Job description
General information
Ally and Your Career
The Opportunity
To read more about what our tech team does, be sure to visit our tech blog at ally.tech
As the Principal Purple Team Engineer, you will be a part of our Threat Emulation and Offensive Security Team (Red Team). Responsibilities include conducting adversarial simulations and threat hunting exercises from start to finish. This includes scoping, testing, reporting, and presenting high quality deliverables to application/network owners. To be successful in this role, a candidate should have a broad knowledge of Blue Team and Red Team methodologies and be highly technical. The candidate should have an insatiable hunger for knowledge and developing professional skills. The candidate is expected to keep up to date with the continuously evolving threat landscape.
The Work Itself
- Conduct threat hunts and adversarial simulations from start to finish
- Partner with other departments to help improve overall security
- Continuously build and improve red team and blue team processes
- Developing training content and conducting trainings with a team of highly skilled operators
- Act as a SME for red team and blue team
- Write comprehensive findings reports with high attention to detail
- Build, develop, and maintain automation projects and tools used by the red team
- Identify and exploit obscure vulnerabilities
The Skills You Bring
- Hands-on experience
- 3+ years Experience with programming and scripting languages (Perl, Python, C#, Rust, Go, etc.)
- Experience network level red teaming and emulating advanced adversarial TTPs
- Experience with evading antivirus, EDR, and email sandboxing solutions
- Experience with social engineering, including building infrastructure for testing
- Experience with payload development
- Experience threat hunting and using EDR tools and monitoring solutions
- Ability to conduct a red team engagement or threat hunt from start to finish
- Hands-on certifications (Offensive Security, eLearn, Zero Point, etc.) or willingness to acquire within 12 months
- Deep understanding of Active Directory
- Experience with Cobalt Strike and malleable C2s
- Ability to think outside the box and identify unique attack paths to move laterally
Nice to Haves
- Web app / API penetration testing experience
- Knowledge of cloud penetration testing and red teaming
- Experience with physical red teaming
- Ability to travel up to three times a year
- Community involvement (blogs, forums, HTB, social media, etc.)
- Having published CVEs
How We'll Have Your Back
- Time Away: competitive holiday and flexible paid-time-off, including time off for volunteering and voting.
- Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan and 529 educational assistance programs, tuition reimbursement, and other financial well-being programs.
- Supporting your Health & Well-being: flexible health and insurance options including dental and vision, pre-tax Health Savings Account with employer contributions and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially.
- Building a Family: adoption, surrogacy, and fertility support as well as parental and caregiver leave, back-up child and adult/elder day care program and childcare discounts.
- Work-Life Integration: other benefits including LifeMatters® Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
Who We Are:
Ally Financial is a customer-centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial-services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com.
Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.
We are committed to working with and providing reasonable accommodation to applicants with physical or mental disabilities. For accommodation requests, email us at work@ally.com. Ally will not discriminate against any qualified individual who is capable of performing the essential functions of the job with or without reasonable accommodation.
caravetterealestate.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, caravetterealestate.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, caravetterealestate.com is the ideal place to find your next job.