At a Glance
- Tasks: Join our team to craft and execute innovative social engineering campaigns that challenge security norms.
- Company: Rapid7, a leader in cybersecurity with a dynamic and collaborative culture.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Be part of a cutting-edge Red Team operation with excellent career advancement opportunities.
- Why this job: Make a real impact by testing and improving clients' security postures through creative attack strategies.
- Qualifications: 5+ years in technical security, strong social engineering skills, and knowledge of penetration testing tools.
The predicted salary is between 60000 - 80000 £ per year.
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defence strategies.
About the Team
Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defence-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.
About the Role
Your primary responsibility is to deliver Rapid7’s Vector Command Continuous Red Teaming service. In this role, you will design social engineering campaigns which function at scale, supporting numerous customers each month, emulating modern adversary TTPs. These campaigns focus on initial access, not click rates, and are often combined with external vulnerabilities or misconfigurations to demonstrate real-world impact. Specifically, your focus will be to:
- Deploy, configure, and maintain social engineering infrastructure to perform phishing operations at scale.
- Perform manual and automated reconnaissance at scale to identify targets for social engineering operations each month.
- Leverage external network vulnerabilities reported by Vector Command team members in targeted real-world social engineering attacks (incorporate subdomain takeovers, cross-site scripting, etc. into campaigns).
- Research the latest techniques in social engineering and implement them in monthly campaigns.
- Research and test methods to bypass social engineering defenses such as email filters, download restrictions, multi-factor authentication mechanisms, etc.
- Be an expert in sending phishing emails which make it to the client’s inbox.
- Design and execute vishing campaigns.
- Incorporate payloads provided by the Red Team lead into phishing and vishing operations.
- Upon successful credential breach or payload execution, evaluate the impact and coordinate with Vector Command team members for post-compromise breach simulation.
- Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.
- Develop and maintain positive relationships with clients and understand their business and needs.
- Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices.
The skills and qualities you’ll bring include:
- 5+ years in an active technical security role
- Strong knowledge of the following:
- Advanced Social engineering techniques and tactics
- Infrastructure management and deployment (domain records, web servers, terraform, ansible, phishing website creation).
- Modern penetration testing tools and methods
- Network, wireless and web application security concepts
- Experience using interpreted languages (Ruby, Python, PHP, etc.)
- Knowledge of common regulatory structures and obligations and common I.T. governance.
- Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet-facing attack surfaces
- Certifications such as OSCP, OSCE, GXPN, OSEE, CREST
Penetration Tester, Vector Command, Social Engineering Specialist employer: Divvy Cloud Corp.
At Rapid7, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture. As a Penetration Tester in our Vector Command team, you will not only enhance your technical skills but also have the opportunity to engage in meaningful projects that directly impact our clients' security posture. With a focus on employee growth, we offer continuous learning opportunities and a supportive environment that encourages creativity and professional development.
StudySmarter Expert Advice🤫
We think this is how you could land Penetration Tester, Vector Command, Social Engineering Specialist
✨Tip Number 1
Network with industry professionals! Attend meetups, conferences, or online webinars related to penetration testing. This is a great way to learn about job openings and get insider info on what companies are looking for.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your past projects, especially any social engineering campaigns or penetration tests you've conducted. This will give potential employers a taste of what you can do.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each company. Research their security posture and mention how your skills can specifically help them improve. This shows you're genuinely interested and not just sending out generic applications.
✨Tip Number 4
Apply through our website! We often have exclusive roles listed there that might not be found elsewhere. Plus, it’s a direct line to us, making it easier for you to stand out in the crowd.
We think you need these skills to ace Penetration Tester, Vector Command, Social Engineering Specialist
Some tips for your application 🫡
Show Off Your Skills:When you're writing your application, make sure to highlight your technical skills and experience in penetration testing. We want to see how you’ve tackled challenges in the past and what tools you’re comfortable using. Don’t hold back—this is your chance to shine!
Tailor Your Application:Make your application stand out by tailoring it to the role. Use keywords from the job description, like 'social engineering' and 'reconnaissance', to show that you understand what we’re looking for. This helps us see how you fit into our team right from the start.
Be Clear and Concise:Keep your application clear and to the point. We appreciate a well-structured application that gets straight to the facts. Use bullet points if necessary to make it easy for us to read through your experience and qualifications.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our company and what we do.
How to prepare for a job interview at Divvy Cloud Corp.
✨Know Your Stuff
Make sure you brush up on your technical skills and knowledge of penetration testing. Familiarise yourself with the latest social engineering techniques and tools, as well as the specific methodologies used by the company. Being able to discuss these confidently will show that you're not just a candidate, but a potential asset to their team.
✨Showcase Your Experience
Prepare to share specific examples from your past roles where you've successfully executed penetration tests or social engineering campaigns. Highlight any unique challenges you faced and how you overcame them. This will demonstrate your problem-solving skills and ability to think on your feet.
✨Understand the Company’s Needs
Research Rapid7 and their Vector Command team thoroughly. Understand their approach to security and what they value in a penetration tester. Tailor your responses to show how your skills align with their goals and how you can contribute to improving their clients' security posture.
✨Ask Insightful Questions
Prepare thoughtful questions about the role, the team dynamics, and the types of projects you might work on. This not only shows your interest in the position but also helps you gauge if the company culture and expectations align with your career goals.