About this role
Red Team Operator
At TransUnion, this role will report to a Director of Cybersecurity. We are seeking an experienced and highly skilled Red Teamer to join our Information Security Department. The Red Teamer will primarily be responsible for conducting in-depth Threat Emulation exercises such as Red Team Operations, Purple Team Operations, and Penetration Tests to assess the security of our systems, networks, and applications.
This is a remote position which may require occasional in-person attendance at work-related events at the discretion of management.
Role Overview and Core Responsibilities
- Conduct comprehensive threat emulation exercises, actively simulating cyber-attacks to uncover vulnerabilities in systems, networks, and applications.
- Collaborate with cross-functional teams to perform purple team exercises that challenge the organization’s overall security posture.
- Perform lateral movement within target environments to assess the effectiveness of internal network segmentation and access controls.
- Demonstrate expertise in local privilege escalation techniques.
- Emulate threat actors by replicating their techniques, tactics, and procedures to identify vulnerabilities and gaps in our defensive measures.
- Develop and utilize custom scripts, tools, and frameworks to enhance red team operations and mimic real-world attacks.
- Conduct reconnaissance activities to gather intelligence on potential targets and identify attack vectors.
- Test the security of cloud-based environments and identify weaknesses in configurations, access controls, and data protection mechanisms.
- Document and communicate findings, risks, and recommendations in clear and concise reports to stakeholders, including technical and non-technical audiences.
Required Knowledge and Experiences
- 5+ years of active experience in conducting penetration tests and actively working as a red teamer; proven track record in performing red team operations and purple team operations.
- Proficiency in ability to compromise a modern organization, escalate privileges, move laterally through complex networks, and achieve adversary goals.
- Strong experience and expertise in phishing techniques, social engineering tactics, and other initial access methods.
- Extensive experience in writing comprehensive and well-structured reports detailing findings, risks, and actionable recommendations.
- Basic development experience (python/bash/git/etc) to create custom solutions for bleeding edge problems.
We’re also looking for the preferred skills below. Whether you are proficient or could use some brushing