M

Information Security Consultant - Threat Detection & Adversary Simulation

MassMutual

Boston, MA
6 days ago

Job Description

Join MassMutual as an Information Security Consultant focusing on threat detection and adversary simulation. Leverage your expertise to enhance security through penetration testing and threat intelligence analysis while collaborating with teams to bolster incident response efforts.

Key Responsibilities

  • Provide technical guidance and hands-on leadership in security operations
  • Lead threat research, detection, and response efforts
  • Analyze and synthesize intelligence from various sources to identify risks
  • Oversee and execute adversary simulation exercises (red/purple team)
  • Research and develop offensive security techniques, tools, and automation frameworks
  • Advise on threat mitigation strategies
  • Lead and support incident response engagements

Required Qualifications

  • Bachelor's degree
  • 8+ years of experience in information security focusing on threat detection, incident response, and adversary simulation

Preferred Qualifications

  • Degree in Cyber Security, Computer Science, or Criminal Justice with a focus in Cyber Security
  • 10+ years of experience in information security focusing on threat detection, incident response, and adversary simulation
  • Proven ability to lead and develop threat hunting, detection engineering, and offensive security programs
  • Expertise in developing advanced threat detection rules, both signature-based and behavior-based analytics
  • Hands-on experience with offensive security tools such as CobaltStrike, Mythic, Evilginx, Outflank C2, and OST
  • Proficient in multiple programming languages including Python, C#, C/C++, and GoLang
  • Proficient in infrastructure automation using Terraform, Ansible, and CloudFormation
  • Proficient with SIEM and EDR platforms, including but not limited to Splunk, SumoLogic, and CrowdStrike Falcon EDR/LogScale
  • Strong understanding of identity management platforms like Okta, Microsoft EntraID, and Active Directory
  • Security automation expertise using Python scripting, Palo Alto Cortex XSOAR, and GitOps practices