About the Role
The Security Specialist, Offensive Security is responsible for testing the security controls, the network, and threat response for Intact Financial globally. This role employs techniques, tactics, and protocols to test security controls as part of a global offensive security team, reporting to the Director, Offensive Security.
Responsibilities
- Conduct reconnaissance on network environment to build external landscape using industry standard tools, threat intelligence feeds, OSINT and other readily available information sources.
- Conduct offensive security testing to ensure security controls and response actions are effective.
- Shift from a red team focus to a purple team approach if detected, aiming to strengthen controls throughout the entire attack chain across the enterprise.
- Employ attack strategies to simulate real-world attacks by threat actors and benchmark response capabilities across the enterprise.
- Identify and exploit vulnerabilities in computer systems, networks and applications to simulate attacks by threat actors.
- Analyze and report on the results of security assessments and make recommendations to improve the security posture of the enterprise.
- Understand the TCP/IP stack in depth and know how to exploit it to create covert beacons, C2 channels, exfiltrate data across DNS.
- Understand how routing tables work (e.g., BGP) and how they can be exploited.
- Work with regional cyber governance and risk teams to ensure that findings are properly tracked for remediation.
- Generate the required metrics and reports to support the CISO IFC Affiliates in reporting on enterprise security control effectiveness.
- Leverage industry standard and emerging tools to evaluate emerging threats to the financial services space and benchmark regions and affiliate companies to peers.
- Consume threat intelligence and apply the attack surface to crown jewel assets for target and tactic development.
- Propose clear rules of engagement for testing activities (either one time or perpetual) and ensure compliance to the ROE through all phases of testing.
- Maintain and update all offensive security tools, technologies and processes in line with company rules of engagement.
- Provide timely and effective communications to key internal stakeholders in alignment with policy and rules of engagement.
Requirements
- Advanced knowledge in computer networks, operational security platforms, information security principles, TCP/IP, DNS, UDP, BGP, SOC, IAM, SIEM, DLP, EDR, Threat intelligence, Incident Response, technical writing, information risk.
- A minimum of five (5) years of relevant professional experience in information technology.
- A minimum of three (3) years of experience in information security.
- Knowledge of offensive security operations, tools and techniques.
- Knowledge of information security standards, regulations and legislation (NIST, COBIT5, ISO 27001), an asset.
- Proficiency in manual testing techniques beyond automated scanning.
- Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
- Ability to take many vectors of technical vulnerability information (Pentest reports, vulnerability scanning data, SAST/DAST reports) and build an attack plan on critical assets.
- Ability to take highly technical data and results and translate them to business-friendly language to help non-technical stakeholders understand the approach, impact and outcome from offensive security operations.
- Analytical mind, pragmatic approach to IT security issues and problems.
- Strong partner in all areas, internally and externally, to provide a secure solution.
- Ability to reduce stress in situations that are stressful to you and others.
- Positive attitude, initiative with strong analytical and interpersonal skills to lead work groups, negotiate and build consensus.
- Ability to write and present material to communicate difficult concepts and gain consensus.
- Ability to work in a dynamic environment with multiple objectives.
- Highly motivated and self-directed, with attention to detail.
- Ability to prioritize and execute tasks in a high-pressure environment.
- Ability to deal diplomatically and effectively at all levels of the organization.
- Ability to challenge the status quo.
- Customer focused approach.
- For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country.
- Must be eligible to work in Canada.
Skills
- Offensive security testing
- Threat response
- Reconnaissance
- OSINT
- Exploiting vulnerabilities
- Evading modern EDR (Crowdstrike, MDE, SentinelOne)
- Privilege escalation
- TCP/IP
- BGP
- Threat intelligence consumption
- Python scripting
- Manual testing techniques
- OWASP Top 10
- MITRE ATT&CK
- CVSS scoring
- Technical writing
- Interpersonal skills
- Analytical skills
Location
- Global
- All regions
- All affiliate companies
Work Type
- Hybrid work model
Experience Level
- Minimum of five (5) years of relevant professional experience in information technology
- Minimum of three (3) years of experience in information security
Education Level
- Bachelor's degree in Computer Technology, Information Security, an asset
- Recognized certification in information security (CEH, CISM or other), an asset
Salary/Compensations
- 118,700 - 145,100 (based on a 35-hour workweek)
Benefits
- Flexible work arrangements
- Possibility to purchase up to 5 extra days off per year
- Telemedicine
- Wellness account
- Share plan & other savings (up to 12% of salary or more)
- Guaranteed income for life via defined benefit pension plan
- Annual bonus target (15%) with potential payout of up to double the target
- Employee Share Purchase Plan (ESPP) with Intact matching 50% of your net shares
About the Company
- Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times.
- Our employee promise represents Intact’s commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career.
- In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us.
- Pay at Intact is about much more than just salary.
- As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP).
- Our pension offerings provide flexibility and long-term security for our employees beyond their careers.
- We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.
Equal Opportunity
- We are an equal opportunity employer.
- At Intact, our Value of respect is founded on seeing diversity as a strength.
- We strive to create an accessible workplace where employees feel valued, included and encouraged to share their unique perspectives.
- We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community.
- As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people.
- We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations).
- If we can provide a specific adjustment to make the recruitment process more accessible for you, please let us know when we reach out about a job opportunity. We’ll work with you to meet your needs.
- Intact does not provide sponsorship or other support for immigration-related matters including but not limited to employer-specific closed work permits.
- Candidates must be eligible to work in Canada from the anticipated start date and throughout their employment and are solely responsible for maintaining their work eligibility.
