Назад
Company hidden
10 часов назад

Principal Adversary Emulation Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Adversary Emulation Engineer (Cybersecurity): Designing and executing controlled, threat-informed adversary emulation scenarios to validate enterprise detection coverage and generate high-fidelity telemetry with an accent on MITRE ATT&CK, threat detection engineering, and purple team operations. Focus on building AI-assisted automation, identifying logging and detection gaps, and translating emulation results into production detections, hunt content, and risk-informed remediation.

Location: Philadelphia, Pennsylvania, United States; onsite collaboration is generally preferred

Company

hirify.global is a Fortune 30 global media and technology company providing connectivity, platforms, content, and digital experiences.

What you will do

  • Establish and mature a repeatable adversary emulation capability, including rules of engagement, approval workflows, success metrics, reporting standards, and validation processes.
  • Design and execute controlled threat-informed scenarios mapped to MITRE ATT&CK and relevant enterprise risks.
  • Build automation and AI-assisted workflows for emulation planning, test execution, evidence collection, detection validation, reporting, and metrics tracking.
  • Partner with threat detection engineering and threat hunting to validate coverage, alert fidelity, hunt hypotheses, telemetry quality, and response workflows.
  • Identify logging gaps, telemetry issues, detection blind spots, enrichment deficiencies, and control weaknesses across endpoint, identity, cloud, network, email, SaaS, application, and data platforms.
  • Convert emulation outcomes into detections, hunt content, playbooks, dashboards, technical reports, executive summaries, and prioritized remediation actions.

Requirements

  • Bachelor’s degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or a related field.
  • 7+ years of relevant cybersecurity experience, including adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations.
  • Strong knowledge of adversary tradecraft, MITRE ATT&CK, threat-informed defense, detection engineering, and enterprise security telemetry.
  • Experience planning and executing controlled security testing in complex enterprise environments, including approvals, deconfliction, rules of engagement, and evidence handling.
  • Proficiency with Python and at least one additional language or shell, such as PowerShell or Bash, plus experience with SIEM, XDR, EDR, cloud, identity, network, email, or application telemetry.
  • Ability to write or validate detection and hunting logic using SPL, KQL, SQL, Sigma, YARA, or similar formats, and communicate technical findings to technical and non-technical stakeholders.

Nice to have

  • Experience building adversary emulation, purple team, detection validation, or security validation functions.
  • Experience with Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, Prelude Operator, or similar tools.
  • Security testing experience across cloud, SaaS, identity, containers, CI/CD, endpoints, networks, or large-scale data platforms.
  • Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, or CISSP.

Culture & Benefits

  • Onsite collaboration is generally preferred unless a team is designated as virtual.
  • Benefits include support and resources for physical, financial, and emotional well-being.
  • Comprehensive benefits options and personalized guidance are available for everyday needs and major life events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →