Adversary Emulation Manager

·
Full time
Location: Belfast
·
Job offered by: TN United Kingdom
·
Social network you want to login/join with: Operating as a function of Cyber Defence under Information Security, you will lead TP ICAP’s purple teaming function, ensuring the firm is well positioned to prevent and detect modern cyber-attacks. As TP ICAP embarks on extensive EDR and SIEM refresh projects, you will be responsible for ensuring these tools are fit for purpose through the delivery of threat-led sprints and the creation or customization of attack detection rules. Being able to model sophisticated and persistent adversaries is essential, and you will be given existing tools such as Prelude, Cobalt Strike, and Vectr to support you, plus any others that you identify. Role Responsibilities

Define and execute purple team sprints that materially and demonstrably improve TP ICAP’s ability to prevent and detect modern attacks. Simulate both established and emerging attacker TTPs and personally build the respective detection rules and response procedures. Identify opportunities to reduce TP ICAP’s attack surface using preventative controls through the delivery of purple team sprints. Work with the Security Engineering team as necessary to support the deployment and tuning of security-related tooling, particularly those that pertain to prevention and detection. Develop processes for attack surface monitoring and constant validation through automation. Act as an escalation point for the SOC and assist with incident response. Experience / Competences

Practical experience emulating sophisticated cyber-attacks, likely in a purple or red team capacity. Deep understanding of modern attacker tools, techniques, and procedures. Comfortable identifying appropriate telemetry sources to collect and using these to build custom attack detection rules where out-of-the-box capability doesn’t exist. Active contributor to offensive security research and/or tooling, perhaps presenting this research at industry-recognized conferences and forums. Experience working with a SOC to: Tune existing rules and increase alert fidelity/decrease alert fatigue. Include analysts on the purple team journey, aiding in staff retention. Train analysts in modern attacker TTPs and the ‘attacker mindset’. Able to evade defensive controls such as EDR and AV, tailoring open-source tooling and rolling your own where required. Experience using Infrastructure-as-Code to support emulation activities, for example Terraform/Ansible. Experience attacking or securing AWS infrastructure. Development experience in one or more programming languages, with one of them ideally being Python.

#J-18808-Ljbffr

Recent Jobs

London (On site) · Full time

Are you a smart, driven professional who takes pride in making a difference in local communities? Turner & Townsend’s Real Estate division is experiencing significant growth and we’re looking for an experienced industry professional with health project experience to join our high-performing and collaborative Project Management team. Why Join Us? Impactful Work: Contribute to social [...]Read More... from Assistant Project Manager – Healthcare See details

Chasetown (On site) · Full time

My client, Autosmart International are a manufacturing success story! Site Operations Manager – leading fast-paced manufacturing and warehousing About Our Client Autosmart International is a manufacturing success story, leading the field in vehicle cleaning products. We are the No.1 choice of automotive trade customers across the UK. We have doubled in size in the last [...]Read More... from Site Operations Manager See details

London (On site) · Full time

CSS are looking for an experienced duty officer to join our client’s team who are a local council responsible for all areas within the Tendering district. Working hours: All shifts are 8 hours long with various start times available: Monday to Friday – start times between 6AM – 3PM Saturday & Sunday – 6AM – [...]Read More... from Duty Officer See details