Information Security Consultant - Threat Detection & Adversary Simulation
MassMutual
Boston, MA
6 days ago
Job Description
Join MassMutual as an Information Security Consultant focusing on threat detection and adversary simulation. Leverage your expertise to enhance security through penetration testing and threat intelligence analysis while collaborating with teams to bolster incident response efforts.
Key Responsibilities
Provide technical guidance and hands-on leadership in security operations
Lead threat research, detection, and response efforts
Analyze and synthesize intelligence from various sources to identify risks
Oversee and execute adversary simulation exercises (red/purple team)
Research and develop offensive security techniques, tools, and automation frameworks
Advise on threat mitigation strategies
Lead and support incident response engagements
Required Qualifications
Bachelor's degree
8+ years of experience in information security focusing on threat detection, incident response, and adversary simulation
Preferred Qualifications
Degree in Cyber Security, Computer Science, or Criminal Justice with a focus in Cyber Security
10+ years of experience in information security focusing on threat detection, incident response, and adversary simulation
Proven ability to lead and develop threat hunting, detection engineering, and offensive security programs
Expertise in developing advanced threat detection rules, both signature-based and behavior-based analytics
Hands-on experience with offensive security tools such as CobaltStrike, Mythic, Evilginx, Outflank C2, and OST
Proficient in multiple programming languages including Python, C#, C/C++, and GoLang
Proficient in infrastructure automation using Terraform, Ansible, and CloudFormation
Proficient with SIEM and EDR platforms, including but not limited to Splunk, SumoLogic, and CrowdStrike Falcon EDR/LogScale
Strong understanding of identity management platforms like Okta, Microsoft EntraID, and Active Directory
Security automation expertise using Python scripting, Palo Alto Cortex XSOAR, and GitOps practices