Purple Team Manager (Defense Improvement Analysis)

Posted yesterday

capital one national associationMcLean (VA)
Information Security AnalystsComputer Systems Design Services

SENIORITY

Senior

Apply

About the role

At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors, who love to solve real problems and meet real customer needs. We want you to be curious and ask "what if?" Capital One started as an information strategy company that specialized in credit cards, and we have become one of the most impactful and disruptive players in the industry.Capital One's Offensive Security Purple Team reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment by conducting covert/overt adversary simulation and emulation. This position works closely with offensive and defensive partner teams to plan, coordinate, execute and report on detection gaps and control weaknesses to improve cyber defense across the enterprise.The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One's brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats.ResponsibilitiesLead "Defense Improvement Analysis" (DIA): Deconstruct adversary simulation activities to identify control gaps and document the full lifecycle, from initial discovery to final technical resolution. Engineering & Analytics: Perform advanced analysis of log events using big data tools to identify, recommend, and engineer specific solutions for threat detection and response.Strategic Collaboration: Serve as the technical bridge between offensive and defensive stakeholders, translating complex adversary TTPs into durable defense strategies and actionable recommendations for both technical and executive audiences. Operational Research: Continuously research emerging threat behaviors and automate repetitive post-exploitation analysis tasks to scale the team's ability to identify and address novel TTPs.Infrastructure & Tooling: Build and maintain the technical infrastructure and lab environments required to support and evolve Purple Team activities.Basic QualificationsHigh School Diploma, GED, or equivalent certification. At least 4 years of information security experience. At least 3 years of experience in Threat Hunting or Detection Engineering within a cloud or hybrid environment. At least 2 years of experience analyzing EDR telemetry and bypass techniques.PreferredQualifications 2+ years of experience performing offensive security operations. 2+ years experience with Databricks, Spark, or similar for security analytics. 4+ years of experience in log analysis, threat detection engineering, threat hunt, incident response, forensics. 4+ years of experience with scripting and compiled languages. One or more of the following certifications: OSCP, OSCE, GPEN, GXPN, CRTO, GCFA, GCIH, OSTH, GDAT.At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization). Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace.Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this