
Senior Purple Team Engineer
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in Canada.
• Take ownership and spearhead incident response preparedness throughout KOHO.
• Strategize and implement adversarial simulations: define engagement scopes, operate under established rules of engagement, conduct offensive operations, and present findings that facilitate measurable security enhancements.
• Enhance incident response capability across KOHO and develop response playbooks for marketing, data, legal, human resources, risk, and more.
• Facilitate tabletop exercises with executive leadership to assess risk tolerance and constraints.
• Record lessons learned, operational enhancements, and updates to playbooks. Implement all improvements.
• Lead incident response and digital forensics investigations during cybersecurity incidents.
• Prepare post-incident documentation to identify contributing factors and extract lessons learned.
• Design and implement internal deception mechanisms to identify lateral movement, insider threats, and unauthorized access within KOHO's environment.
• Develop external-facing deception capabilities, such as fake credentials, canary tokens integrated into customer-facing platforms, and decoy infrastructures embedded in breach databases and other surfaces accessible to attackers.
• Equip deception assets to provide actionable threat intelligence and incorporate findings into detection logic, playbooks, and the overall threat model.
• Establish the triage and response process for alerts triggered by deception into current SOC operations, from signal identification to investigation and lessons learned.
• Bachelor's degree in computer science, technology management, or a related technical or management discipline.
• You are a proactive individual capable of constructing programs from the ground up and establishing operations.
• Practical experience and a solid understanding of AWS.
• Experience in designing and implementing deception programs that encompass both internal detection assets and external-facing deception frameworks.
• Strong expertise in MITRE ATT&CK and the cyber kill chain.
• Practical experience in planning and executing adversarial simulations, including defining engagement scopes, establishing rules of engagement, and delivering post-engagement reports.
• Familiarity with operating offensive security tools and techniques to replicate real-world threat actor behavior.
• Competitive compensation & equity
• Generous vacation + Wellness days + Flex Days + holiday closure
• Remote-first environment + coworking support + yearly all hands retreat
• Access to coaching & growth programs
• Parental top-up & leave policies
• Comprehensive health benefits
• Power-up budgets for books, home office setup, phone & internet, AI tools, and professional development
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.