Senior Security Engineer Red Team

Quality, Security, & Compliance Columbus, Ohio


Company Information

Be a part of the future of cloud at one of the fastest growing and profitable companies in enterprise software. Veeva is experiencing rapid growth and strong demand as the cloud software market is evolving toward industry-specific, cloud solutions. Veeva topped the Fortune Future 50 list of U.S. companies poised for breakout growth and was listed as one of the fastest growing companies among Forbes Fast Tech 25.  

We build innovative SaaS solutions that span CRM, content management, and data for the life sciences industry. Our more than 675 customers ranging from emerging biotechs to the largest global pharmaceutical companies including Bayer, Lilly, Merck, and Novartis. 

We are driven by our core values: do the right thing, employee success, customer success, and speed. We are innovators, collaborators, and thought leaders out to create and bring to market solutions that help our customers improve and extend human life.

Job Summary

Veeva’s Security Engineering Team is seeking Red Teamers to help keep Veeva secure and safe from attackers. Our team in Columbus is growing, and we want you to join us!

This role has a broad scope, ranging from attacking Veeva’s AWS services, infrastructure and processes, discovering weaknesses in Veeva’s architecture, and working with various platform teams, third party testers and researchers to sharpers our detective and preventative capabilities. This role presents an ultimate test of one’s security knowledge and ability, along with the support of a team of highly skilled individuals.

Responsibilities

A Security Engineer at Veeva is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Security, such as the Threat Intelligence, Application Security and Security Operations teams, as well as provide technical leadership and advice to teams and leaders throughout Veeva. You will be in direct contact with numerous teams in a variety of business platforms, giving you firsthand knowledge about how Veeva is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Veeva to find new ways to break software and processes throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Individuals in this role will be expected to provide thought leadership for the organization as you discover, invent and innovate throughout the course of their duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Veeva and its customers secure.

  • Participate in Red Team engagements throughout Veeva with few limits and restrictions.
  • Conduct full cycle engagements with business units independently, or as part of a team.
  • Perform manual examination of client systems, web sites and networks to discover weaknesses.
  • Thoroughly document exploit chain/proof of concept scenarios for client consumption.
  • Communicate findings and discoveries prioritize and execute remediation plans.
  • Train other members of the Red Team, developers or engineers in the exploits and fixes
  • Assist in Security Incident Response and Cyber Forensics during and post an incident and assist in reverse engineering the attack and designing security controls
  • Coordinate find remediation from third party penetration testers
  • Review and validate findings from Veeva’s bug bounty program
  • Maintain AWS VPC and related testing systems for our third-party testers and bug bounty programs
Requirements
  • BS in Computer Science or related field, or equivalent work experience
  • 4+ years in an Information Security role, preferably in red teaming, penetration testing, reverse engineering, incident response or vulnerability management
  • Advanced knowledge and understanding in various disciplines such as security engineering, system and network security, authentication and security protocols, cryptography, and application security
  • Experience with interpreted or compiled languages: Python, Ruby, Perl, PHP, C/C++, Java, C#
  • Experience with cloud service providers and their offerings, preferably AWS and its various technologies and APIs
  • Experience with various testing tools, such as Netspaker, Kali Linux, Metasploit, Nmap, Nessus, Burp Suite, etc.
  • Familiar with offensive TTPs (Tactics, Techniques and Procedures) including post-exploitation and lateral movement
  • Experience with Redhat, AWS Linux, AWS Linux 2, Windows Server 2008, 2012, 2016 and 2019 etc.
  • Understanding of OSWAP Top 10, SANS Top 20, NIST 800-53, CIS, CSC or other security standards
  • Knowledge of the MITRE ATT&CK Framework
  • Industry penetration certifications such as OSCP, GPEN, GXPN, GWAPT etc
Nice to Have
  • Master of Science in Cyber Security, Information Security, MIS or equivalent
  • Industry security certifications such as CISSP, CEH or others
  • Experience in conducting social engineering focused assessments
  • Experience in CTF competitions, CVE research and/or Bug Bounty recognition
  • Experience in Web and Mobile (Android/iOS) based application/service assessment
  • Experience in Wireless and Network assessment in enterprise infrastructure
  • Experience in reverse engineering and associated tooling such as IDA
  • Experience in Advanced Persistent Threat exploits
  • Experience with Web Application Firewalls (WAF), IDS/IPS or other security platforms
  • Knowledge of fuzzing, memory corruption and exploit development
  • Knowledge about hardware hacking
  • Intermediate to advanced communication and presentation skills
  • Experience providing training and mentorship
  • Demonstrable teamwork skills and resourcefulness
  • Ability to make concrete progress in the face of ambiguity and imperfect knowledge

We don’t accept candidates from recruiters or placement agencies. If you have a candidate interested in Veeva, they should apply directly below or at careers@veeva.com. For more information regarding this policy click here.