Offensive Security Cyber Security Research Consultant

Wells Fargo
Charlotte, North Carolina, United States
20 days ago


About this role:

Wells Fargo is seeking a Cyber Security Research Consultant to join its Offensive Security Application Research team. This role will involve performing cutting-edge research on new attack vectors, techniques, and tactics. This role will emulate adversarial attacks in order to provide information to Wells Fargo Lines of Business with the overall goal of providing knowledge of indicators or compromise and TTP (Tools, Tactics, and Procedures) to other teams. Team member will be responsible for creating attack chains and will explain how combining different weaknesses can result in higher impact. This team member must be able to utilize complex hacking tools, create proof of concept exploits, and document attack chains so they can be re-created and defensive tactics developed for them. This role will research, analyze, design, test, and implement complex technologies, systems, and applications. This position will work closely with our partners in a purple team capacity.

In this role, you will:
  • Participate in the research, analysis, design, testing and implementation of medium to complex computer network security and protection technologies
  • Act as professional ethical penetration tester utilizing hacking tools to modify or create proof of concept exploits that mimic techniques of attackers to identify vulnerabilities and associate with a severity rating by deriving impact and ease of exploit
  • Review and analyze security vulnerabilities for the company's networks, application systems, hardware infrastructure and emerging technologies to improve the enterprise information security posture
  • Perform basic computer security incident response activities and technical investigations of information security related incidents
  • Present recommendations to the line of business on the inherent risks, providing meaningful mitigation strategies
  • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
  • Interact with internal customers
  • Receive direction from leaders and exercise independent judgment while developing the knowledge to understand function, policies, procedures, and compliance requirements
Required Qualifications, US:
  • 2+ years of Cyber Security Research experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 1+ years of web application penetration testing
  • 2+ years of information security experience in converged testing (red teaming)
  • 2+ years of experience in one or a combination of the following: creating proofs of concept, creating exploits, or reverse engineering
  • 1+ years of performing white hat exploitation and post-exploitation experience
Desired Qualifications:
  • Expert Information Security technical skills
  • Proficient in working with systems, networks, and application vulnerability testing
  • Security engineering experience that includes knowledge and understanding of recent research and industrial advances in one or more of the following areas: computer and communication networks, cyber security threat detection, cyber security experimentation and testing, innovative research in cyber security, physical security controls and their weaknesses, debugging, hardware and device hacking, or electronics security
  • Knowledge of Python, Ruby, PowerShell, and Shell Scripting
  • Ability to work effectively, as well as independently, in a team environment
  • Experience working in a large enterprise environment
  • Strong analytical skills with high attention to detail and accuracy
  • Knowledge and understanding of system/application architecture and design concepts
Job Expectations:
  • Conduct innovative research in cyber security
  • Conduct active offensive security operations
  • Develop custom penetration testing tools
  • Develop in-depth findings report
  • Communicate findings to lines of business based on inherit risks
  • Participate in purple teaming
  • Collaborate with customers and partners on matters of security

We Value Diversity

At Wells Fargo, we believe in diversity, equity and inclusion in the workplace; accordingly, we welcome applications for employment from all qualified candidates, regardless of race, color, gender, national origin, religion, age, sexual orientation, gender identity, gender expression, genetic information, individuals with disabilities, pregnancy, marital status, status as a protected veteran or any other status protected by applicable law.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in US: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Job Information

  • Job ID: 62998299
  • Location:
    Charlotte, North Carolina, United States
  • Company Name For Job: Wells Fargo
  • Position Title: Offensive Security Cyber Security Research Consultant
  • Job Function: Other
  • Job Type: Full-Time
Jobs You May Like