SOC Purple Team Expert
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
The SOC Purple Team Expert is a senior, hands-on practitioner who brings offensive and defensive teams together to measurably improve prevention, telemetry, detection, investigation, and response.
POSITION MAIN ACTIVITIES
Security Operations Center (SOC) delivers the following capabilities to the AXA entities around the globe: Security Incident Detection, Threat Hunting, Security Incident Response and Threat Intelligence.
KEY RESPONSIBILITIES
- Threat-led exercise planning: Translate threat intelligence, recent incidents, material business risks, and detection-coverage gaps into prioritized hypotheses, exercise objectives, rules of engagement, and measurable success criteria.
- Adversary emulation and control validation: Design and execute safe, authorized campaigns and atomic tests across endpoint, identity, email, network, and cloud attack surfaces. Emulate relevant adversary behaviors and map activity to MITRE ATT&CK techniques.
- Detection engineering partnership: Work directly with detection engineers and threat hunters to validate telemetry, create and tune analytics, reduce blind spots and false negatives, and verify the quality of KQL queries, correlation rules, and behavioral detections.
- End-to-end SOC readiness: Assess whether alerts are generated, enriched, triaged, escalated, investigated, contained, and documented as intended. Exercise both technical controls and operational procedures, including automated response playbooks.
- Remediation and re-testing: Record evidence and root causes, agree practical actions with control owners, prioritize findings by threat relevance and business impact, track closure, and independently re-test until the expected outcome is demonstrated.
- Automation and capability development: Develop reusable test content, telemetry replay, orchestration, reporting, and platform integrations using Python, PowerShell, Bash, APIs, version control, and CI/CD practices.
- Measurement and reporting: Maintain ATT&CK-aligned coverage views and report on control performance, detection pass rate, time to validate priority TTPs, remediation progress, and recurring gaps. Communicate technical evidence and risk clearly to senior stakeholders.
- Collaboration and mentoring: Facilitate purple-team workshops, after-action reviews, and knowledge-sharing sessions. Coach SOC analysts and engineers in adversary behavior, test design, evidence collection, and sustainable detection improvement
PROFILE
Experience
- At least 5 years of hands-on experience across offensive security, adversary emulation, penetration testing, detection engineering, threat hunting, incident response, or closely related disciplines.
- At least 3 years of practical red-team or purple-team experience, including planning and safely executing threat-led exercises in enterprise environments.
- Demonstrated experience turning test results into improved telemetry, detections, investigation procedures, response playbooks, and validated remediation.
- Experience working with distributed teams and stakeholders in a large, regulated, or multi-entity organization is strongly preferred.
Education
- University degree in information security, computer science, engineering, or an equivalent combination of professional training and relevant work experience.
Technical Skills and Competencies
- Adversary tradecraft: Strong knowledge of attack paths and post-exploitation behaviors across Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, networks, and cloud services.
- Threat-informed defense: Deep working knowledge of MITRE ATT&CK and the ability to convert threat intelligence into realistic, scoped, and measurable test scenarios.
- SOC technologies: Proficiency with SIEM, EDR/XDR, SOAR, network security monitoring, email security, identity telemetry, and cloud security logging. Microsoft Sentinel, Defender XDR, and Kusto Query Language (KQL) expertise are strongly preferred.
- Emulation frameworks: Hands-on experience with adversary-emulation, breach-and-attack simulation, command-and-control, and atomic testing frameworks. Ability to select the lightest safe technique that satisfies the test objective.
- Detection validation: Ability to trace expected telemetry from source to analytics and analyst workflow, identify collection and parsing defects, validate rule logic, and distinguish control failure from test failure.
- Engineering and automation: Advanced scripting in Python and working proficiency in PowerShell and/or Bash; experience with APIs, Git, CI/CD, infrastructure or content as code, and structured test data.
- Analysis and communication: Ability to expl