Director of Offensive Security
Jobleads-US
Director of Offensive Security
The Director of Offensive Security reports directly to the Chief Information Security Officer (CISO) and owns continuous adversarial validation of the NMC² production environment. This is not a scheduled penetration testing function but a standing offensive capability that operates against production with authorization, emulates named threat actors relevant to our customer base and infrastructure class, and produces evidence‑backed assessments of whether our controls hold under realistic attack conditions.
Responsibilities:
- Build and run a continuous red team program against the production NMC² environment – HPC clusters, multi‑tenant Kubernetes, bare‑metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface (SIEM, EDR, IAM, PAM).
- Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers, APT groups with interest in research computing, and insider threat scenarios covering privileged‑operator abuse.
- Independently validate detection and response efficacy: every red‑team operation generates a detection coverage report measured against the SOC and IR functions, including time‑to‑detect, time‑to‑contain, and detection gap inventory by ATT&CK technique ID.
- Own the purple‑team feedback loop: every undetected TTP becomes a tracked detection‑engineering deliverable with owner and SLA, every detected‑but‑unresponded TTP becomes a tracked IR playbook deliverable.
- Run continuous attack surface validation against production (not just pre‑production) with a documented Rules‑of‑Engagement framework, blast‑radius controls, and CISO‑level authorization gates for destructive or high‑risk techniques.
- Lead threat‑led penetration testing of the HPC‑specific attack surface: Slurm and workload‑manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross‑tenant lateral movement in shared compute, and scientific software supply‑chain compromise.
- Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross‑account and cross‑tenant escape attempts, container breakout chains, service‑mesh bypass, admission‑controller evasion, and secrets‑management integrity.
- Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial‑design reviews that the CISO signs off on before build.
- Manage the external pentest and red‑team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation‑tracking system.
- Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit‑development capability, with clear controls on tool custody, source‑code management, and destruction protocols.
- Define and publish offensive security KPIs to the CISO and board level: coverage against MITRE ATT&CK technique inventory, mean time to compromise from assumed‑breach scenarios, control‑validation pass rate by control family, remediation velocity on P1 and P2 findings, and repeat‑finding rate.
- Issue formal assessment reports using CWE classification, CVSS v3.1 base and environmental scoring, and explicit exploitation evidence; findings are attestations, not suggestions.
- Champion an adversarial engineering culture across Platform and Security Engineering through documented attack patterns, regular internal briefings, and integration of offensive findings into developer tooling and CI/CD gates.
Requirements
- 15+ years in offensive security with demonstrated hands‑on depth across at least three of: network penetration testing, red‑team operations, cloud penetration testing, application exploitation, hardware and firmware attack research, or advanced adversary emulation.
- 5+ years leading offensive security teams, including direct accountability for hiring specialized offensive talent, managing operational security of red‑team infrastructure, and operating under formal rules of engagement against production systems.
- Demonstrated red‑team leadership against mature target environments with functioning SOC, EDR, and IR capability, not greenfield pentest targets.
- Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple‑team execution models.
- Hands‑on capability with production‑grade offensive tooling: C2 frameworks (Cobalt Strike, Mythic, Sliver, or equivalent), exploitation frameworks, custom tool development, and operational security for red‑team infrastructure.
- Strong command of cloud and container offensive trade‑craft: Kubernetes attack paths, cloud IAM privilege escalation chains, service mesh and side‑car abuse, and multi‑tenant isolation testing.
- Fluency with CWE, CVSS v3.1 & v4.0, OWASP Top 10, SANS CWE Top 25, and the CIS Controls v8 Penetration Testing domain (Control18).
- Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking.
- Demonstrated ability to execute offensive work against production with appropriate authorization, blast‑radius control, and executive communication discipline.
- Exceptional written communication: findings must stand up to scrutiny from engineering leadership, auditors, and customers.
Preferred
- OSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications; CISSP alone is not sufficient evidence of hands‑on offensive capability.
- Prior experience building an offensive security function from scratch, not inheriting an existing one.
- HPC, bare‑metal, or hyperscale data‑center offensive assessment experience.
- Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research.
- Background in threat intelligence consumption for adversary emulation planning (CTI‑led red teaming).
- Experience with sovereign cloud, export‑controlled, or financial services customer environments.
Benefits & Perks
- Company‑Paid Lunch Stipend: Lunch is provided via GrubHub.
- 100% Employer‑Paid Medical in a High‑Deductible Health Plan, Dental and Vision benefits for employees and families.
- 16 weeks of Paid Parental Leave.
- Employee Assistance Program.
- Life insurance, Short‑Term Disability and Long‑Term Disability.
- 401(k): Company will match 100% of your contributions up to 6%.
- Medical insurance in our PPO plan and other benefits such as Health Savings Accounts (with Company Contribution), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
- Time Off: 25 days of Paid Time Off plus 12 company holidays.
Equal Opportunity Employer
NorthMark Strategies LLC is an equal employment opportunity employer. The company’s policy is not to discriminate against any applicant or employee based on race, color, religion, national or origin, gender, age, sexual orientation, gender identity or expression, marital status, mental or physical disability, genetic information, or any other basis protected by applicable law. The firm also prohibits harassment of applicants or employees based on any of these protected categories. Must be legally authorized to work in the United States without the need for employer sponsorship, now or in the future.
#J-18808-Ljbffr Jobleads-US- ...simulations, analysis, and decision-making, acc elerating discovery and driving faster innovation. The Position The Director of Offensive Security reports directly to the CISO and owns continuous adversarial validation of the NMC² production environment. This is not...SuggestedTemporary workFlexible hours
- ...NorthMark Compute & Cloud (NMC2) seeks a Director of Offensive Security to own continuous adversarial validation of the production environment. This role reports to the CISO and builds a standing offensive capability that emulates threat actors and delivers independent...Suggested
- ...NorthMark Compute and Cloud LLC is seeking a Director of Offensive Security to own continuous adversarial validation of our production environment, operate an authorized red-teaming program across HPC, Kubernetes, and cloud infrastructure, and report to the CISO. You...Suggested
- ...NorthMark Compute & Cloud (NMC²) is seeking a Director of Offensive Security to own continuous adversarial validation of our production environment, including HPC clusters and multi-tenant Kubernetes. You will emulate threat actors, measure detection efficacy, and drive...Suggested
- NorthMark Compute & Cloud seeks a Director of Offensive Security to own and run a standing offensive capability against production HPC and cloud infrastructure. You will emulate threat actors, validate detections, and produce evidence-backed assessments to ensure controls...Suggested
- ...people.Job DescriptionThe Team As part of Delivery Excellence, our Security and Risk Services team empowers enterprises to build resilience... ...through our Security and Risk product portfolio. The Role As Director, Security and Risk Services (Americas), you will lead services...Work at officeImmediate startRemote workFlexible hours
- ...Planned Parenthood of Greater Texas, Inc. is seeking a Manager of Safety and Security to lead the organization’s security program across multiple admin locations including Dallas, Fort Worth, Austin, and Houston. The role ensures the safety of employees, patients,...For contractors
- ...Chief Security Officer About the Company Diverse provider of document management products & solutions Industry Information... ...for the CSO include leading cyber operations, both offensive and defensive, and owning the security architecture across various...Work at office
- ...Overview This position can be filled in our Dallas Admin, Fort Worth Admin, Austin Admin or Houston Admin Office. The Director of Security and Facilities Operations provides leadership and strategic direction of the organization’s Facilities, Safety and Security...Permanent employmentTemporary workFor contractorsWork at officeLocal areaImmediate startFlexible hoursShift workAfternoon shift
- ...Asset Living seeks a Director of Cybersecurity in Dallas, TX to lead the enterprise security program. This executive role drives governance, strategy, and operations across a cloud-first environment, aligning with NIST CSF 2.0 and CIS Controls. The Director will build...
- ...Job Description Job Description Director of Cyber Security 10916 The ideal candidate brings deep security operations experience, strong leadership skills, and expertise in the Microsoft security ecosystem, with a proven ability to modernize cyber defense through...Interim role
- ...position can be filled at our Dallas Admin, Fort Worth Admin, Austin Admin or Houston Admin Office. The Manager of Safety and Security is responsible for management of the daily functions of Planned Parenthood of Greater Texas’ (PPGT) Security department, whose role...Permanent employmentFor contractorsWork at officeFlexible hoursAfternoon shift
- ...Head of Security About the Company Innovative platform for sending rewards & payouts globally Industry Financial Services Type Privately Held, VC-backed Founded 2010 Employees 51-200 Categories Mobile Payments Payments Financial Vehicles...Shift work
- ...Chief Security Officer, Foundational Services and OSES 522503 15-Sep-2026 Research & Development Siemens Industry Software Inc. We are a leading global software company dedicated to the world of computer-aided design, 3D modeling, and simulation, helping innovative...Work at officeLocal areaWork from home
$317.5k - $365k
...financial infrastructure through programmable money, blockchain-based payments, and cloud-native APIs. As VP, Global Head of Product Security & Risk, you will define and lead the enterprise framework that enables Circle’s products to scale securely, compliantly, and...WorldwideFlexible hours- ...performance, improve customer experiences and unlock new growth opportunities. As we continue to grow, we're looking for a Head of Security & Data Governance to lead our security, compliance and governance strategy in a highly regulated global payments environment. The...
- ...Mend.io is seeking a Head of Product Marketing to define positioning and messaging for AppSec, AI Security, and software supply chain offerings, driving revenue growth in a remote US-based role. You will own GTM strategy, pricing input, analyst relations, and cross-functional...Remote work
$161.5k - $299.7k
...within the broader Cyber Defense & Investigation ecosystem. As the Director of CFC, the person in this role is responsible for ensuring the... ...cyber threats and constantly improve the organization’s Cyber Security Posture, ensuring the CFC is operating effectively within the...Full time$98.5k - $188k
...Join the #VTeamLife.What you’ll be doing...We are seeking a highly analytical and proactive Senior Manager to join our team in Cyber Security. In this role, you will be responsible for investigating complex operational, security, and fraud threats across our wireline and...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift workWeekend work3 days per week- ...Security ManagerJob Summary:The Security Manager is responsible for overseeing the daily operations of the designated security department, ensuring the protection of company assets, personnel, and facilities. The role involves developing, implementing, and managing security...Contract workFor contractorsLocal areaAll shiftsFlexible hoursAfternoon shift
$136k - $204k
...empowered to do your best work.Job SummaryWe are looking for a Product Manager, SecOps to lead the strategy, roadmap, and adoption of security capabilities embedded directly into our engineering ecosystem. This is not a policy-writing or governance role. It is a product...Full timeWork at office$125.76k - $188.64k
...5067648Posted: 2026-09-17Location: Irving, Texas, United StatesSalary: $125,760.00 - $188,640.00Category: Technology, Information Security, ProfessionalCompany: CitiAbout Citi:Citi, the leading global bank, has approximately 200 million customer accounts and does business...Full time$134.5k - $265.1k
Position Summary AI Security ManagerOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through...Local areaWorldwideVisa sponsorship$163.4k - $322.1k
Position Summary AI Security Senior ManagerOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape....Local areaWorldwideVisa sponsorship$200k - $215k
...adaptive collaboration, and accelerated intelligence.Learn about the Danaher Business System which makes everything possible.The Director, Global Security is responsible for leading the company’s global security strategy and operations to protect employees, facilities, assets,...Hourly payFull timeRemote workWork from homeFlexible hours- ...expertise spans 40+ industries across 120+ countries and impacts millions of lives every day. We turn ideas into reality.We Are Platform Security professionals develop and deliver solutions to strengthen the SAP cybersecurity considerations of enterprise applications;...Full timeContract workWork experience placementLive inWork at officeLocal area
- ...approaches to care, Concentra colleagues provide exceptional service to employers and exceptional care to their employees.The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead the efforts in maintaining compliance with various regulatory...Local area
- ...health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.The Director, Application & AI Security owns application and AI security end to end: the security of the software and the AI systems Lantern builds. It is...
- We AreAccenture Security helps organizations prepare, protect, detect, respond, and recover along with all points of the security lifecycle. Cybersecurity challenges are different for every business in every industry. Leveraging our global resources and advanced technologies...Full timeWork experience placementLive inWork at officeLocal area
- ...gender expression, age, veteran or military status, disability, genetic predisposition, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws. Pursuant to the San...Full timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Offensive Security. Be the first to apply!



