Red Team Lead
: Job Details :


Red Team Lead

USAA

Location: San Antonio,TX, USA

Date: 2024-11-16T08:37:55Z

Job Description:

**Why USAA?**

Let's do something that really matters.

At USAA, we have an important mission: facilitating the financial security of millions of U.S. military members and their families. Not all of our employees served in our nation's military, but we all share in the mission to give back to those who did. We're working as one to build a great experience and make a real impact for our members.

We believe in our core values of honesty, integrity, loyalty and service. They're what guides everything we do - from how we treat our members to how we treat each other. Come be a part of what makes us so special!

**The Opportunity**

The Cyber Threat Fusion and Emulation Team is seeking a motivated Red Team Lead with demonstrated experience in Red Teaming in large or complex organizations. The Red team is dedicated to support our Cyber Threat Operation Center (CTOC). The CTOC exists to detect, analyze, and respond to cyber security events. The CTOC is comprised of many teams that work together to achieve mission success. These teams are individual units that partner as needed to provide centralized and coordinated response activities. Our Cyber Red Team is responsible for conducting exercises modeled after real-world threat actors. The Red Team outcomes combined with the teams across Cyber Threat Fusion and Emulation continually enhance threat management capabilities to maximize our protective and detective cyber security posture and continuously improve our processes.

Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA's environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stays current with latest information security threats, exploits, trends, and intelligence.

We offer a flexible work environment that requires an individual to be **in the office 4 days per week.** This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Charlotte, NC. Relocation assistance is **not** available for this position.

**What you'll do:**

+ Influences and leads efforts across the Information Security department and enterprise as a subject matter expert in their domain.

+ Leads research efforts and analysis of the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with the enterprise. Collaborates in the Intelligence community with external organizations.

+ Serves as subject matter expert, leads, and improves the vulnerability management, security configuration assessment, and/or penetration testing programs.

+ Develops analysts through training and knowledge sharing activities.

+ Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g. suspicious behavior attacks, and security breaches). Trains analysts in incident detection and response. Leads and improves the incident response program.

+ Leads and responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Acts as leader for cyber incidents.

+ May testify as expert witness in court.

+ Incorporates discoveries from the incident response process to substantially improve the existing detection capabilities, operational processes, security controls, and overall program.

+ Prepares and delivers written and verbal briefs with recommendations to senior leadership and external parties on latest threats, alerts, incidents, and improvements.

+ Drives and directs quality work efforts. Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.

+ Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws, and regulations.

+ Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.

**What you have:**

+ Bachelor's degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.

+ 8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.

+ 6 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.

+ Expert level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.

+ Experience performing security reviews to identify gaps, resulting in recommendations for inclusion in risk mitigation strategies.

+ Experience investigating potentially malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.

**What sets you apart:**

+ 6+ years proven experience leading peers and team on execution of specific Red Team operations, mentoring, research, advanced analysis, executive reporting, maturing team functions, managed technical and business risks

+ Excellent knowledge of adversarial cyber actors, to include tactics, techniques, and procedures, and strong understanding of the intelligence lifecycle, analytic tradecraft, and attack methodologies such as MITRE ATT&CK.

+ Ability to identify threat actor TTPs and campaigns, gather information for reconnaissance, including large and unstructured data sets to identify trends and anomalies indicative of malicious cyber activities

+ Excellent communication and presentation skills with the ability to present to a variety of internal audiences including senior executives.

+ Ability to develop, execute and report Red Team operations and Purple Team engagements end to end

+ Knowledge of social-engineering techniques and methodology

+ Administrative and command line knowledge of operating systems (Windows, Linux, MacOS), applications and networks

+ Foundational knowledge in Red Team tooling or Offensive Security Tooling (OST)

+ Experience with scripting and development languages (e.g. Bash, PowerShell, Python, Perl, Ruby, PHP, C/C++,C#, Java, etc.)

+ Experience developing Red Team applications, tools and infrastructure (e.g. Windows API, implants, exploits, C2, etc.)

+ Knowledge of cloud infrastructure deployment and administration (i.e. AWS, GCP, Azure)

+ Understanding of firewalls, proxies, mail servers and web servers

+ Understanding of network, endpoint, cloud, and OWASP security principles

+ Any of the following certifications are highly desirable: GCIH, GPEN, GCPN, GXPN, OSCE, OSCP

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

**What we offer:**

**Compensation:** USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location. The salary range for this position is: $138,238-$264,200.

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

**Benefits:** At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

For more details on our outstanding benefits, please visit our benefits page on USAAjobs.com.

_Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting._

_USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran._

**If you are an existing USAA employee, please use the internal career site in OneSource to apply.**

**Please do not type your first and last name in all caps.**

**_Find your purpose. Join our mission._**

USAA is unlike any other financial services organization. The mission of the association is to facilitate the financial security of its members, associates and their families through provision of a full range of highly competitive financial products and services; in so doing, USAA seeks to be the provider of choice for the military community. We do this by upholding the highest standards and ensuring that our corporate business activities and individual employee conduct reflect good judgment and common sense, and are consistent with our core values of service, loyalty, honesty and integrity.

USAA attributes its long-standing success to its most valuable resource: our 35,000 employees. They are the heart and soul of our member-service culture. When you join us, you'll become part of a thriving community committed to going above for those who have gone beyond: the men and women of the U.S. military, their associates and their families. In order to play a role on our team, you don't have to be connected to the military yourself - you just need to share our passion for serving our more than 13 million members.

USAA is an EEO/AA Employer - applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity or expression, pregnancy, protected veteran status or other status protected by law.

California applicants, please review our HR CCPA - Notice at Collection ( here.

USAA is an EEO/AA Employer - applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity or expression, pregnancy, protected veteran status or other status protected by law.

Apply Now!

Similar Jobs (0)