Opportunity brief
BCG is hiring for the role of Global Cybersecurity Specialist!
Responsibilities of the Candidate:
- Support the planning and execution of red team engagements, including reconnaissance, initial access, post-exploitation, and lateral movement phases.
- Conduct phishing simulations, social engineering campaigns, and assume-breach exercises under the direction of senior team members.
- Assist in the development and maintenance of offensive tooling, attack infrastructure, and automation scripts to support engagement operations.
- Perform vulnerability assessments and penetration testing across network, endpoint, web application, and cloud environments.
- Document attack paths, findings, and technical evidence to support high-quality engagement reports.
- Contribute to purple team exercises by collaborating with detection and response teams to validate and improve security controls.
- Research emerging attack techniques, threat actor TTPs, and AI led offensive security tooling to enhance team capabilities.
- Participate in post-engagement reviews and knowledge-sharing sessions to support continuous improvement of Red Team methodologies.
- Assist in maintaining and operating command-and-control infrastructure and offensive security platforms.
- Support the development of internal training materials, playbooks, and documentation for the Offensive Security team.
Requirements:
- 1–3 years of experience in offensive security, penetration testing, or a related cybersecurity discipline.
- Foundational knowledge of enterprise attack techniques across Active Directory, endpoints, networks, and web applications.
- Exposure to common offensive security tools and frameworks such as Metasploit, BloodHound, Burp Suite, or equivalent.
- Basic scripting or programming skills in Python, PowerShell, or Bash for task automation and tooling support.
- Understanding of networking fundamentals, operating system internals, and common security protocols.
- Familiarity with the MITRE ATT&CK framework and common adversary tactics, techniques, and procedures.
- Strong analytical and problem-solving skills with a keen interest in understanding how attackers think and operate.
- Ability to document technical findings clearly and communicate results to peers and team leads.
- Eagerness to learn, take direction from senior practitioners, and grow within a structured offensive security program.
- Exposure to cloud environments (Azure, AWS, or Google Cloud) is advantageous.
- Participation in CTF competitions, bug bounty programs, or personal security research projects is valued.
- Familiarity with basic reverse engineering, malware analysis, or exploit research is a bonus.
- Understanding of defensive security concepts and technologies such as SIEM, EDR, and network monitoring is beneficial.