Listing Description
The Role
As a Senior Offensive Security Engineer, you will leverage your technical, creative, and adversarial mindset to proactively identify gaps, flaws, and vulnerabilities in Proofpoint's detection platforms. This is a highly technical role that requires the ability to grasp complex systems, validate behavioral assumptions, design and implement evasion/attack strategies, accurately assess risk, and persuasively communicate at multiple organizational levels. This highly impactful role is situated within Proofpoint's threat research team.
What you bring to the team:
• Intermediate experience with Linux and its core services (system, httpd, etc.); Kernel-mode experience a plus
• Significant experience with Sandboxing including methods for evasion and escape
• Experience with virtualization technologies such as KVM/libvirt
• Experience conducting vulnerability research using a variety of tools, methods, and approaches
• Experience with various file formats (e.g. archive formats), and the weaponization thereof
• Experience leveraging fuzzing to discover vulnerabilities
• Experience with exploit development methodology (x86/x64 preferred)
• Ability to find vulnerabilities based on source code review
• Intermediate to Advanced-level python
• Outstanding verbal and written communication skills
• Proven ability to work remotely and collaboratively across teams
• Highly self-directedStay abreast of the latest attacker techniques, vulnerabilities, and penetration testing tools and methods
Technically assess the impact of announced vulnerabilities and exploits on Proofpoint detection platforms
Work with Engineering and Security Researchers to thoroughly understand Proofpoint threat detection platforms
Design strategies to expose unknown coverage gaps in detection platforms
Design proofs-of-concept to expose design or implementation flaws that could bypass detection
Work in a self-directed fashion to scope, prioritize, coordinate attack strategies
Iteratively develop a framework for documenting, communicating, monitoring and achieving appropriate responses to identified risk
Listing Details
- Citizenship: Us Citizen
- Incentives: Not Provided
- Education: Bachelors Degree
- Travel: Travel 25
- Telework: Full Telecommute