infrastructure;applying hacker's mindset to bypass protections and identify cracks within target systems;providing clients with technical recommendations that match their situation and environment;turning security weaknesses into tailored and concrete recommendations which you will present to clients and provide hands-on support to help clients with improving their security postureperforming offensive research on new technologies and developing methodologies to evaluate the security of the setup and configuration;sharing your research within the Deloitte Global Offensive Security community and with the broader security community, for example writing blogs, speaking at conferences, or publishing code.
We have 64,022 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume — in under a minute we'll analyze all 64,022 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume