10 часов назад
Principal Adversary Emulation Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Adversary Emulation Engineer (Cybersecurity): Designing and executing controlled, threat-informed adversary emulation scenarios to validate enterprise detection coverage and generate high-fidelity telemetry with an accent on MITRE ATT&CK, threat detection engineering, and purple team operations. Focus on building AI-assisted automation, identifying logging and detection gaps, and translating emulation results into production detections, hunt content, and risk-informed remediation.
Location: Philadelphia, Pennsylvania, United States; onsite collaboration is generally preferred
Company
is a Fortune 30 global media and technology company providing connectivity, platforms, content, and digital experiences.
What you will do
- Establish and mature a repeatable adversary emulation capability, including rules of engagement, approval workflows, success metrics, reporting standards, and validation processes.
- Design and execute controlled threat-informed scenarios mapped to MITRE ATT&CK and relevant enterprise risks.
- Build automation and AI-assisted workflows for emulation planning, test execution, evidence collection, detection validation, reporting, and metrics tracking.
- Partner with threat detection engineering and threat hunting to validate coverage, alert fidelity, hunt hypotheses, telemetry quality, and response workflows.
- Identify logging gaps, telemetry issues, detection blind spots, enrichment deficiencies, and control weaknesses across endpoint, identity, cloud, network, email, SaaS, application, and data platforms.
- Convert emulation outcomes into detections, hunt content, playbooks, dashboards, technical reports, executive summaries, and prioritized remediation actions.
Requirements
- Bachelor’s degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or a related field.
- 7+ years of relevant cybersecurity experience, including adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations.
- Strong knowledge of adversary tradecraft, MITRE ATT&CK, threat-informed defense, detection engineering, and enterprise security telemetry.
- Experience planning and executing controlled security testing in complex enterprise environments, including approvals, deconfliction, rules of engagement, and evidence handling.
- Proficiency with Python and at least one additional language or shell, such as PowerShell or Bash, plus experience with SIEM, XDR, EDR, cloud, identity, network, email, or application telemetry.
- Ability to write or validate detection and hunting logic using SPL, KQL, SQL, Sigma, YARA, or similar formats, and communicate technical findings to technical and non-technical stakeholders.
Nice to have
- Experience building adversary emulation, purple team, detection validation, or security validation functions.
- Experience with Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, Prelude Operator, or similar tools.
- Security testing experience across cloud, SaaS, identity, containers, CI/CD, endpoints, networks, or large-scale data platforms.
- Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, or CISSP.
Culture & Benefits
- Onsite collaboration is generally preferred unless a team is designated as virtual.
- Benefits include support and resources for physical, financial, and emotional well-being.
- Comprehensive benefits options and personalized guidance are available for everyday needs and major life events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 часа назад
Cyber Threat Emulation Operator, Lead
CrowdStrike
14 часов назад
Senior Analyst, Falcon Complete (Cybersecurity)
125 000 - 180 000$
6 часов назад
Endpoint Automation Staff Engineer (Cybersecurity)
110 000 - 230 000$
20 часов назад
Network Threat Detection R&D Engineer (AI)
143 800 - 230 000$
4 дня назад
Cyber Threat Analyst (Cybersecurity)
5 дней назад