11 Sep
|
Jobtailor
|
Toronto
- Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact • Validate data collection accuracy and ensure attack path fidelity • Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage • Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises • Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders • Work in complex and critical environments that power the economy • Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills Requirements ~3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments ~ Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar) ~ Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation ~ Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications ~ Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments ~ Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings ~ Working knowledge of Linux and Windows operating systems ~ Familiarity with MITRE ATT&CK;,
threat emulation frameworks (Caldera, Atomic Red Team), and purple teaming methodologies ~ Ability to reverse-engineer or emulate TTPs from threat intel reports ~ Ability to analyze and identify complex cross-platform attack vectors ~ Hands‑on experience with AD and/or cloud‑focused penetration testing, threat simulation, or detection/response in regulated or complex production environments ~ PaaS/SaaS operational know‑how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management ~ Offensive/defensive security certifications or cloud security specialties are nice‑to‑have ~ BloodHound Operator Certification (BHOC) is nice‑to‑have ~ Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them ~ Proven ability to build, grow, and maintain relationships both internally and externally Core Competencies Demonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures. Highest-signal resume keywords BloodHound Enterprise Operation Active Directory Security Cloud Security Engineering DevOps/CI-CD Tooling Penetration Testing ATS Optimization Keywords Hard Skills BloodHound Ciphers PowerShell C# Python Network Protocols Identity and Access Management Container Security Threat Emulation Frameworks Cross‑Platform Attack Analysis PaaS/SaaS Operations Soft Skills Relationship Building Communication Collaboration Goal Setting Problem Solving Certifications & Qualifications BloodHound Operator Certification Offensive Security Certifications Cloud Security Specialties Industry Keywords Red Team Operations Blue Team Operations Purple Team Methodologies MITRE ATT&CK; Threat Detection Incident Response Regulated Environments Complex Production Environments Tools & Technologies Jenkins GitHub Actions Terraform CloudFormation Ansible Kubernetes Linux Windows
📌 Senior Security Specialist - Attack Path Management (Toronto)
🏢 Jobtailor
📍 Toronto