We are looking for a highly skilled Senior Purple Team Security Consultant with a strong offensive security background to join an experienced security team within a large and complex enterprise environment.
The primary focus of this role is the design and execution of Purple Team exercises across the customer's technology landscape. You will emulate realistic adversary behaviour, execute attack techniques and tactics, validate detection and response capabilities, and identify opportunities to improve the organization's cyber resilience.
You will work closely with senior security specialists, security engineering teams and detection teams to assess the effectiveness of existing security controls and drive continuous improvements in threat detection, response and overall security posture.
Responsibilities
- Design and execute Purple Team exercises based on realistic threat scenarios and adversary behavior.
- Execute adversarial Techniques, Tactics and Procedures (TTPs) aligned with frameworks such as MITRE ATT&CK.
- Perform threat-led security assessments and risk assessments across enterprise environments.
- Simulate attacker activities including privilege escalation, lateral movement, persistence and credential access techniques.
- Collaborate closely with security engineering, SOC and detection teams to validate and improve detection capabilities.
- Develop Purple Team scenarios based on current threat intelligence and attack trends.
- Assess security controls across on-premises, cloud and hybrid environments.
- Translate technical findings into business risks and actionable remediation recommendations.
- Contribute to continuous improvement of cyber defense capabilities and security maturity.
Environment
Purple Team exercises may encompass the complete customer environment, including:
- Mainframe platforms
- Enterprise on-premises infrastructure
- Private cloud environments
- Microsoft Azure public cloud
- Hybrid enterprise architectures
- Windows, macOS and Linux platforms
- Enterprise networking and security infrastructure
Required Experience
- Minimum 5 years of experience within Offensive Security, Red Teaming or Purple Teaming.
- Proven experience executing adversarial TTPs in enterprise environments.
- Experience performing threat assessments and risk assessments.
- Deep understanding of attack methodologies and attacker behavior.
- Extensive experience in complex Windows, macOS and Linux environments.
- Extensive experience working within complex enterprise IT architectures.
- Ability to translate technical risks into business impact and vice versa.
- Experience designing and executing Purple Team engagements independently.
Required Certifications
One or more of the following certifications are strongly preferred:
- OSCP (Offensive Security Certified Professional)
- OSEP (Offensive Security Experienced Penetration Tester)
- OSWE (Offensive Security Web Expert)
- OSED (Offensive Security Exploit Developer)
- CRTO (Certified Red Team Operator)
- CRTP (Certified Red Team Professional)
Personal Profile
- Takes ownership and works independently.
- Proactive and highly self-motivated.
- Analytical and pragmatic mindset.
- Strong communication and stakeholder management skills.
- Comfortable working in Agile environments.
- Fluent in spoken and written English.
- Curious, innovative and eager to continuously learn and experiment.