Adversary Emulation Analyst

TP ICAP

London, United Kingdom
Hybrid
Emulating sophisticated cyber-attacks
Purple or red team capacity
Build detection rules and response procedures
Define and execute purple team sprints that materially and demonstrably improve TP ICAP’s ability to prevent and detect modern attacks

Job Summary

  • Define and execute purple team sprints that materially and demonstrably improve TP ICAP’s ability to prevent and detect modern attacks.
  • Work in tandem with the SOC to tune existing rules and increase alert fidelity/decrease alert fatigue, and train analysts in modern attacker TTPs.
  • Develop processes for attack surface monitoring and constant validation through automation, and act as an escalation point for the SOC.

Matching Summary

Define and execute purple team sprints that materially and demonstrably improve TP ICAP’s ability to prevent and detect modern attacks.

Skills & Requirements

Must-have

  • Emulating sophisticated cyber-attacks
  • Purple or Red Team capacity
  • Build detection rules and response procedures
  • Tune existing rules and increase alert fidelity
  • Familiarity with Mitre ATT&CK
  • Development/automation experience

Nice-to-have

  • Active contributor to offensive security research
  • Tailoring open-source tooling
  • Familiarity with AWS
  • Inclusivity and diverse perspectives

Key Requirements

  • Experienced Red/Purple team operator
  • Practical experience emulating sophisticated cyber-attacks
  • Able to evade defensive controls
  • Experience working closely with the SOC
  • Strong knowledge of offensive security and modern attacker TTPs

Work Rights

Not specified

Tailored Resume

Cover Letter