18 Sep
|
Confidential
|
Toronto
18 Sep
Confidential
Toronto
- Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms- Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact- Validate data collection accuracy and ensure attack path fidelity- Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound- Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage- Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises- Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams- Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders- Work in complex and critical environments that power the economy- Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skillsRequirements- 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments- Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar)- Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation- Familiarity with containerized environments (e.G., Kubernetes) and associated RBAC/security implications- Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments- Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings- Working knowledge of Linux and Windows operating systems- Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team),
and purple teaming methodologies- Ability to reverse-engineer or emulate TTPs from threat intel reports- Ability to analyze and identify complex cross-platform attack vectors- Hands‑on experience with AD and/or cloud‑focused penetration testing, threat simulation, or detection/response in regulated or complex production environments- PaaS/SaaS operational know‑how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management- Offensive/defensive security certifications or cloud security specialties are nice‑to‑have- BloodHound Operator Certification (BHOC) is nice‑to‑have- Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them- Proven ability to build, grow, and maintain relationships both internally and externallyCore CompetenciesDemonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures.Highest-signal resume keywords- BloodHound Enterprise Operation- Active Directory Security- Cloud Security Engineering- DevOps/CI-CD Tooling- Penetration TestingATS Optimization KeywordsHard Skills- BloodHound Ciphers- PowerShell- C#- Python- Network Protocols- Identity and Access Management- Container Security- Threat Emulation Frameworks- Cross‑Platform Attack Analysis- PaaS/SaaS OperationsSoft Skills- Relationship Building- Communication- Collaboration- Goal Setting- Problem SolvingCertifications & Qualifications- BloodHound Operator Certification- Offensive Security Certifications- Cloud Security SpecialtiesIndustry Keywords- Red Team Operations- Blue Team Operations- Purple Team Methodologies- MITRE ATT&CK- Threat Detection- Incident Response- Regulated Environments- Complex Production EnvironmentsTools & Technologies- Jenkins- GitHub Actions- Terraform- CloudFormation- Ansible- Kubernetes- Linux- Windows#J-18808-Ljbffr
📌 Intermediate Security Specialist (Toronto)
🏢 Confidential
📍 Toronto