Enable job alerts via email!

Purple Team Senior Operator

JPMorganChase

City Of London

On-site

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Job summary

A leading global financial institution is seeking an experienced Purple Team Operator to join their Assurance Operations team. The role involves collaboration with the Cybersecurity Operations Center and conducting offensive activities to strengthen system defenses against threats. Ideal candidates will have extensive experience in penetration testing and network exploitation within cloud-based environments, as well as relevant cybersecurity certifications.

Qualifications

  • 3+ years of experience in Information Security, particularly in cloud-based environments.
  • Strong understanding of various operating systems and security tools.
  • Ability to analyze vulnerabilities and threats effectively.

Responsibilities

  • Collaborate with the Cybersecurity Operations Center for offensive activities.
  • Conduct hands-on research as part of Purple Team engagements.
  • Perform network exploitation and assessments.

Skills

Network exploitation
Threat hunting
Penetration testing
Cybersecurity principles

Education

BS/BA degree or equivalent experience

Tools

Cobalt Strike
Metasploit
Burp Suite
Job description

Working in Cybersecurity takes pure passion for technology, speed, a constant desire to learn, and above all, vigilance in keeping every last asset safe and sound. You'll be on the front lines of innovation, working with a highly-motivated team laser-focused on analyzing, designing, developing and delivering solutions built to stop adversaries and strengthen our operations.

Your research and work will ensure stability, capacity and resiliency of our products and emerging industry trends. Working in tandem with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop adversaries and strengthen our data.

Purple Team Operator Role

JPMC's Assurance Operations organization is looking to expand its Purple Team with an experienced Purple Team Operator with particular specialties in supporting Purple Team engagements and operating in cloud-based environments. The primary focus of this role will be to jointly collaborate with the firm's Cybersecurity Operations Center (SOC) to perform hands-on offensive activities and research as part of Purple Team engagements.

The successful candidate will have a proven track record in conducting network exploitation operations, to include Red Team and Purple Team assessments. Additionally, the candidate will be able to demonstrate in-depth knowledge and experience around computer networking fundamentals, modern threats and vulnerabilities, attack methodologies, incident response, threat hunting, and penetration testing tools.

Qualifications
  • BS/BA degree or equivalent experience
  • Excellent command of Cybersecurity organization practices, operations risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies
  • Ability to analyze vulnerabilities, threats, designs, procedures and architectural design, producing reports and sharing intelligence
  • 3+ years of Information Security experience in cloud-based environments (Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) in both private and public (AWS, Azure) environments) and in one or more of the following verticals: network penetration testing, application (web, mobile) penetration testing, Red Team/Purple Team operations, application security assessments, and network exploitation operations.
  • Strong understanding of the following: Windows/Linux/Unix/Mac operating systems; OS and software vulnerability and exploitation techniques; commercial or open-source offensive security tools for reconnaissance, scanning, exploitation, and post exploitation (e.g. Cobalt Strike, Metasploit, Burp Suite); networking fundamentals (all OSI layers, protocols); Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) providers in both private and public (AWS, Azure) environments; DevOps; incident response; threat hunting; and familiarity with interpreting log output from networking devices, operating systems, and infrastructure services
  • Preferred qualifications include: Intelligence Community/Security Services background, relevant certifications such as those offered by Offensive Security (OSCP, OSEP, OSED, OSEE, OSCE), CREST (Certified Simulated Attack Specialist, Registered Penetration Tester, Certified Infrastructure Tester), SANS (GPEN, GXPN, GWAPT), knowledge of malware packing, obfuscation, persistence, exfiltration techniques, and understanding of financial sector or other large security and IT infrastructures
  • Technical knowledge or experience developing proof of concept exploits and in house scripting, using interpreted languages such as Python, Ruby, or Perl, compiled languages such as C, C++, C#, or Java, and security tools or technology such as Firewalls, IDS/IPS, Web Proxies, DLP and the ability to articulate and visually present complex penetration testing and Red Team/Purple Team results is highly desirable
  • Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals
  • Experience with Agile and can work with at least one of the common frameworks is highly desired

We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.