Security Operations Specialist

Open 36d reposted 2× · 2 open copies

As a Security Operations Specialist, you will monitor and maintain security operations, ensuring alignment with regulatory requirements and business policies. You will actively contribute to improving the organizational security posture and support continuous compliance efforts. This role involves implementing robust security controls to safeguard systems and data. Furthermore, you will be responsible for responding effectively to security incidents within established frameworks.

  • Vulnerability Management: Conduct continuous asset discovery, automated vulnerability scanning, false positive analysis, and manage the closure and re-testing of identified vulnerabilities.
  • Penetration Testing: Perform deep-dive infrastructure, web, mobile application (DAST/manual, OWASP Top 10, OMTG), and segmentation penetration testing.
  • Red Teaming & Adversary Simulation: Lead "Assume Breach" simulations, execute complex attack chains (lateral movement, privilege escalation), and develop evasion techniques against security controls.
  • Telecom Core Targeting: Conduct specialized attacks against critical telecom systems (OSS/BSS, HLR, VLR, MSC) to identify risks to subscriber data and call routing.
  • APT Simulation: Replicate real-world adversary Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework.
  • Attack Surface Management (ASM): Monitor for "Shadow IT" and exposed digital assets through automated black-box reconnaissance and risk prioritization.
  • Dark Web Monitoring: Proactively monitor dark web forums, paste-sites, and messaging channels for leaked telecom-specific data and credentials.
  • Reporting & Mentorship: Evaluate Blue Team performance during exercises, and produce high-quality Proof-of-Concepts (PoCs) and remediation roadmaps for technical and executive stakeholders.

Must-Have:

  • A minimum of 9+ years in Offensive Security/Red Teaming, specifically within a Telecommunications or ISP environment.
  • This is explicitly stated as a minimum required certification is OSCP Certification.
  • Expert MITRE ATT&CK Framework understanding and applying adversary tactics, techniques, and procedures.
  • Advanced Exploitation Techniques proficiency in methods such as Kerberoasting, Pass-the-Hash, Golden Ticket, PowerShell/Bash scripting, and EDR bypass.
  • Foundational Telecom Protocol understanding of SS7, GTP, and Diameter, which is critical for the specified environment.

Nice-To-Have:

  • Advanced Certifications (OSEP, OSWE, or CRTP): While OSCP is a minimum, possessing one of these advanced certifications demonstrates a higher level of specialized expertise.
  • NIST Security Standards Knowledge: Beyond the expert knowledge of MITRE ATT&CK, familiarity with NIST security standards would be a valuable complementary skill.
  • Deep Understanding of NOC/SOC Workflows: While a deep understanding of Network Segmentation and Active Directory is listed, specific insight into NOC/SOC workflows would be beneficial for red teamers to understand blue team operations and evasion techniques.