Summary
Rapid7 is a cybersecurity company focused on helping customers create a secure digital world. The Vector Command Specialist supports customers through external attack surface analysis, reconnaissance, platform integrations, customer communications, reporting, and entry-level penetration testing activities.
Responsibilities
- Onboard customers to the Vector Command platform and technologies
- Oversee and ensure the completeness of customer report deliverables
- Serve as the primary point of contact for customer inquiries related to testing operations, alerts, or general Vector Command questions associated with Red Team activities
- Coordinate and host monthly Vector Command Red Team update calls in conjunction with a Rapid7 Red Team lead
- Translate technical concepts and communicate them effectively to non-security personnel
- Coordinate communications between internal Rapid7 services on behalf of customers, including the Managed Detection and Response (MDR) and Managed Vulnerability Management (MVM) teams
- Provide monthly written summaries of each customer’s attack surface and Vector Command Red Team operations
- Analyze each customer’s exposures and attack surface within the Vector Command platform
- Conduct manual network and service reconnaissance to identify new exposures
- Perform Open-Source Intelligence (OSINT) gathering on customers to identify attack surface elements that extend beyond traditional network services
- Keep the Red Team informed of significant changes in customers’ attack surfaces
- Coordinate customer requests and prioritizations with the Red Team operators
- Develop scripts to query and analyze attack surface data from numerous sources and automated systems
- Perform entry level penetration testing activities against external assets, as assigned by the Red Team lead
Skills
- 3+ years in an active technical security role
- Knowledge of modern penetration testing tools and methods
- Experience prioritizing customer success by putting client needs at the forefront of technical recommendations and investigative reporting
- Knowledge of external attack surface reconnaissance techniques to identify customer's internet facing exposures
- Strong knowledge of network, web-based application, and IEEE 802.11 security concepts
- Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite
- Experience using scripting languages such as Python and PowerShell
- Experience with social engineering techniques and tactics related to reconnaissance and OSINT gathering
- Communicate in a clear manner that conveys objectives and rationale, fostering commitment from cross-functional partners
- Collaborate effectively as a dedicated team player who supports peers, shares domain knowledge, and celebrates team achievements
- Demonstrate a strong sense of ownership and commitment to the “end-to-end” testing process. Holds themselves and other accountable to driving value and customer outcomes from the initial pre-engagement planning to the final remediation phase
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success
- Certifications such as CREST, GPEN, PJPT, PNPT, CPTS, or OSCP are preferred
Qualifications
Must Haves
- 3+ years in an active technical security role
- Knowledge of modern penetration testing tools and methods
- Experience prioritizing customer success by putting client needs at the forefront of technical recommendations and investigative reporting
- Knowledge of external attack surface reconnaissance techniques to identify customer's internet facing exposures
- Strong knowledge of network, web-based application, and IEEE 802.11 security concepts
- Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite
- Experience using scripting languages such as Python and PowerShell
- Experience with social engineering techniques and tactics related to reconnaissance and OSINT gathering
- Communicate in a clear manner that conveys objectives and rationale, fostering commitment from cross-functional partners
- Collaborate effectively as a dedicated team player who supports peers, shares domain knowledge, and celebrates team achievements
- Demonstrate a strong sense of ownership and commitment to the “end-to-end” testing process. Holds themselves and other accountable to driving value and customer outcomes from the initial pre-engagement planning to the final remediation phase
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success
Nice to Haves
- Certifications such as CREST, GPEN, PJPT, PNPT, CPTS, or OSCP are preferred
Benefits