Director of Offensive Security

NMC2

Dallas, Northern (TX, KY)

Hybrid

USD 180,000 - 260,000

Full time

8 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Lunch stipend
Medical/Dental/Vision benefits
401(k) match
Paid time off and holidays
Equal opportunity employer

Job summary

NorthMark Compute & Cloud (NMC²) is seeking a Director of Offensive Security to own continuous adversarial validation of our production environment, including HPC clusters and multi-tenant Kubernetes. You will emulate threat actors, measure detection efficacy, and drive remediation with an objective risk-based approach.

You will lead a mature security program, partner with SOC/IR teams, and report directly to the CISO.

Qualifications

  • 15+ years in offensive security with hands-on depth across multiple domains.
  • 5+ years leading offensive security teams with hiring and operations responsibility.
  • Proven red team leadership in mature SOC/EDR/IR environments.
  • Deep fluency with MITRE ATT&CK v15 and adversary emulation planning.
  • Hands-on tooling with production-grade offensive capabilities and strong comms.

Responsibilities

  • Build and run a continuous red team program against the production NMC² environment: HPC clusters, multi-tenant Kubernetes, bare-metal provisioning, customer network fabric, identity plane, and internal control surface.
  • Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model.
  • Independently validate detection and response efficacy with measurable metrics.
  • Own the purple team feedback loop and track undetected/undressed TTPs with owners and SLAs.
  • Run continuous attack surface validation against production with documented rules of engagement and authorization gates.
  • Lead threat-led penetration testing of HPC-specific surfaces including Slurm, GPU paths, InfiniBand, and scheduler escalation.
  • Own offensive validation of cloud and Kubernetes controls and secrets management integrity.
  • Drive threat modeling at design stage for new platform capabilities and architecture changes.
  • Manage external pentest vendors and integrate findings into remediation tracking.
  • Build and maintain the offensive tooling stack with custody and destruction controls.
  • Define and publish offensive security KPIs to leadership and the board.

Skills

Offensive security
Red team leadership
MITRE ATT&CK v15
Cloud and Kubernetes security
Adversary emulation

Tools

Cobalt Strike
Mythic
Sliver
Caldera

Job description

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, acc elerating discovery and driving faster innovation.

The Position

The Director of Offensive Security reports directly to the CISO and owns continuous adversarial validation of the NMC² production environment. This is not a scheduled pentest function or a compliance-checkbox red team. You will build and run a standing offensive capability that operates against production with authorization, emulates named threat actors relevant to our customer base and infrastructure class, and produces independent, evidence-backed assessments of whether our controls work under realistic attack conditions.

This function operates as an independent line of assurance within the Security organization, with a direct reporting relationship to the CISO. To preserve objectivity, assessment findings are delivered to the CISO without editorial review by the teams whose controls or systems are under evaluation. Security Engineering, Platform Engineering, and Security Architecture receive findings as remediation owners.

Responsibilities:

Build and run a continuous red team program against the production NMC² environment: HPC clusters, multi-tenant Kubernetes, bare-metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface itself (SIEM, EDR, IAM, PAM)

Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers (e.g., TTP sets associated with initial access brokers targeting financial services customers), APT groups with demonstrated interest in research computing and scientific workloads, and insider threat scenarios covering privileged operator abuse

Independently validate detection and response efficacy: every red team operation produces a detection coverage report measured against the SOC and IR functions, including time-to-detect, time-to-contain, and detection gap inventory by ATT&CK technique ID

Own the purple team feedback loop: every undetected TTP becomes a tracked detection engineering deliverable with owner and SLA, every detected-but- unresponded TTP becomes a tracked IR playbook deliverable

Run continuous attack surface validation against production, not just pre-production, with a documented rules-of-engagement framework, blast radius controls, and CISO-level authorization gates for destructive or high-risk techniques

Lead threat-led penetration testing of the HPC-specific attack surface: Slurm and workload manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross-tenant lateral movement in shared compute, and scientific software supply chain compromise

Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross-account and cross-tenant escape attempts, container breakout chains, service mesh bypass, admission controller evasion, and secrets management integrity

Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial design reviews that the CISO signs off on before build

Manage the external pentest and red team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation tracking system

Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit development capability, with clear controls on tool custody, source code management, and destruction protocols

Define and publish offensive security KPIs to CISO and board level: coverage against MITRE ATT&CK technique inventory, mean time to compromise from assumed-breach scenarios, control validation pass rate by control family, remediation velocity on P1 and P2 findings, and repeat finding rate

Issue formal assessment reports using CWE classification, CVSS v3.1 base and environmental scoring, and explicit exploitation evidence; findings are attestations, not suggestions

Champion an adversarial engineering culture across Platform and Security Engineering through documented attack patterns, regular internal briefings, and integration of offensive findings into developer tooling and CI/CD gates

R equirements:

1 5 + years in offensive security with demonstrated hands-on depth across at least three of: network penetration testing, red team operations, cloud penetration testing, application exploitation, hardware and firmware attack research, or advanced adversary emulation

5+ years leading offensive security teams, including direct accountability for hiring specialized offensive talent, managing operational security of red team infrastructure, and operating under formal rules of engagement against production systems

Demonstrated red team leadership against mature target environments: environments with functioning SOC, EDR, and IR capability, not greenfield pentest targets

Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple team execution models

Hands-on capability with production-grade offensive tooling: C2 frameworks (Cobalt Strike, Mythic, Sliver, or equivalent), exploitation frameworks, custom tool development, and operational security for red team infrastructure

Strong command of cloud and container offensive tradecraft: Kubernetes attack paths, cloud IAM privilege escalation chains, service mesh and sidecar abuse, and multi-tenant isolation testing

Fluency with CWE, CVSS v3.1 and v4.0, OWASP Top 10, SANS CWE Top 25, and the CIS Controls v8 Penetration Testing domain (Control18)

Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking, not report-and-walk-away engagements

Demonstrated ability to execute offensive work against production with appropriate authorization , blast radius control, and executive communication discipline

Exceptional written communication: findings must stand up to scrutiny from engineering leadership who will push back, and from auditors and customers who will consume the output

Preferred:

OSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications; CISSP alone is not sufficient evidence of hands-on offensive capability

Prior experience building an offensive security function from scratch, not inheriting an existing one

HPC, bare-metal, or hyperscale data center offensive assessment experience

Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research

Background in threat intelligence consumption for adversary emulation planning (CTI-led red teaming)

Experience with sovereign cloud, export-controlled, or financial services customer environments

It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company’s needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Company-Paid Lunch Stipend: Lunch is provided via GrubHub

Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability

401(k): Company will match 100% of your contributions up to 6%

Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.

Time Off: 25 days of Paid Time Off plus 12 company holidays

EQUAL OPPORTUNITY EMPLOYER

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Offensive Security
Director of Offensive Security

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 180,000 - 280,000
Lunch stipend
Company-paid benefits
Director of Offensive Security
Director of Offensive Security

NorthMark Compute and Cloud LLC • Dallas (TX)

On-site
USD 180,000 - 280,000
Lunch Stipend
Medical Insurance
Parental Leave (16 weeks)
+5
Director of Offensive Security
Director of Offensive Security

NorthMark Strategies LLC • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
Director of Vulnerability and Exploits
Director of Vulnerability and Exploits

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 280,000
Lunch stipend
Medical benefits
Dental & Vision
+7
Senior Offensive Security Engineer
Senior Offensive Security Engineer

United States Digital Space LLC • Bellevue (NY)

On-site
USD 187,000 - 220,000
Health insurance
Equity
Wellness allowance
+4
Offensive Security Consultant
Offensive Security Consultant

NEPSE Trading • Northern (KY)

On-site
USD 120,000 - 150,000
Health insurance
Paid holidays
401(k) with company match
+2
Managing Principal, Red Team Operator
Managing Principal, Red Team Operator

Armadin • Palo Alto (CA)

On-site
USD 200,000 - 320,000
Full Health, Dental, & Vision Coverage
Meaningful Equity Ownership
In-Office Meals
+3
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Town of Texas (WI)

On-site
USD 90,000 - 130,000
Flexible work environment
Paid education reimbursement
Volunteer day
Principal Offensive Security Engineer
Principal Offensive Security Engineer

Jobs Paloaltonetworks • California (MO)

On-site
USD 170,000 - 275,000
Senior Platform Security Engineer
Senior Platform Security Engineer

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 120,000 - 180,000
Lunch stipend
Medical benefits
Parental leave
+2