Назад
Company hidden
2 часа назад

Cyber Threat Emulation Operator, Lead

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Threat Emulation Operator, Lead (Offensive Security/AI): Designing and executing end-to-end red team engagements while building custom offensive security tooling and AI-assisted agentic workflows across enterprise, cloud, identity, application, and AI-enabled environments with an accent on adversary simulation, attack-path orchestration, and control validation. Focus on engineering adaptive multi-agent attack simulations, testing AI applications and agentic systems, and partnering with defenders to improve security controls.

Location: Plano, Texas, United States. Applicants must already have the right to work in the United States and must not require hirify.global immigration support or sponsorship now or in the future.

Company

hirify.global Financial Services provides finance and insurance services for hirify.global and Lexus in North America within hirify.global’s mobility organization.

What you will do

  • Design and execute end-to-end red team and control-testing engagements across identity, endpoint, network, application, cloud, container, and AI-enabled environments.
  • Develop custom offensive security tooling, reusable attack capabilities, and automation for realistic adversary simulations.
  • Build AI-assisted and agentic workflows for reconnaissance, attack-path discovery, campaign planning, vulnerability analysis, payload development, and control validation.
  • Engineer safe multi-agent systems that adapt attack paths, interpret results, and coordinate multi-stage simulations.
  • Test AI applications and agentic systems, including model interfaces, retrieval pipelines, tool integrations, authorization boundaries, data flows, and indirect prompt-injection paths.
  • Partner with SOC analysts, detection engineers, incident responders, and threat intelligence analysts in purple team exercises; mentor offensive security practitioners.

Requirements

  • Extensive experience in red teaming, adversary simulation, penetration testing, or offensive security.
  • Experience planning and leading complex, end-to-end enterprise security engagements.
  • Strong knowledge of attack techniques across identity, endpoints, networks, cloud platforms, applications, AI, and security infrastructure.
  • Hands-on experience developing offensive security tooling, automation, or agentic workflows.
  • Ability to communicate complex technical findings to technical and non-technical audiences, with sound judgment and knowledge of offensive security governance safeguards.
  • Bachelor’s degree from an accredited institution or equivalent experience.

Nice to have

  • CRTO, OSCP, OSWE, CISSP, or another relevant security certification.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, STRIDE, CVSS, NIST, and PCI guidance.
  • Understanding of CFPB, GLBA, SOX, GDPR, CCPA, and related privacy, legal, and information security requirements.
  • Advanced degree in an IT-related field.

Culture & Benefits

  • Team-oriented, flexible, and respectful work environment.
  • Professional development programs and tuition reimbursement.
  • Comprehensive health care and wellness plans, paid holidays, and paid time off.
  • 401(k) plan with company match and annual retirement contribution.
  • Vehicle purchase discount, lease vehicle program where applicable, tax-advantaged accounts, and family support services.
  • Relocation assistance where applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →