Senior Security Specialist - Attack Path Management (Global Security)

Jobgether

Toronto, Vancouver

Hybrid

CAD 120,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid-remote working
Professional training and conference
Access to industry cybersecurity培训
Mentorship and development

Job summary

Jobgether seeks a Senior Security Specialist - Attack Path Management based in Canada to identify and reduce identity-driven security risks across on-prem and cloud environments. You’ll map attack paths, analyze Tier Zero exposures, and collaborate with Red, Blue, and Purple Teams to strengthen enterprise resilience.

You will expand coverage into CI/CD, secrets management, and IAM tooling, while designing custom tooling and supporting threat simulations.

Qualifications

  • 3+ years in enterprise on-premises and cloud security or engineering with hands-on AD/Entra-Azure, AWS and/or GCP.
  • Strong understanding of IAM, network protocols, misconfigurations, and attack paths across AD, cloud and DevOps.
  • Experience with Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible or comparable tooling.
  • Proficiency with BloodHound, PowerShell, C#, Python; ability to build or automate security tools/workflows.
  • Familiarity with Kubernetes and RBAC security implications.
  • Experience in Red/Blue/Purple Team operations and security testing in enterprise environments.
  • Strong communication to translate security findings to technical and non-technical stakeholders.

Responsibilities

  • Operate and tune BloodHound Enterprise to map identity-based attack paths across AD, Entra/Azure, AWS, GCP, and PAM systems.
  • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by exploitability and impact.
  • Validate data collection accuracy to ensure accurate attack path analysis.
  • Expand coverage into CI/CD pipelines, secrets management, IAM tooling with OpenHound and custom collectors.
  • Design and maintain custom tooling to enrich attack path intelligence beyond standard capabilities.
  • Support Red Team activities by developing realistic attack paths and threat simulations.
  • Collaborate with Cloud Engineering, IAM, Threat Detection, and SOC teams and communicate findings clearly.
  • Contribute to security initiatives across complex enterprise environments and improve attack path practices.

Skills

Identity & IAM
Attack path analysis
Security collaboration
Excellent communication
Cloud security
Linux/Windows
Problem solving
Security certifications (valued)

Tools

BloodHound
PowerShell
C#
Python
Kubernetes
RBAC
GitHub Actions
Jenkins
Terraform
CloudFormation
Ansible

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Specialist - Attack Path Management (Global Security) based in Canada.

This role focuses on identifying and reducing identity-driven security risks across complex enterprise environments. You will operate and continuously improve attack path management capabilities spanning on-premises Active Directory, Entra/Azure, AWS, GCP, DevOps platforms, and privileged access management systems. You will analyze attack paths, Tier Zero exposures, and critical choke points to prioritize remediation based on real-world exploitability and business impact. The position also offers opportunities to expand coverage across CI/CD, secrets management, IAM, and other emerging technologies. You will collaborate closely with Red, Blue, and Purple Teams as well as cloud, identity, detection, and incident response specialists. This is a highly collaborative environment where strong technical judgment, communication, and offensive security expertise can directly strengthen enterprise resilience.

Accountabilities:

  • Operate, continuously tune, and improve BloodHound Enterprise to map identity-based attack paths across Active Directory, Entra/Azure, AWS, GCP, DevOps platforms such as GitHub, PAM environments, and other enterprise technologies.
  • Analyze attack path data to identify critical choke points, Tier Zero exposures, and high-risk identity relationships, prioritizing remediation according to exploitability and business impact.
  • Validate the accuracy and completeness of data collection to ensure attack path analysis accurately represents the underlying environment.
  • Expand attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms using OpenHound and custom collectors.
  • Help design, build, adapt, and maintain custom tooling that enriches attack path intelligence beyond standard platform capabilities.
  • Support Red Team activities by developing realistic attack paths for covert operations, adversary emulation, and threat simulation exercises.
  • Build strong working relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, Incident Response, SOC, and other cybersecurity teams.
  • Communicate attack path exposures, identity risk trends, remediation progress, and security findings clearly to technical teams, internal stakeholders, and business audiences.
  • Contribute to security initiatives across complex and critical enterprise environments while continuously improving attack path management practices and capabilities.
Requirements
  • 3+ years of experience in enterprise on-premises and cloud security or engineering, with hands‑on knowledge of Active Directory and Entra/Azure, AWS, and/or GCP environments.
  • Strong understanding of identity and access management, network protocols, common security misconfigurations, and attack paths spanning AD, cloud, and DevOps environments.
  • Experience with DevOps and CI/CD technologies such as Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or comparable tooling.
  • Proficiency with BloodHound Ciphers and PowerShell, C#, and/or Python, with the ability to build, customize, or automate security tools and workflows.
  • Familiarity with containerized environments such as Kubernetes, including RBAC models and associated security implications.
  • Experience working in or supporting Red Team, Blue Team, and/or Purple Team operations within enterprise environments.
  • Working knowledge of both Linux and Windows operating systems.
  • Strong analytical, strategic-thinking, decision‑making, problem‑solving, and attention‑to‑detail skills, with the ability to identify complex cross‑platform attack vectors.
  • Excellent communication skills, including the ability to translate technical security findings into clear, high‑impact messages for both technical and non‑technical stakeholders.
  • A collaborative mindset and demonstrated ability to build, maintain, and strengthen relationships across cybersecurity and technology teams.
  • Offensive or defensive security certifications such as OSCP, CPTS, CAPE, GXPN, MCRTP, ACRTP, GCRTP, and/or cloud security certifications are valued.
  • BloodHound Operator Certification (BHOC) is a plus.
  • Familiarity with MITRE ATT&CK, Caldera, Atomic Red Team, purple teaming methodologies, and the ability to reverse‑engineer or emulate threat actor TTPs from threat intelligence reports is advantageous.
  • Hands‑on experience with AD or cloud penetration testing, threat simulation, detection and response, or security operations in regulated or highly complex production environments is preferred.
  • Knowledge of PaaS/SaaS operational practices, including SLAs, load balancing, high availability, OS patching, networking, and security patch management, is an advantage.
  • A high‑performance mindset, passion for cybersecurity, willingness to take on challenging problems, and ability to set ambitious but achievable goals are important for success.
Benefits
  • Comprehensive total rewards program that may include bonuses, flexible benefits, competitive compensation, commissions, and stock where applicable.
  • Dedicated annual budget for professional training and conference attendance.
  • Access to industry‑leading public and private cybersecurity training to deepen offensive, defensive, and threat‑hunting expertise.
  • Coaching, mentorship, and development opportunities supported by experienced leaders.
  • Exposure to complex and critical enterprise environments where cybersecurity plays an important role in protecting systems that support the broader economy.
  • Opportunity to collaborate with highly skilled offensive security, defensive security, and threat‑hunting professionals.
  • Hybrid‑remote working environment designed to support flexibility and work‑life balance.
  • Dynamic, collaborative, progressive, and high‑performing team culture.
  • Opportunities to make a meaningful security impact and take on progressively greater responsibilities.
  • Opportunities to build strong relationships across a broad range of cybersecurity and technology teams.
  • Full‑time, salaried position with a standard 37.5‑hour work week.
  • Work location options include Toronto or Vancouver, Canada.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

RBC • Vancouver

Hybrid
CAD 110,000 - 150,000
Total rewards program
Annual training budget
Hybrid-remote work environment
+2
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

Jobgether • Toronto

Hybrid
CAD 120,000 - 180,000
Bonuses
Stock options
Training budget
+2
Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

Socket.dev • Toronto

Hybrid
CAD 110,000 - 170,000
Flexible work/life balance
Hybrid-remote working environment
Bonuses and stock where applicable
+1
Senior Software Developer - Offensive AI (Global Security)
Senior Software Developer - Offensive AI (Global Security)

Jobgether • Toronto

Hybrid
CAD 120,000 - 170,000
Hybrid-remote working environment
Bonuses and flexible benefits
Annual training budget
+2
Spécialiste en Sécurité Offensive-Red Team
Spécialiste en Sécurité Offensive-Red Team

Vaco by Highspring • Quebec

On-site
CAD 80,000 - 100,000
Accès à des mandats stimulants
Développement professionnel
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1