Every day, Global Payments makes it possible for millions of people to move money between buyers and sellers using our payments solutions for credit, debit, prepaid and merchant services. Our worldwide team helps over 3 million companies, more than 1,300 financial institutions and over 600 million cardholders grow with confidence and achieve amazing results. We are driven by our passion for success and we are proud to deliver best-in-class payment technology and software solutions. Join our dynamic team and make your mark on the payments technology landscape of tomorrow.
Conducts planned and authorized real world attack scenarios against corporate assets, networks and applications utilizing common hacking methodologies and tools. Leveraging industry standard methodologies, evaluates corporate security posture through various technical, manual and automated methods to accomplish various designated goals such as the review and evaluation of software or network architecture and design (consulting), the coordinated validation of defensive controls (purple team), attempted exploit, pivot and exfiltration of data (red team) and manual review / validation of the existence of vulnerabilities on systems (penetration testing). This is a highly technical and specialized position within security that requires a wide array of experience, knowledge and discipline in all aspects of IT (development, operations and security).
-
Independently leads an assigned team of junior level resources on the planning, coordination, research and execution of engagements. Identifies potential targets and develops scenarios for future engagements. Can execute tests on a wide array of systems beyond specialties. Has developed skills in scripting, query and / or traditional coding languages. Understands and can articulate vulnerability impacts and exploit methods to junior members of the team or customers as needed.
-
Oversee the documentation and reporting for assigned engagements. Ability to independently identify and document scope/objectives and approve the documentation of junior members of the team. Responsible for the quality and accuracy of all documentation and reporting for an engagement.
-
Leads efforts to perform accurate analysis of targets and objectives as well as the analysis of results, risks and findings. Ability to clearly and professionally coordinate engagement efforts. Ability to review and approve junior team member's work and provide structured opportunities for learning. Ability to evaluate and recommend remediation actions independently and advise internal customers on secure techniques on various systems, applications and/ or networks.
-
Ability to instruct and consult other team members on security principles and the appropriate design and hardening of applications, systems and networks. Able to evaluate complex situations and execute outcomes favorable to the organization. Able to apply corporate and security ethics in every aspect of day to day activities
Minimum Qualifications
-
Bachelor's Degree
-
Relevant Experience or Degree in: with a concentration in security, networking or development / computer science
-
Typically Minimum 6 Years Relevant Exp
-
Ethical Hacking/Penetration Testing, software development, cyber forensics or threat hunting. Additional 4 years related experience may be considered in lieu of a degree.
-
Certified Ethical Hacker (CEH) or GIAC Penetration Tester (GPEN) or equivalent certification
Preferred Qualifications
-
Typically Minimum 8+ Years Relevant Exp
-
Ethical Hacking/Penetration Testing, software development, cyber forensics or threat hunting.
-
one or more of the following: CISSP, CEH, GPEN, GXPN, GWAPT, OSCP
-
Skills / Knowledge - Having wide-ranging experience, uses professional concepts and company objectives to resolve complex issues in creative and effective ways. Some barriers to entry exist at this level (e.g., dept./peer review).
-
Job Complexity - Works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Exercises judgment in selecting methods, techniques and evaluation criteria for obtaining results. Networks with key contacts outside own area of expertise.
-
Supervision - Determines methods and procedures on new assignments and may coordinate activities of other personnel (Team Lead).
-
Experience with vulnerability exploit techniques and tools. - Ability to setup, configure and utilize ethical hacking tools and exploits. Ability to develop exploits and demonstrate impacts to others
-
Proficient in research and analysis of security intelligence data, system/application/network configurations and logs - Ability to understand and execute complex analysis of intelligence data as well as systems/application/network configurations and logs to determine preliminary threats, targets and evaluate risk appropriately. Ability to apply controls to safely traverse the dark web for research purposes.
-
Experience with activities involving APT Threats - Ability to describe various tools, techniques, and procedures (TTPs) associated with threat actors known to operate in the financial services domain.
Global Payments Inc. is an equal opportunity employer. Global Payments provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex (including pregnancy), national origin, ancestry, age, marital status, sexual orientation, gender identity or expression, disability, veteran status, genetic information or any other basis protected by law. If you wish to request reasonable accommodations related to applying for employment or provide feedback about the accessibility of this website, please contact [email protected].