Director of Offensive Security

NorthMark Compute and Cloud LLC

Dallas (TX)

On-site

USD 180,000 - 280,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Lunch Stipend
Medical Insurance
Parental Leave (16 weeks)
Employee Assistance Program
Life Insurance
Short/Long-Term Disability Insurance
401(k) matching
Wellhub benefits

Job summary

NorthMark Compute and Cloud LLC is seeking a Director of Offensive Security to own continuous adversarial validation of our production environment, operate an authorized red-teaming program across HPC, Kubernetes, and cloud infrastructure, and report to the CISO.

You will lead threat emulation, validate detection and response, drive KPI reporting to the board, and oversee external red-team vendors while shaping adversarial design reviews for platform changes.

Job description

Director of Offensive Security

The Director of Offensive Security reports directly to the Chief Information Security Officer (CISO) and owns continuous adversarial validation of the NMC² production environment. This is not a scheduled penetration testing function but a standing offensive capability that operates against production with authorization, emulates named threat actors relevant to our customer base and infrastructure class, and produces evidence‑backed assessments of whether our controls hold under realistic attack conditions.

Responsibilities:

  • Build and run a continuous red team program against the production NMC² environment – HPC clusters, multi‑tenant Kubernetes, bare‑metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface (SIEM, EDR, IAM, PAM).
  • Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers, APT groups with interest in research computing, and insider threat scenarios covering privileged‑operator abuse.
  • Independently validate detection and response efficacy: every red‑team operation generates a detection coverage report measured against the SOC and IR functions, including time‑to‑detect, time‑to‑contain, and detection gap inventory by ATT&CK technique ID.
  • Own the purple‑team feedback loop: every undetected TTP becomes a tracked detection‑engineering deliverable with owner and SLA, every detected‑but‑unresponded TTP becomes a tracked IR playbook deliverable.
  • Run continuous attack surface validation against production (not just pre‑production) with a documented Rules‑of‑Engagement framework, blast‑radius controls, and CISO‑level authorization gates for destructive or high‑risk techniques.
  • Lead threat‑led penetration testing of the HPC‑specific attack surface: Slurm and workload‑manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross‑tenant lateral movement in shared compute, and scientific software supply‑chain compromise.
  • Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross‑account and cross‑tenant escape attempts, container breakout chains, service‑mesh bypass, admission‑controller evasion, and secrets‑management integrity.
  • Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial‑design reviews that the CISO signs off on before build.
  • Manage the external pentest and red‑team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation‑tracking system.
  • Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit‑development capability, with clear controls on tool custody, source‑code management, and destruction protocols.
  • Define and publish offensive security KPIs to the CISO and board level: coverage against MITRE ATT&CK technique inventory, mean time to compromise from assumed‑breach scenarios, control‑validation pass rate by control family, remediation velocity on P1 and P2 findings, and repeat‑finding rate.
  • Issue formal assessment reports using CWE classification, CVSS v3.1 base and environmental scoring, and explicit exploitation evidence; findings are attestations, not suggestions.
  • Champion an adversarial engineering culture across Platform and Security Engineering through documented attack patterns, regular internal briefings, and integration of offensive findings into developer tooling and CI/CD gates.
Requirements
  • 15+ years in offensive security with demonstrated hands‑on depth across at least three of: network penetration testing, red‑team operations, cloud penetration testing, application exploitation, hardware and firmware attack research, or advanced adversary emulation.
  • 5+ years leading offensive security teams, including direct accountability for hiring specialized offensive talent, managing operational security of red‑team infrastructure, and operating under formal rules of engagement against production systems.
  • Demonstrated red‑team leadership against mature target environments with functioning SOC, EDR, and IR capability, not greenfield pentest targets.
  • Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple‑team execution models.
  • Hands‑on capability with production‑grade offensive tooling: C2 frameworks (Cobalt Strike, Mythic, Sliver, or equivalent), exploitation frameworks, custom tool development, and operational security for red‑team infrastructure.
  • Strong command of cloud and container offensive trade‑craft: Kubernetes attack paths, cloud IAM privilege escalation chains, service mesh and side‑car abuse, and multi‑tenant isolation testing.
  • Fluency with CWE, CVSS v3.1 & v4.0, OWASP Top 10, SANS CWE Top 25, and the CIS Controls v8 Penetration Testing domain (Control18).
  • Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking.
  • Demonstrated ability to execute offensive work against production with appropriate authorization, blast‑radius control, and executive communication discipline.
  • Exceptional written communication: findings must stand up to scrutiny from engineering leadership, auditors, and customers.
Preferred
  • OSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications; CISSP alone is not sufficient evidence of hands‑on offensive capability.
  • Prior experience building an offensive security function from scratch, not inheriting an existing one.
  • HPC, bare‑metal, or hyperscale data‑center offensive assessment experience.
  • Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research.
  • Background in threat intelligence consumption for adversary emulation planning (CTI‑led red teaming).
  • Experience with sovereign cloud, export‑controlled, or financial services customer environments.
Benefits & Perks
  • Company‑Paid Lunch Stipend: Lunch is provided via GrubHub.
  • 100% Employer‑Paid Medical in a High‑Deductible Health Plan, Dental and Vision benefits for employees and families.
  • 16 weeks of Paid Parental Leave.
  • Employee Assistance Program.
  • Life insurance, Short‑Term Disability and Long‑Term Disability.
  • 401(k): Company will match 100% of your contributions up to 6%.
  • Medical insurance in our PPO plan and other benefits such as Health Savings Accounts (with Company Contribution), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays.
Equal Opportunity Employer

NorthMark Strategies LLC is an equal employment opportunity employer. The company’s policy is not to discriminate against any applicant or employee based on race, color, religion, national or origin, gender, age, sexual orientation, gender identity or expression, marital status, mental or physical disability, genetic information, or any other basis protected by applicable law. The firm also prohibits harassment of applicants or employees based on any of these protected categories. Must be legally authorized to work in the United States without the need for employer sponsorship, now or in the future.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Offensive Security
Director of Offensive Security

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
Lunch stipend
Medical/Dental/Vision benefits
401(k) match
+2
Director of Offensive Security
Director of Offensive Security

NorthMark Strategies LLC • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
Director of Vulnerability and Exploits
Director of Vulnerability and Exploits

NorthMark Strategies LLC • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Company-Paid Lunch Stipend
Company-Paid Benefits: Medical, Dental
401(k) match up to 6%
+2
Senior Platform Security Engineer
Senior Platform Security Engineer

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 120,000 - 180,000
Lunch stipend
Medical benefits
Parental leave
+2
Network Security Engineer
Network Security Engineer

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 120,000 - 180,000
Lunch stipend
Employer-paid medical
Dental & Vision
+4
Director of Cyber Defense
Director of Cyber Defense

NorthMark Strategies LLC • United States

On-site
USD 210,000 - 260,000
Lunch stipend
Employer-paid health benefits
401(k) match
+1
Senior Platform Security Engineer
Senior Platform Security Engineer

NorthMark Strategies • Dallas (TX)

On-site
USD 120,000 - 150,000
Company-Paid Lunch Stipend
100% Employer-Paid Medical Benefits
401(k) Matching
+1
Senior Network Security Engineer
Senior Network Security Engineer

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 125,000 - 180,000
Lunch stipend
Medical benefits
Dental & Vision
+6
Senior Network Security Engineer
Senior Network Security Engineer

NorthMark Strategies • Dallas (TX)

On-site
USD 100,000 - 130,000
Company-Paid Lunch Stipend
100% Employer-Paid Medical
401(k) Match
+1
Director, Operational Technology (OT) Engineering
Director, Operational Technology (OT) Engineering

NorthMark Compute & Cloud • Spartanburg (SC)

On-site
USD 180,000 - 240,000
Lunch stipend
Company‑paid benefits
401(k) match
+2