Sr Cyber Security Engineer -Threat Simulation

Overview

On Site
USD 160,000.00 - 180,000.00 per year
Full Time

Skills

Geographic Information System
Testing
Internet
Cyber Security
Pivotal
Threat Analysis
Research
Knowledge Transfer
Mentorship
Security Awareness
Knowledge Sharing
Information Security
Penetration Testing
Emulation
Apache Bloodhound
Burp Suite
Security Controls
Finance
Scripting Language
Python
Windows PowerShell
C#
Microsoft Windows
Linux
Hardening
Cloud Computing
Amazon Web Services
Microsoft Azure
Google Cloud Platform
Google Cloud
Financial Services
OSCP
GPEN
Emerging Technologies
Artificial Intelligence
Machine Learning (ML)
OS X
MEAN Stack
Customer Service
Training And Development
SAP BASIS

Job Details

Software Guidance & Assistance, Inc., (SGA), is searching for an Sr Cyber Security Engineer for a FULL TIME assignment with one of our premier Financial Clients clients in Chicago, IL .

Join our client's Global Information Security (GIS) department as a Sr. Cyber Security Engineer - Threat Simulation. You will be an integral part of our Offensive Security organization, directly contributing to improving security posture. This high-impact role is responsible for the execution of Red Team adversary emulations against our complex hybrid environment, proactively testing and strengthening our internal and internet-facing systems.

You'll also be a key participant in Purple Team activities to continuously improve the organization's cyber detection and response capabilities. This is a perfect opportunity for a sharp, action-oriented engineer to become a key part of a team of highly skilled cybersecurity professionals who execute a pivotal role in protecting and defending national critical infrastructure.

Responsibilities :
  • Execute high-impact Red Team exercises against our complex hybrid cloud environments, driven by real-world threat intelligence and the MITRE ATT&CK Framework.
  • Engineer and maintain robust Red and Purple Team infrastructure, continuously automating processes for efficiency and scale.
  • Co-design and lead joint Purple Team exercises, directly partnering with cyber defense to improve detection and response capabilities.
  • Innovate through continuous research into new offensive security TTPs (Tactics, Techniques, and Procedures) and drive knowledge transfer across the security organization.
  • Conduct specialized, ad-hoc offensive security tests utilizing industry-leading and internally developed tooling to uncover subtle security gaps.
  • Author comprehensive post-exercise reports, including detailed technical findings, compromise narratives, and strategic, risk-rated recommendations for remediation.
  • Mentor cyber defense teams during incident investigations, providing critical subject matter expertise on attacker tradecraft and mindset.
  • Champion security awareness and technical knowledge-sharing by collaborating with information security, technology, and business stakeholders
Required Skills:
  • We're looking for an engineer with a robust offensive mindset and a proven track record of breaking and building in complex enterprise environments.
  • 5+ years' experience wielding industry-standard penetration testing and adversary emulation tools (e.g., Cobalt Strike, Sliver, Mythic, Bloodhound, Burp Suite).
  • Expert understanding of the MITRE ATT&CK Framework and advanced evasion techniques used to bypass modern security controls.
  • Strong comprehension of the cyber kill chain and the full lifecycle of an Advanced Persistent Threat (APT) targeting financial institutions.
  • Proficiency in at least one scripting language (e.g., Python, PowerShell) and experience with a compiled language (e.g., Go, C#) for tool development.
  • Deep experience attacking and securing complex cloud, on-prem, and hybrid environments, from initial access through actions on objective.
  • Solid knowledge of Windows and Linux system hardening concepts, Purple Team automation strategies, and vulnerability rating methodologies.
  • Proven experience with security within at least one major cloud provider (e.g., AWS, Azure, Google Cloud Platform).

Preferred Skills:
  • Previous hands-on experience performing sophisticated adversary emulations/simulations specifically within the financial services sector.
  • A recognized offensive security industry certification (e.g., OSCP, GPEN, GXPN, OSWE, eCPTX) demonstrating specialized, high-impact skills.
  • Familiarity with modern enterprise security standards and frameworks (e.g., TIBER-EU, CBEST, NIST CSF).
  • Experience conducting offensive security exercises against emerging technologies, such as AI/ML systems or macOS.

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.\

#LI-NK1
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About Software Guidance & Assistance