Senior Security Specialist – Attack Path Management

Jobtailor

Toronto

On-site

CAD 110,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking a BloodHound-focused security engineer to map identity attack paths across on-prem and cloud platforms, including Entra/Azure, AWS, and GCP. The role emphasizes validating data accuracy, expanding coverage into CI/CD pipelines, and collaborating with IAM, Threat Detection, and Incident Response teams.

You will work in cross-functional teams to extend attack path analytics, contribute to red/blue/purple team exercises, and share insights with stakeholders across cloud

Qualifications

  • 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments.
  • Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar).
  • Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation.
  • Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications.
  • Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments.
  • Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings.
  • Working knowledge of Linux and Windows operating systems.
  • Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team), and purple teaming methodologies.
  • Ability to reverse-engineer or emulate TTPs from threat intel reports.
  • Ability to analyze and identify complex cross-platform attack vectors.
  • Hands-on experience with AD and/or cloud-focused penetration testing, threat simulation, or detection/response in regulated or complex production environments.
  • PaaS/SaaS operational know-how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management.
  • Offensive/defensive security certifications or cloud security specialties are nice-to-have
  • BloodHound Operator Certification (BHOC) is nice-to-have
  • Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them
  • Proven ability to build, grow, and maintain relationships both internally and externally

Responsibilities

  • Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms
  • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact
  • Validate data collection accuracy and ensure attack path fidelity
  • Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound
  • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage
  • Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises
  • Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams
  • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders
  • Work in complex and critical environments that power the economy
  • Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills

Skills

BloodHound
Active Directory
Entra/Azure
AWS/GCP
PowerShell
C#
Python
Kubernetes
DevOps/CI-CD tooling
Threat Emulation

Tools

Jenkins
GitHub Actions
Terraform
CloudFormation
Ansible
Linux
Windows

Job description

• Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms
• Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact
• Validate data collection accuracy and ensure attack path fidelity
• Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound
• Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage
• Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises
• Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams
• Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders
• Work in complex and critical environments that power the economy
• Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills

Requirements

  • 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments
  • Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar)
  • Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation
  • Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications
  • Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments
  • Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings
  • Working knowledge of Linux and Windows operating systems
  • Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team), and purple teaming methodologies
  • Ability to reverse-engineer or emulate TTPs from threat intel reports
  • Ability to analyze and identify complex cross-platform attack vectors
  • Hands‑on experience with AD and/or cloud‑focused penetration testing, threat simulation, or detection/response in regulated or complex production environments
  • PaaS/SaaS operational know‑how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management
  • Offensive/defensive security certifications or cloud security specialties are nice‑to‑have
  • BloodHound Operator Certification (BHOC) is nice‑to‑have
  • Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them
  • Proven ability to build, grow, and maintain relationships both internally and externally

Core Competencies

Demonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures.

Highest-signal resume keywords

  • BloodHound Enterprise Operation
  • Active Directory Security
  • Cloud Security Engineering
  • DevOps/CI-CD Tooling
  • Penetration Testing

ATS Optimization Keywords

Hard Skills

  • BloodHound Ciphers
  • PowerShell
  • C#
  • Python
  • Network Protocols
  • Identity and Access Management
  • Container Security
  • Threat Emulation Frameworks
  • Cross‑Platform Attack Analysis
  • PaaS/SaaS Operations

Soft Skills

  • Relationship Building
  • Communication
  • Collaboration
  • Goal Setting
  • Problem Solving

Certifications & Qualifications

  • BloodHound Operator Certification
  • Offensive Security Certifications
  • Cloud Security Specialties

Industry Keywords

  • Red Team Operations
  • Blue Team Operations
  • Purple Team Methodologies
  • MITRE ATT&CK
  • Threat Detection
  • Incident Response
  • Regulated Environments
  • Complex Production Environments

Tools & Technologies

  • Jenkins
  • GitHub Actions
  • Terraform
  • CloudFormation
  • Ansible
  • Kubernetes
  • Linux
  • Windows
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

Jobgether • Toronto, Vancouver

Hybrid
CAD 120,000 - 160,000
Hybrid-remote working
Professional training and conference
Access to industry cybersecurity培训
+1
Senior Security Specialist – Cloud
Senior Security Specialist – Cloud

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
Senior Attack Path Architect | BloodHound & IAM Trails
Senior Attack Path Architect | BloodHound & IAM Trails

RBC • Vancouver

Hybrid
CAD 110,000 - 150,000
Total rewards program
Annual training budget
Hybrid-remote work environment
+2
Senior Systems Administrator
Senior Systems Administrator

Jobtailor • Coquitlam

On-site
CAD 90,000 - 130,000
Director, IT & Cybersecurity
Director, IT & Cybersecurity

Jobtailor • Toronto

On-site
CAD 150,000 - 190,000
Cybersecurity Production Expert
Cybersecurity Production Expert

Tech Talent International • Montreal (administrative region)

Hybrid
CAD 110,000 - 120,000
Bonus 9%
Vacation 3–5 weeks
RRSP contribution
+2
Senior Red Team Engineer
Senior Red Team Engineer

OffSeq • North Glengarry

Hybrid
CAD 40,983 - 49,089
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Infrastructure Developer – Platform Engineering
Infrastructure Developer – Platform Engineering

Jobtailor • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Software Engineer II – Release & Deploy
Software Engineer II – Release & Deploy

Jobtailor • Toronto

On-site
CAD 90,000 - 130,000