- Runs red and purple team engagements against critical apps, infrastructure and controls
- Builds and maintains fit-for-purpose red team infrastructure
- Validates controls, detection and logging; finds gaps and proves they are closed
- Owns an d matures Breach & Attack Simulation
- Uses AI to scale attack-path analysis and prioritise the gaps that matter
- Closes the loop: proposes remediation, recent detections, log sources and controls; drives findings into the engineering backlog
- Acts as the validation arm of threat-informed defence (ATT&CK-mapped;)
Must-have skills:
- Hands-on offence: adversary emulation, C2, exploitation, attack-path analysis across cloud / infra / endpoint
- Detection and logging fluency (the purple half)
- BAS and ATT&CK;
- Python and automation; tight rules-of-engagement discipline