Manager, Offensive Security leading Capital One's Purple Team to enhance cyber defense posture. Collaborating across teams to address vulnerabilities and improve information security protocols.
Responsibilities
Lead "Defense Improvement Analysis" (DIA): Deconstruct adversary simulation activities to identify control gaps and document the full lifecycle, from initial discovery to final technical resolution.
Engineering & Analytics: Perform advanced analysis of log events using big data tools to identify, recommend, and engineer specific solutions for threat detection and response.
Strategic Collaboration: Serve as the technical bridge between offensive and defensive stakeholders, translating complex adversary TTPs into durable defense strategies and actionable recommendations for both technical and executive audiences.
Operational Research: Continuously research emerging threat behaviors and automate repetitive post-exploitation analysis tasks to scale the team’s ability to identify and address novel TTPs.
Infrastructure & Tooling: Build and maintain the technical infrastructure and lab environments required to support and evolve Purple Team activities.
Requirements
High School Diploma, GED, or equivalent certification.
At least 4 years of information security experience.
At least 3 years of experience in Threat Hunting or Detection Engineering within a cloud or hybrid environment.
At least 2 years of experience analyzing EDR telemetry and bypass techniques.
2+ years of experience performing offensive security operations.
2+ years experience with Databricks, Spark, or similar for security analytics.
4+ years of experience in log analysis, threat detection engineering, threat hunt, incident response, forensics.
4+ years of experience with scripting and compiled languages.
One or more of the following certifications: OSCP, OSCE, GPEN, GXPN, CRTO, GCFA, GCIH, OSTH, GDAT.
Benefits
Comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being
Performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
Principal Security Engineer working on network security lifecycle and threat management for Verizon’s 4G/5G Cloud Networks. Collaborating with multiple teams to enhance cybersecurity posture.
Cybersecurity Engineer at Verizon responsible for security lifecycle and effectiveness across networks. Leading incident response and vulnerability management in a hybrid work role.
Director of Security and Compliance safeguarding digital assets and data with a focus on cybersecurity and compliance. Leading risk management, stakeholder engagement, and team leadership initiatives.
Information Security Risk & Compliance Analyst at AAB focusing on ISO 27001 compliance and information security management. Collaborating across teams to ensure robust risk and compliance frameworks.
Information Security Risk & Compliance Analyst at AAB managing compliance with ISO 27001, supporting enterprise risk assessments and enhancing information security systems.
Information Security Risk & Compliance Analyst supporting the maintenance of ISO 27001 standards. Contributing to risk assessments and compliance across AAB’s Business Protection Team.
Security Principal at Optiv designing AI security solutions for clients, leveraging advanced security services and technologies. Driving pipeline generation and maintaining strong client relationships as a trusted advisor.
Cloud Security Architect supporting federal customer projects focused on architecture and security solutions. Conducting risk assessments and defining security requirements within a cloud environment.
Information Security Specialist responsible for enhancing cybersecurity posture through incident management and compliance. Collaborating with cross - functional teams to monitor threats and implement security measures.
Senior Lead Info Security Architect leading and collaborating on cybersecurity solutions at TIAA. Responsible for secure design and implementation of cloud security strategies and practices.