Senior Security Specialist - Attack Path Management (Global Security)

Socket.dev

Toronto

Hybrid

CAD 110,000 - 170,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work/life balance
Hybrid-remote working environment
Bonuses and stock where applicable
Training and conference attendance

Job summary

RBC is seeking a security-focused professional to operate and optimize BloodHound Enterprise, mapping identity attack paths across on-prem and cloud environments (AD/Entra, AWS, GCP).

You will expand coverage into CI/CD pipelines and IAM tooling, design collectors, and collaborate with Red Team and cloud-focused teams to improve exposure management and risk visibility.

Qualifications

  • 3+ years in on-premises and cloud security/engineering with AD and Entra/Azure, AWS or GCP.
  • Proficient in PowerShell, C#, Python and BloodHound tooling.
  • Familiar with Kubernetes and RBAC/security implications.
  • Experience in cross-team collaboration across security and cloud platforms.

Responsibilities

  • Operate and tune BloodHound Enterprise to map identity attack paths across multicloud environments.
  • Extend attack path coverage into CI/CD pipelines and IAM tooling with OpenHound.
  • Collaborate with Red Team and stakeholders to model realistic attack paths and remediation.
  • Communicate exposure, remediation progress, and identity risk trends to teams.

Skills

Active Directory
Entra/Azure
AWS
GCP
Cloud security
DevOps/CI-CD tooling
PowerShell
C#
Python
BloodHound
Kubernetes

Tools

Jenkins
GitHub Actions
Terraform
CloudFormation
Ansible

Job description

Job Description
What will you do?
  • Attack Path Operations
    • Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps (e.g., GitHub), and PAM platforms (and more!).
    • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact.
    • Validate that data collection accurately reflects the true state of the environment, ensuring attack path fidelity.
  • Coverage Expansion
    • Extend attack path coverage into CI/CD pipelines (e.g., Jenkins), secrets management (e.g., HashiCorp), IAM tooling and more with OpenHound.
    • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage.
  • Red Team & Stakeholder Collaboration
    • Assist the Red Team in building realistic attack paths to support covert operations and adversary emulation exercises.
    • Build strong relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams.
    • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders
Must Haves
  • 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments.
  • Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar).
  • Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation.
  • Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications.
  • Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments.
  • Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings.
  • Working knowledge of Linux and Windows operating systems.
Nice-to-Have
  • Certifications
    • Offensive/defensive security certifications (OSCP, CPTS, CAPE, GXPN, MCRTP, ACRTP, GCRTP, etc.) and/or cloud security specialties (AWS/GCP/Azure).
    • BloodHound Operator Certification (BHOC), regardless of specialty.
  • Tradecraft & Methodology
    • Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team), purple teaming methodologies, and the ability to reverse-engineer or emulate TTPs from threat intel reports.
    • Ability to analyze and identify complex cross-platform attack vectors.
  • Hands-on Experience
    • AD and/or cloud-focused penetration testing, threat simulation, or detection/response in regulated or complex production environments.
    • PaaS/SaaS operational know-how (SLAs, load balancing, high availability, OS patching, networking, security patch management).
  • Above average performance. You are competitive and passionate. You thrive on challenge and have a proven ability to set ambitious but achievable goals and surpass them.
  • A team player.At RBC we work together. You will be the type of person that brings that approach to your work. You will have a proven ability to build, grow, and maintain relationships both internally and externally.
What’s in it for you?

At a team level, you will have exposure to operating in complex and critical environments that power our economy. You will work with talented and driven offensive, defensive, and threat hunting security experts; refining and expanding your skillset. You will be given the opportunity to attend industry-leading public and private training sessions to take your skills to the next level.

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference in our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable;
  • Dedicated budget for annual training and conference attendance;
  • Leaders who support your development through coaching, training, and managing opportunities;
  • Ability to make a difference and lasting impact;
  • Work in a dynamic, collaborative, progressive, and high-performing team;
  • Flexible work/life balance options including a hybrid-remote working environment;
  • Opportunities to do challenging work;
  • Opportunities to take on progressively greater accountabilities; and
  • Opportunities to build close relationships with various cyber security teams.
Job Skills

Confidentiality, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security, Strategic Thinking

Additional Job Details

Address:

16 YORK ST:TORONTO

City:

Toronto

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2026-09-06

Application Deadline:

2026-09-25

Note

Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Endpoint Security Operations Analyst (Global Security)
Senior Endpoint Security Operations Analyst (Global Security)

Socket.dev • Toronto

On-site
CAD 100,000 - 135,000
Total Rewards Program
Leadership development
Flexible work‑life balance
+1
Senior Cyber Security Network Analyst (Global Security)
Senior Cyber Security Network Analyst (Global Security)

RBC • Vancouver

On-site
CAD 90,000 - 120,000
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Bedford

On-site
CAD 110,000 - 160,000
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Ottawa

On-site
CAD 120,000 - 180,000
Total rewards program
Annual training budget
Stock where applicable
Senior Security Detection Engineer (Global Security)
Senior Security Detection Engineer (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 180,000
Bonuses and flexible benefits
Stock options where applicable
World-class training program
Senior Endpoint Security Operations Analyst (Global Security)
Senior Endpoint Security Operations Analyst (Global Security)

RBC • Toronto

On-site
CAD 90,000 - 130,000
Total Rewards Program
Flexible benefits
Work-life balance
+1
Senior Cyber Security Network Analyst (Global Security)
Senior Cyber Security Network Analyst (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 150,000
Total rewards program
Flexible benefits
Coaching and development
+2
Senior Information and Data Security Analyst (Global Security)
Senior Information and Data Security Analyst (Global Security)

Socket.dev • Toronto

On-site
CAD 110,000 - 140,000
Total Rewards Program
Coaching and development opportunities
Flexible work-life balance
+2
Principal Engineer, Cyber Technology Operations SRE (Global Security)
Principal Engineer, Cyber Technology Operations SRE (Global Security)

RBC • Vancouver

On-site
CAD 160,000 - 230,000
Total rewards program
Bonuses and stock where applicable
Flexible benefits
+2
Senior Manager, Data Security Automations & Engineering (Global Security)
Senior Manager, Data Security Automations & Engineering (Global Security)

RBC • Toronto

On-site
CAD 140,000 - 210,000
Total rewards program
Coaching & development
Impactful work
+3