Lead IT Risk and Security Engineer - Breach & Attack Simulation (BAS)
Dtcc
Job Title
Breach & Attack Simulation (BAS) Engineer
Job Description
Are you ready to make an impact at DTCC? Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
This position will report to the Associate Director, Cyber Threat Defense and Controls within the Cybersecurity Engineering & Operations team. The Breach & Attack Simulation (BAS) Engineer will be responsible for the day-to-day design, execution, and operationalization of the organization's breach and attack simulation program. This includes emulating real-world adversary techniques to validate the effectiveness of preventive and detective security controls across on-premises and cloud environments. The role focuses on continuous security control testing, mapping results to frameworks such as MITRE ATT&CK, identifying detection and response gaps, and working closely with SIEM, SOC, and security engineering teams to improve detection coverage, incident readiness, and overall cyber resilience.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
- Identify, assess, and document security monitoring control issues to mitigate risks.
- Monitor IT platforms that are sending logs to security event monitoring systems and work with relevant IT groups for the remediation of gaps in coverage.
- Integrate new log sources and security technologies by building parsers, onboarding data feeds, and validating data quality to ensure accurate and complete visibility across the environment.
- Ensure platform availability, security, and compliance by monitoring system health, performing upgrades and patching, managing access controls, and aligning configurations with organizational and regulatory requirements.
- detection coverage and operational efficiency.
- Support Disaster Recovery Exercises
- Support audits and regulatory assessments
- Interface with CTDC internal and external stakeholders
- Support the preparation of reports that goes out to stakeholders and senior management.
- Prepare, format and present metrics and reporting for technical and management audiences.
- Coordinate with IT teams for the remediation of identified risks and issues affecting security monitoring controls.
- Support CTDC projects related to implementation of security monitoring controls.
- Support other CTDC responsibilities as assigned.
Qualifications:
- Minimum of 6 years of related experience
- Bachelor's degree preferred or equivalent experience
Talents Needed for Success:
- Feedback: Seeks feedback from others, provides feedback to others in support of their development, and is open and honest while dealing constructively with criticism.
- Delegating: Effectively manages tasks and people, taking a practical approach to determine the most effective method of execution while respecting others' expertise and considering others' feelings and working styles.
- Inclusive Leadership: Values individuals and embraces diversity by integrating differences and promoting diversity and inclusion across teams and functions.
Specific Skills & Technologies
- Adversary Emulation & Attack Modeling: Ability to simulate real-world attacker techniques using frameworks like MITRE ATT&CK , mapping tactics, techniques, and procedures (TTPs) to validate security control coverage across the kill chain.
- Security Control Validation & Detection Engineering: Experience analyzing BAS results to assess the effectiveness of preventive and detective controls , identify detection gaps, and collaborate with SIEM and SOC teams to improve alert fidelity and coverage.
- Risk & Exposure Analysis with Actionable Reporting: Skill in translating BAS findings into clear, actionable insights , prioritizing risks, recommending remediation, and communicating impact to both technical teams and security leadership.
Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
About Us
With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 20 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC's subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC's Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually.
DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you'll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It's the chance to make a difference at a company that's truly one of a kind.
Learn more about Clearance and Settlement by clicking here.
- ...through our network for a Lead Enterprise Application Security Architect at a... ...mitigating security risks throughout the software... ..., guide engineering teams through secure... ...informed about the latest attack vectors, and implement... ...Features Job Category IT, Security #J-18808-...RiskPermanent employmentWork at officeShift work2 days per week3 days per week
- ...Financial Services & Insurance IT Security Engineering Advisor Sr PRIMARY... ...automating repeatable tasks. Leads IT groups and business units... .... Implementation of attack surface reduction rules, antivirus... ...with organizational risk tolerance and compliance requirements...RiskWork at officeLocal area
- ...Refresco Benelux is seeking a highly motivated IT GRC Manager in Tampa, Florida. This role is critical for maintaining our IT governance, risk, and compliance program with an emphasis on SOX compliance, third-party risk management, and disaster recovery planning. The ideal...Risk
- ...Security Engineer - GRC We are seeking a skilled professional to join our team for a 6-month contract role focused on Data Loss Prevention... ...in cybersecurity, data governance, and information risk Familiarity with DLP, data classification, and data lifecycle...RiskContract workWork experience placement
- ...pioneering Managed IT. Jobs in... ...facing role, you will simulate real-world cyberattacks... ...infrastructure to uncover security weaknesses,... ...our Cybersecurity Engineers team to scope... ...drive remediation and risk reduction. Key Responsibilities... ...Simulate advanced attack scenarios,...RiskLocal area
- ...cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage... ...operations, vulnerability management, or IT security functions. - Familiarity with basic... ...environments - Familiarity with risk management, POA&M governance, and compliance...RiskMinimum wageContract workTemporary workWork experience placementRemote work
$113k - $168k
...MUFG), one of the world's leading financial groups.... ...highly motivated SIEM Engineer as part of the Engineering... ...technology to improve security posture. This person will... ...to understand security risks and controls, to analyze... ...and frameworks (MITRE Attack Framework, CIS, etc.)...RiskWork experience placementWork at officeLocal areaRemote work$92k - $120k
...Information Technology Job Description Summary: The Senior IT Security Engineer is responsible for planning, deploying, administering, and... ...compliant. Key responsibilities include incident response, risk management, and collaboration to enhance security posture. Strong...RiskFull timeWork experience placementWork at officeRemote workWork from homeFlexible hours2 days per week- ...General Description: We are seeking an IT Senior Security Engineer to join our team. The IT Senior... ...and Essential Job Functions: Lead the research, analysis, design, testing... ..., understand and determine associated risk levels and make recommendations for approval...RiskTemporary workWork experience placement
- ...table. We are the leading global independent beverage... ...experienced Senior SailPoint Identity Security Cloud (ISC) Engineer to join our team. In this... ...build connectors with an IT Service Management ( ITSM )... .... Non-Employee Risk management (NERM) Module Administration...RiskTemporary workFor contractorsLocal areaWork from homeWorldwideFlexible hours
$73.45k - $132.78k
...and more efficient through technology, engineering, and science. You would be a valued member... ...individual. The Tier III Network Security Engineer position at MacDill AFB, FL... ...mitigations on design solutions to comply with Risk Management Framework (RMF) cybersecurity...RiskLocal areaImmediate startFlexible hours- ...Principal Security Engineer We are seeking a highly experienced and skilled... ...customer third-party risk management requests. Security... ...and Investigation: Lead incident response efforts, including... ...-functional teams, including IT, development, and operations,...RiskLocal area
- ...GuidePoint Security provides trusted cybersecurity expertise, solutions... ...decisions and minimize risk. By taking a three-tiered, holistic... ...not limited to Threat and Attack Simulation (TAS), Application Security,... ...engagements with existing clients.Lead strategic planning sessions...RiskRemote workFlexible hours
- The Cyber Security Specialist will be responsible for protecting the organization... ...from unauthorized access, attacks, and breaches. The specialist will work closely with the IT team to identify potential... ...develop strategies to mitigate risks. Responsibilities: Develop and...Risk
- A leading IT governance organization is seeking a Lead IT Governance and Process Improvement Specialist to develop and maintain critical risk management reports and dashboards using Microsoft's Power Platform. This role requires deep expertise in Power BI, analytics, and...Risk
- ...Data Security Engineer Minimum 7 years Knowledge in process design and implementation Strong security tool experience (M365 security... ...Pureview, Imperva,) Excellent understanding of cyber security and risk Very good knowledge about encryption and database...Risk
- ...Senior Information System Security Engineer (ISSE) Our partner is building... ...leadership on cybersecurity risks, vulnerabilities, and mitigation... ...Act as a technical lead and mentor to engineers at all... ...solved our clients' toughest IT challenges with integrity, security...Risk
- A leading beverage company in Tampa, Florida, is seeking an experienced IT GRC Manager to enhance their IT governance, risk, and compliance program. You will focus on maintaining SOX compliance, managing third-party risks, and ensuring effective disaster recovery plans....Risk
- ...IT Risk and Security Engineer (PKI-Certificate Management) Location: Jersey City, Tampa, Dallas, TX Skills: Information Security, PKI, Cryptography, On-Premise, Cloud, Python, Agile, Kanban, Jenkins, Chef Job Description: The Cybersecurity Services domain protects...Risk
$165k - $180k
...Senior Data Security Engineer (DRM Specialist) Platinum Technologies is a Northern Virginia based... ...products we want to hear from you. We lead with technical expertise, but that is just... ...including clearance, role, and risk level. You will also manage the key management...Risk$100k - $172.5k
...Function: Technology Enterprise Strategy & Security Job Sub Function: Solution... ...talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan,... ...you are eager to leverage your security risk and compliance skills to make a difference...RiskFull timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ...Solutions... We are looking for Site IT Lead @ Tampa, FL for the below mentioned job... ...comply with IT policies Ensure site IT security compliance with global standard - co-work... ...an inventory of IT assets and managing risks associated with aging components. A critical...RiskLocal area
- ...Cyber Red Team Lead - Jersey/Tampa/Dallas #1... ...and executing advanced security testing and adversaryemulation... ...delivers clear, actionable risk insights to both technical... ..., endpoint, and human attack surfaces. Plan and manage... ...relationships with IT, security leadership, business...RiskWorldwide
- JOB DESCRIPTION This Lead IT Governance and Process Improvement Specialist in the IT Risk Management CoE will be responsible for creation and maintenance of key IT wide... ...priorities at any given time Knowledge of the security markets, post-trade processing and clearing and...RiskFlexible hours
- ...The Information Technology group delivers secure, reliable technology solutions that enable... ...crypto metadata used for CBOM reporting and risk analysis. Request intake, issuance,... ...revocation, rotation, and expiry governance. Lead SSL/TLS certificate installation,...RiskRemote workFlexible hours
- ...Job Title Lead IT Security Endpoint Engineer Job Description Are you ready to make an impact at DTCC? Do you want to work on innovative projects... ...cybersecurity and eager to contribute to minimizing risks and strengthening the security posture of DTCC's digital...Risk
$140k - $203k
...Group (MUFG), one of the world's leading financial groups. Across the... ...seeking a highly motivated Security Data Architect & Governance... ...Functions: Data architecture, engineering and analytics using various... ...to understand security risks and controls, to analyze various...RiskWork experience placementWork at officeLocal areaRemote work- ...Vice President Drive the security of critical banking applications... ...include technical details, risk assessments, and actionable remediation... ..., vulnerabilities, and attack techniques by leveraging... ...Rust). Experience in reverse engineering thick-client and mobile...Risk
$133.6k - $185.1k
...across defense, national security, public safety,... ...Senior Security DevOps Engineer . The ideal candidate... ...collaboratively with other IT professionals to ensure... ...understanding NIST 800-53 Risk Management Framework (RMF... ...and guidelines. Lead the effort in closing out...RiskLive inWork at officeLocal area- ...years experience | 3+ Locations We are seeking an Offensive Security Engineer (Application Security) to perform offensive security testing... ...with security tools and code, and stays current with modern attack techniques and emerging vulnerability classes. This position...Full timeWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead IT Risk and Security Engineer - Breach & Attack Simulation (BAS). Be the first to apply!
- sr information security engineer Tampa, FL
- senior application security engineer Tampa, FL
- aws cloud security engineer Tampa, FL
- dlp security engineer Tampa, FL
- sr security engineer Tampa, FL
- senior cloud security engineer Tampa, FL
- cloud security engineer Tampa, FL
- IT security engineer Tampa, FL
- information technology security engineer Tampa, FL
- endpoint security engineer Tampa, FL


