Senior Security Specialist – Attack Path Management (Ontario)

Senior Security Specialist – Attack Path Management (Ontario)

10 Sep
|
Jobtailor
|
Ontario

10 Sep

Jobtailor

Ontario

• Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms
• Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact
• Validate data collection accuracy and ensure attack path fidelity
• Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound
• Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage
• Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises
• Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams
• Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders
• Work in complex and critical environments that power the economy
• Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills
Requirements
3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments
Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar)
Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation
Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications
Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments
Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings
Working knowledge of Linux and Windows operating systems
Familiarity with MITRE ATT&CK;, threat emulation frameworks (Caldera, Atomic Red Team),



and purple teaming methodologies
Ability to reverse-engineer or emulate TTPs from threat intel reports
Ability to analyze and identify complex cross-platform attack vectors
Hands‑on experience with AD and/or cloud‑focused penetration testing, threat simulation, or detection/response in regulated or complex production environments
PaaS/SaaS operational know‑how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management
Offensive/defensive security certifications or cloud security specialties are nice‑to‑have
BloodHound Operator Certification (BHOC) is nice‑to‑have
Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them
Proven ability to build, grow, and maintain relationships both internally and externally
Core Competencies
Demonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures.
Highest-signal resume keywords
BloodHound Enterprise Operation
Active Directory Security
Cloud Security Engineering
DevOps/CI-CD Tooling
Penetration Testing
ATS Optimization Keywords
Hard Skills
BloodHound Ciphers
PowerShell
C#
Python
Network Protocols
Identity and Access Management
Container Security
Threat Emulation Frameworks
Cross‑Platform Attack Analysis
PaaS/SaaS Operations
Soft Skills
Relationship Building
Communication
Collaboration
Goal Setting
Problem Solving
Certifications & Qualifications
BloodHound Operator Certification
Offensive Security Certifications
Cloud Security Specialties
Industry Keywords
Red Team Operations
Blue Team Operations
Purple Team Methodologies
MITRE ATT&CK;
Threat Detection
Incident Response
Regulated Environments
Complex Production Environments
Tools & Technologies
Jenkins
GitHub Actions
Terraform
CloudFormation
Ansible
Kubernetes
Linux
Windows

#J-18808-Ljbffr

📌 Senior Security Specialist – Attack Path Management (Ontario)
🏢 Jobtailor
📍 Ontario

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security specialist – attack path management (ontario) / ontario

Subscribe to this job alert:

Get the latest job offers by email for: senior security specialist – attack path management (ontario) / ontario