Manager, Offensive Security: Purple Team

Capital One Capital One · Banking · McLean, VA +2

Manager, Offensive Security: Purple Team role at Capital One. Focuses on reducing cyber risk through adversary simulation and emulation, identifying vulnerabilities, and improving cyber defense. Responsibilities include leading Defense Improvement Analysis, performing advanced log analysis for threat detection, collaborating between offensive and defensive teams, researching emerging threats, and building/maintaining infrastructure for Purple Team activities.

What you'd actually do

  1. Lead "Defense Improvement Analysis" (DIA): Deconstruct adversary simulation activities to identify control gaps and document the full lifecycle, from initial discovery to final technical resolution.
  2. Engineering & Analytics: Perform advanced analysis of log events using big data tools to identify, recommend, and engineer specific solutions for threat detection and response.
  3. Strategic Collaboration: Serve as the technical bridge between offensive and defensive stakeholders, translating complex adversary TTPs into durable defense strategies and actionable recommendations for both technical and executive audiences.
  4. Operational Research: Continuously research emerging threat behaviors and automate repetitive post-exploitation analysis tasks to scale the team’s ability to identify and address novel TTPs.
  5. Infrastructure & Tooling: Build and maintain the technical infrastructure and lab environments required to support and evolve Purple Team activities.

Skills

Required

  • High School Diploma, GED, or equivalent certification.
  • At least 4 years of information security experience.
  • At least 3 years of experience in Threat Hunting or Detection Engineering within a cloud or hybrid environment.
  • At least 2 years of experience analyzing EDR telemetry and bypass techniques.

Nice to have

  • 2+ years of experience performing offensive security operations
  • 2+ years experience with Databricks, Spark, or similar for security analytics.
  • 4+ years of experience in log analysis, threat detection engineering, threat hunt, incident response, forensics
  • 4+ years of experience with scripting and compiled languages
  • One or more of the following certifications: OSCP, OSCE, GPEN, GXPN, CRTO, GCFA, GCIH, OSTH, GDAT

What the JD emphasized

  • advanced analysis of log events using big data tools
  • Continuously research emerging threat behaviors
  • build and maintain the technical infrastructure