Director, Ethical Hacking

| Hybrid
Sorry, this job was removed at 10:22 p.m. (CST) on Tuesday, November 30, 2021
Find out who's hiring in Chicago, IL.
See all Operations jobs in Chicago, IL
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Job Summary
Leadership position responsible for advising security and technology leadership on ways to reduce CNA's threat landscape. This position develops strategy for the following areas: Ethical Hacking Red-Team and Purple team cyber threat assessments and social engineering campaigns. This function oversees all penetration testing related operations work. This position also serves as the subject matter expert for leveraging various TTPs utilized by various threat actors to help CNA understand whether an actual threat actor using similar techniques would be able to accomplish specific objective(s).
Essential Duties & Responsibilities
Performs a combination of duties in accordance with departmental guidelines:

  • Develops and delivers the Ethical Hacking initiatives and roadmaps after initial assessment of the environment.
  • Builds leads and has full management responsibility for the performance and development of Ethical Hacking team.
  • Collaborates with leaders to define secure approach by analyzing information requirements; determines systems architecture components and technologies; studies business capabilities; develops points of views on emerging technologies and evaluates their applicability to business goals and operational requirements.
  • Provides coaching guidance and direction on Ethical Hacking activities ensuring overall fit CNA InfoSec direction.
  • Participates in technical testing against CNA's WebApps infrastructure and network assets from operational planning initiation and remediation to reporting
  • Communicates findings attack paths and recommendations to technical non-technical and senior leadership through written reports and verbal presentations.
  • Oversees the development of scripts tools techniques and methodologies to improve the overall ability of the team to deliver high-quality tests.
  • Helps develop and employ advanced internal networks wireless networks mobile applications thick-client applications embedded applications or hardware penetration testing techniques.
  • Responsible for development and contribution to Red-Team's Tactics Techniques and Procedures (TTPs) knowledge base
  • Demonstrates an understanding of penetration testing techniques and methodologies.
  • Develops and customizes payloads specific to the environment software version or for evasion of defensive technologies related to mobile applications.
  • Establishes performance metrics and leverage metrics to drive control and process improvements.


May perform additional duties as assigned.
Reporting Relationship
Typically AVP or above
Skills Knowledge & Abilities

  • Senior-level knowledge of tools associated with penetration testing (Metasploit Burp Suite Cobalt Strike etc.)
  • Ability to effectively code in a scripting language (Python Perl etc)
  • Expert level knowledge of Ethical Hacking Red Team Pentesting and Social Engineering security concepts.
  • Proven ability to effectively lead coach and develop a team.
  • Senior-level knowledge of platform security technical solutions (to properly gauge compensating controls and their affect)
  • Senior-level knowledge of modern security architectures (i.e. Zero Trust Architecture)
  • Demonstrated success in establishing strategic objectives and driving tactical execution of initiatives aligned with company goals and objectives.
  • Subject matter expertise across all facets of Ethical Hacking


Education & Experience

  • Bachelor's degree in Computer Science or related discipline or equivalent work experience
  • Typically a minimum of ten years in Information Technology preferably with Penetration testing experience
  • Applicable certifications preferred (e.g. OSCP GPEN OSCE)
Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • JavaLanguages
    • JavascriptLanguages
    • KotlinLanguages
    • PerlLanguages
    • PythonLanguages
    • RLanguages
    • SqlLanguages
    • jQueryLibraries
    • jQuery UILibraries
    • ReactLibraries
    • Node.jsFrameworks
    • SpringFrameworks
    • AccessDatabases
    • DB2Databases
    • Microsoft SQL ServerDatabases
    • MySQLDatabases
    • OracleDatabases
    • PostgreSQLDatabases
    • Google AnalyticsAnalytics
    • ConfluenceManagement
    • JIRAManagement
    • Microsoft ProjectManagement
    • SalesforceCRM
    • SendGridEmail
    • MarketoLead Gen

An Insider's view of CNA

How would you describe the company’s work-life balance?

Work-life balance has always been a priority for me. It always will be. CNA’s hybrid working model allows me to not only maximize collaboration with my peers but also take advantage of increased flexibility by combining remote and in-office work. I’m empowered to take control of my schedule based on what works best for me and my team.

Alison Massey

Agile Scrum Master Consultant

How do you collaborate with other teams in the company?

On the Security Advisory team, collaboration is key to what we do. We sit at a unique intersection of security goals and business objectives. By working across nearly every IT team at CNA, we balance the need for maintaining secure initiatives and keeping projects on track. It’s our job to find the best, secure path to ‘Yes’ for business requests.

Zach Jones

Director, Security Advisory

How has your career grown since starting at the company?

I joined CNA as a contractor and became a full-time employee after an eight-year contractor journey. I’m passionate about solving technical challenges and CNA allows me to foster that passion. Every day, I learn about emerging technologies. I’m empowered to develop, grow, and create a career that works for me and my lifestyle.

SenthilKumar Asokan

Applications Engineer Senior Specialist

How do your team's ideas influence the company's direction?

Enterprise Architecture creates foundations for IT expectations across CNA. I’m on a team that builds reusable IT assets, communicates best practices, and decides standards for tooling, and more. I influence CNA outside of my role, too, specifically through CNA’s Employee Resource Groups. I’m empowered to influence both IT and our culture of inclus

Lisa Smith

Architecture Senior Specialist

What does career growth look like on your team?

Career growth can take on many different forms at CNA, and that’s because there are always opportunities to acquire transferrable skills. On my team specifically, we’re encouraged to identify and work toward development opportunities that matter to us. We’re empowered to make a difference while advancing our careers.

Josie Lee

Director, HR Business Partner

What are CNA Perks + Benefits

CNA Benefits Overview

One of the many advantages of working at CNA is the benefits program we offer you and your eligible dependents,
beginning on the first day of your employment. The program features a variety of plans that provide health care
benefits, well-being, disability and survivor protection, and 401(k) savings, among others. Below are highlights
of the offerings.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Diversity employee resource groups
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Employee stock purchase plan
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Generous parental leave
Family medical leave
Adoption Assistance
Vacation + Time Off
Generous PTO
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Some meals provided
Relocation assistance
Onsite gym
Professional Development
Job training & conferences
Tuition reimbursement
Lunch and learns
Online course subscriptions available
Paid industry certifications

More Jobs at CNA

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about CNAFind similar jobs like this