Consulting Services: Associate, Consultant, Sr. Consultant

SpecterOps is looking for associate, mid-level & senior consultants to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive assessment services (red team assessments, penetration tests, defensive capability tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives. A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual. Salary Range: Base salary annually, commensurate with experience. • Associate Consultant: $90,000 - $115,000 • Consultant - $115,000 - $135,000 • Senior Consultant - $135,000 - $160,000 Location: This position is remote, based in the U.S. with optional travel quarterly for in person company events and other ad hoc meetings. • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas Responsibilities • Plan and conduct offensive engagements ranging in size, scope, focus, and approach • Effectively communicate findings, attack paths, and recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations • Build scripts, tools, or methodologies to enhance offensive services • Serve as a subject matter expert (SME) in one of the following areas: initial access, intelligence analysis, adversary tradecraft, offensive Windows/Nix/macOS operations, evasion operations, or technical capability development • Utilize common offensive security testing tools and tradecraft • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities • Effectively communicate successes and obstacles with fellow team members and team lead(s) • Interface with client contact(s) and staff in a constructive and professional manner • Coordinate and prepare for internal and customer facing meetings • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc) Requirements (All Positions) • Ability to travel domestically and internationally an average of 25% over the course of one year, this may include bursts up to 50% • Must be able to pass a criminal background check • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency Associate Consultant: As an Associate Consultant, your primarily responsibility will be to learn. You will engage, participate, and contribute to the execution of a variety of services and projects. In doing so, you will actively develop a basic understanding of the SpecterOps Adversary Simulation service line and develop skills in one or more technical areas. Desired Qualifications: • Foundational knowledge of offensive security concepts and assessments • Foundational knowledge of security principles, policies, and industry best practices • Working knowledge of Windows and *NIX-based operating systems • Working knowledge of networking concepts • Working knowledge of Active Directory • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc • Aptitude for technical writing, including assessment reports, presentations and operating procedures • Strong written/verbal communication and interpersonal skills • Determination to better self and the overall information security community through research efforts and release through blog posts, conference talk delivery, open-source tool release, and white paper publication • Willingness to support delivery of public and private training offerings (e.g., providing lab support, fielding student questions, etc) Consultant: As a Consultant, you will independently contribute to significant services and projects. You will be responsible for the entire lifecycle of small to medium-size services and projects. Desired Qualifications-Must meet the desired qualifications for an Associate Consultant, plus the following: • Foundational knowledge of defensive security concepts and assessments • Working knowledge of offensive security concepts and assessments • Working knowledge of common regulatory requirements and governance frameworks • Proficient with Windows and *NIX-based operating systems and related offensive techniques • Proficient with networking concepts and related offensive techniques • Proficient with Active Directory and related offensive techniques • Ability to lead small to medium sized services and projects • Ability to communicate effectively with customers, team members and upper management for project delivery • Ability to contribute to the majority of offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, defensive capability test, etc) as part of a team for the full project lifecycle • Strong analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with attention to detail and accuracy Senior Consultant: As a Senior Consultant, you will be responsible for the entire lifecycle of significant services and projects. Desired Qualifications - Must meet the desired qualifications for a Consultant, plus the following: • A clear expert in one or more service lines and/or technical areas • Ability to lead and execute the majority of offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, defensive capability test, etc) • Experience leading small teams and engagements • Experience managing multiple projects at once • Experience communicating with clients and delivering presentations • Experience independently managing client projects • Willingness to develop and deliver training content as a lead course instructor • Willingness to mentor and train fellow consultants Nice to Haves (All Positions) • Bachelor's degree in a technical field • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development) • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments • Experience in technical writing • Experience working for a service-based information security consultancy • Experience developing and/or providing technical training • Desire to teach and train students in offensive techniques • Desire to travel internationally and domestically on a more frequent basis (more than 50%) What We Offer • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family • Flexible time off policy • 10+ paid holidays annually • 401(k) with up to 4% company match • Equity and a potential bonus based on company performance • Remote work: $2,000 first year allowance to set up home office • Open intellectual property policies; allow researchers to retain rights over open sourced research & tools • $150 monthly cell phone and internet reimbursement • $5,000 annual professional development allowance • $5,250 towards continuing education or student loan repayment • $100 monthly reimbursement for lifestyle, wellness, pet insurance or home office expenses • A one-time $10,000 benefit towards family planning • In person and virtual employee events throughout the year • And of course, company swag! All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. Unsolicited resumes are not accepted #LI-REMOTE Apply tot his job

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...