Information Security Lead - Offensive and Threat Intel, Cheyenne

ANB Bank

Cheyenne (WY)

On-site

USD 73,000 - 107,000

Full time

31 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

PTO: 4 weeks
Medical, Dental, Vision Insurance
401(k) with company match
Discretionary annual bonus

Job summary

ANB Bank is seeking an Information Security Lead for Offensive and Threat Intel to own and advance the organization’s offensive security program across on-prem and cloud environments. You will guide red team operations, adversary emulation, and targeted testing to improve detection and response while coordinating with SOC and engineering teams.

The role requires senior expertise in Windows/AD, identity attack paths, and cloud security with hands-on experience in C2, EDR/XDR evasion, and rogue

Qualifications

  • Seven years of related experience and/or training.
  • Preferred college degree; or equivalent combination of education and experience.
  • Demonstrated expertise in Windows/Active Directory, identity attack paths (Kerberos/NTLM/LDAP/SSO), and cloud (Azure/Microsoft 365 a plus).
  • Hands‑on proficiency with C2 frameworks, EDR/XDR evasion techniques, password/credential attack methods, and lateral movement.
  • Strong understanding of detection engineering concepts, logging/telemetry, and purple team collaboration.
  • Exceptional communication skills with the ability to translate complex findings into business‑aligned risk narratives.
  • Several industry standard Information Security advanced certifications (OSCP, GXPN, CISSP) in good standing and appropriate training and experience required.

Responsibilities

  • Offensive Operations Program Ownership.
  • Define and maintain the offensive security strategy, roadmap, playbooks, SLAs, and rules of engagement (ROE).
  • Own intake and scoping for engagements; prioritize based on business impact, threat intel, and control validation needs.
  • Ensure all activities align with legal, regulatory, and corporate policy requirements, including operational safety and privacy controls.
  • Red Team & Adversary Emulation
  • Plan and execute realistic, threat-informed operations mapping to MITRE ATT&CK, targeting identity, endpoints, network, applications, and cloud services.
  • Develop and maintain adversary emulation plans, chained attack paths, and objective-based scenarios for critical business processes.
  • Oversee exploitation research and proof-of-concept development (privilege escalation, lateral movement, persistence) with strict safeguards and de-confliction.
  • Lead purple team exercises to drive measurable detections and response playbook improvements with Detection Engineering and SOC teams.

Skills

Windows/Active Directory
Identity attack paths
Cloud (Azure/Microsoft 365)
C2 frameworks
EDR/XDR evasion
Lateral movement
Communication skills

Education

Bachelor's degree or equivalent
Industry certifications (OSCP/GXPN/CISSP)

Tools

BloodHound
Burp Suite

Job description

General Information

Job Title: Information Security Lead - Offensive and Threat Intel

Location: 1912 Capitol Avenue, Cheyenne, WY 82001

Work Schedule: Monday - Friday, 8:00am - 5:00pm

Employee Type: Non-Exempt Full-Time

Hiring Pay Ranges: $35.00 - $51.50 per hour

The hiring pay range for this position is commensurate with the level of relevant experience and education.

This position may be eligible to receive an additional $1.00 per hour if approved for the Spanish Communication Assistant Program.

ANB Bank has financial strength embodied in $3 billion in assets and is a true community bank with an unwavering commitment to excellence. The bank helps each of its communities prosper through investment, sponsorship, philanthropy, and employee volunteerism. It is a passion ANB has for banking that makes the difference.

ANB Bank hires individuals who provide excellent customer service and build meaningful relationships with our customers and within our communities. ANB is committed to rewarding our team members who strengthen our company and culture. ANB offers competitive compensation and a comprehensive benefits package for this position.

Health & Wellness Benefits (Subject To Eligibility Requirements)
  • Minimum 4 Weeks of Paid Time Off (PTO)
  • 11 Paid Holidays
  • Medical, Dental, and Vision Insurance
  • Health Savings (HSA), Flexible Spending (FSA), and dependent care spending accounts
  • Company provided Life, AD&D, and Disability Insurance with supplementation options
  • 401(k) plan with discretionary company match and profit sharing
  • Discretionary annual bonus and employee referral incentives
  • Employee Assistance Program (EAP)
  • Tuition Reimbursement Program
  • Spanish Communication Assistant Program Incentive
  • Employee banking products
Summary

The Offensive Operations Team Lead owns the strategy, execution, and continuous improvement of the organization’s offensive security program. This role directs red team operations, adversary emulation, targeted penetration testing, and purple team exercises to measurably improve detection, response, and hardening across on-premises and cloud environments. The role partners closely with all other aspects of Information Security and relevant parties within the organization to validate control effectiveness and reduce risk to critical business services. Responsible for implementation and administration of corporate Information Security Systems as listed below.

Essential Duties And Responsibilities
  • Offensive Operations Program Ownership
  • Define and maintain the offensive security strategy, roadmap, playbooks, SLAs, and rules of engagement (ROE).
  • Own intake and scoping for engagements; prioritize based on business impact, threat intel, and control validation needs.
  • Ensure all activities align with legal, regulatory, and corporate policy requirements, including operational safety and privacy controls.
  • Red Team & Adversary Emulation
  • Plan and execute realistic, threat-informed operations mapping to MITRE ATT&CK, targeting identity, endpoints, network, applications, and cloud services.
  • Develop and maintain adversary emulation plans, chained attack paths, and objective-based scenarios for critical business processes.
  • Oversee exploitation research and proof-of-concept development (privilege escalation, lateral movement, persistence) with strict safeguards and de-confliction.
  • Lead purple team exercises to drive measurable detections and response playbook improvements with Detection Engineering and SOC teams.
  • Tooling, Infrastructure & Automation
  • Design, secure, and maintain operator environments (segmented labs, cloud resources, and approved tooling).
  • Evaluate and integrate offensive tools (e.g., BloodHound, Burp Suite, custom scripts) and maintain an internal, access-controlled repository.
  • Develop automation to streamline reconnaissance, validation, artifact collection, reporting, and metrics.
  • Collaboration, Communications & Reporting
  • Produce clear post-operation reports with technical detail, business impact, exploited control gaps, and prioritized remediation.
  • Partner with relevant parties to translate findings into backlog items; track remediation and validate fixes.
  • Provide executive-level updates and program metrics demonstrating risk reduction and control effectiveness over time.
  • Support Incident Response by advising on attacker TTPs, containment strategies, and root cause analysis when appropriate.
  • Governance, Safety & Compliance
  • Enforce ROE, change control, maintenance windows, de-confliction, and kill-switch procedures to protect production systems.
  • Document methodologies, tool usage, and operational decisions; maintain evidence handling and data retention practices.
  • Periodically review program compliance with legal, regulatory, and internal policy obligations (e.g., GLBA/PCI/FFIEC as applicable).
  • Continuous Improvement & Innovation
  • Track emerging threat actor behaviors, new exploits, and research; proactively test controls against evolving TTPs.
  • Upskill the team across identity, cloud, application, and social engineering domains; lead internal workshops and demos.
  • Establish and maintain a safe disclosure process for internally discovered vulnerabilities.
  • Threat Intelligence Integration
  • Consume and analyze internal and external threat intelligence to identify relevant adversary behaviors, emerging vulnerabilities, and likely attack paths targeting the financial sector.
  • Translate threat intelligence into actionable offensive testing objectives, adversary emulation plans, and targeted validation activities.
  • Maintain alignment between offensive operations and intelligence-driven priority threats, including nation-state TTPs, ransomware groups, and financially motivated actors.
  • Ensure operational findings feed back into Information Security threat models and detection logic.
  • Track exploit releases, zero-day disclosures, cloud-identity abuse techniques, and industry reports to proactively schedule offensive testing before weaponization impacts the organization.
  • Produce periodic intelligence-driven risk reports for leadership, highlighting threat trends, likely impacts, and recommended offensive validation activities.
  • Ensuring management is made aware of critical events and situations within the department.
  • Maintains a current knowledge and understanding of requirements, policies, configurations, and procedures related to the Information Security team.
  • Maintains a current knowledge and consistent compliance with Bank Secrecy Act (BSA) requirements, as well as knowledge and consistent compliance with other banking regulations and Bank policies and procedures related to the position.
  • Delivers quality of service as defined by department standards.
  • Maintains confidentiality as defined by department standards.
  • Supports the company’s Mission, Vision, and Values.
  • Other duties may be assigned.
Education and/or Experience
  • Seven years of related experience and/or training.
  • Preferred college degree; or equivalent combination of education and experience.
  • Demonstrated expertise in Windows/Active Directory, identity attack paths (Kerberos/NTLM/LDAP/SSO), and cloud (Azure/Microsoft 365 a plus).
  • Hands‑on proficiency with C2 frameworks, EDR/XDR evasion techniques, password/credential attack methods, and lateral movement.
  • Strong understanding of detection engineering concepts, logging/telemetry, and purple team collaboration.
  • Exceptional communication skills with the ability to translate complex findings into business‑aligned risk narratives.
  • Performs several, if not all, of the above duties with minimal direction and supervision.
  • Several industry standard Information Security advanced certifications (OSCP, GXPN, CISSP, etc) in good standing and appropriate training and experience required.

Equal Opportunity Employer / Aff… / …

ANB Bank

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Lead - Offensive and Threat Intel
Information Security Lead - Offensive and Threat Intel

Mt. Washington Pediatric Hospital • Cheyenne (WY)

On-site
USD 48,000 - 72,000
PTO 4 weeks
11 paid holidays
Medical, Dental, Vision insurance
+6
Senior Red Team Operator
Senior Red Team Operator

U.S. Bank • Englewood (CO)

Hybrid
USD 133,000 - 157,000
Healthcare (medical, dental, vision)
401(k) and employer‑funded retirement
Paid vacation and holidays
+2
Information Security Analyst
Information Security Analyst

Bank of the Orient • Millbrae (CA)

On-site
USD 110,000 - 140,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
2U Network Security Operations Analyst
2U Network Security Operations Analyst

NBH Bank • Kansas City (MO)

On-site
USD 90,000 - 120,000
Insurance
401k
Stock purchase plan
+2
2U Network Security Operations Analyst
2U Network Security Operations Analyst

Bankmw • Kansas City (MO)

On-site
USD 90,000 - 120,000
Insurance
401k
Stock purchase program
+2
2U Network Security Operations Analyst
2U Network Security Operations Analyst

Vista Bank • Kansas City (MO)

On-site
USD 65,000 - 100,000
Insurance
401(k)
Stock purchase plan
+2
Technology Security Engineering Manager (Hybrid within a BankUnited Office Location)
Technology Security Engineering Manager (Hybrid within a BankUnited Office Location)

BankUnited • Town of Florida (NY)

On-site
USD 180,000 - 250,000
Information Security Officer
Information Security Officer

City First Bank • Washington

On-site
USD 90,000 - 130,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Koitecc Solutions • Denver (CO)

On-site
USD 160,000 - 205,000