Senior Security Specialist - Attack Path Management (Toronto)

Senior Security Specialist - Attack Path Management (Toronto)

11 Sep
|
Jobtailor
|
Toronto

11 Sep

Jobtailor

Toronto

- Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact • Validate data collection accuracy and ensure attack path fidelity • Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage • Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises • Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders • Work in complex and critical environments that power the economy • Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills Requirements ~3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments ~ Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar) ~ Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation ~ Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications ~ Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments ~ Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings ~ Working knowledge of Linux and Windows operating systems ~ Familiarity with MITRE ATT&CK;,



threat emulation frameworks (Caldera, Atomic Red Team), and purple teaming methodologies ~ Ability to reverse-engineer or emulate TTPs from threat intel reports ~ Ability to analyze and identify complex cross-platform attack vectors ~ Hands‑on experience with AD and/or cloud‑focused penetration testing, threat simulation, or detection/response in regulated or complex production environments ~ PaaS/SaaS operational know‑how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management ~ Offensive/defensive security certifications or cloud security specialties are nice‑to‑have ~ BloodHound Operator Certification (BHOC) is nice‑to‑have ~ Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them ~ Proven ability to build, grow, and maintain relationships both internally and externally Core Competencies Demonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures. Highest-signal resume keywords BloodHound Enterprise Operation Active Directory Security Cloud Security Engineering DevOps/CI-CD Tooling Penetration Testing ATS Optimization Keywords Hard Skills BloodHound Ciphers PowerShell C# Python Network Protocols Identity and Access Management Container Security Threat Emulation Frameworks Cross‑Platform Attack Analysis PaaS/SaaS Operations Soft Skills Relationship Building Communication Collaboration Goal Setting Problem Solving Certifications & Qualifications BloodHound Operator Certification Offensive Security Certifications Cloud Security Specialties Industry Keywords Red Team Operations Blue Team Operations Purple Team Methodologies MITRE ATT&CK; Threat Detection Incident Response Regulated Environments Complex Production Environments Tools & Technologies Jenkins GitHub Actions Terraform CloudFormation Ansible Kubernetes Linux Windows

📌 Senior Security Specialist - Attack Path Management (Toronto)
🏢 Jobtailor
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security specialist - attack path management (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior security specialist - attack path management (toronto) / toronto