Principal Purple Team Operator

1611 Ally Bank

North Carolina

Hybrid

USD 110,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid time off
Holidays
401K retirement
Health insurance
Parental leave
Relocation assistance
Employee discounts

Job summary

Ally Financial is seeking a Principal of Cyber Security to join the Information Protection and Risk Management team. The role emphasizes aligning security initiatives with business objectives and guiding technical staff to achieve company goals.

This mid-to-senior level position requires strong offensive security experience, SIEM expertise, and excellent communication to coordinate policies, audits, and security testing across IT and business units.

Qualifications

  • At least 2 years in cybersecurity and 5 years in offensive security or red teaming.
  • Experience with enterprise-grade BAS solutions.
  • Familiarity with MITRE ATT&CK Navigator, Atomic Red Team and SIEM products.

Responsibilities

  • Collaborate with Director to align the security program with business needs.
  • Analyze threat landscape and report risks to leadership.
  • Lead policy improvements and ensure regulatory compliance.
  • Coordinate incident management and security testing procedures.
  • Provide security training for diverse audiences.
  • Liaise with vendors, legal, and procurement for contracts.

Skills

Cybersecurity
Red team
SIEM
MITRE Navigator
Atomic Red Team
BAS solutions
Communication skills
Analytical thinking
Team collaboration

Education

Bachelor's Degree in Computer Science or IT

Tools

MITRE ATT&CK Navigator
Atomic Red Team

Job description

Ally and Your Career Ally Financial only succeeds when its people do - and that’s more than some cliché people put on job postings. We love this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion. From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You’re constantly evolving, so shouldn’t your opportunities be, too?

Work Schedule: Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week as indicated by your manager. Your hiring manager will discuss this role's specific work requirements with you during the hiring process. All work requirements are subject to change at any time based on leader discretion and/or business need.

The Opportunity

The Principal of Cyber Security position at Ally is a member of the Information Protection and Risk Management team and works closely with other members of the IPRM program to develop and implement a comprehensive approach to the management of security risks at Ally. The Principal of Cyber Security role requires an individual with a strong technical background as well as an ability to work with the IT organization and business management to align priorities and plans with key business objectives. Responsible for providing technical guidance to staff as they work to accomplish company objectives. This is a mid-level to senior-level highly technical role. At this time, Ally will not sponsor a new applicant for employment authorization for this position.

Work Itself
  • Work with the Director of Security Operations to ensure the security program addresses identified risks and business requirements.
  • Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the Director of Security Operations with a realistic overview of risks and threats in the enterprise environment.
  • Identify process improvement opportunities and develop subsequent plans of action to resolve gaps with minimal management intervention.
  • Monitor and report on compliance with security policies and standards, as well as the enforcement of policies within the IT department.
  • Propose changes to existing policies and procedures to ensure operating efficiency and regulatory compliance.
  • Assist resource owners and IT staff in understanding and responding to security audit failures reported by auditors and regulatory bodies.
  • Provide security communication, awareness and training for audiences which may range from senior leaders to field staff.
  • Work as a liaison with vendors and the legal and purchasing departments to establish mutually acceptable contracts and service level agreements.
  • Manage production issues and incidents and participate in problem and change management forums.
  • Manage and coordinate operational components of incident management, including detection, response and reporting.
  • Manage the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend treatment plans and communicate information about residual risk.
  • Manage security projects and provide expert guidance on security matters for other IT projects.
  • Ensure audit trails, system logs and other monitoring data sources are reviewed periodically and are in compliance with policies and audit requirements.
  • Design, coordinate and oversee security testing procedures to verify the security of systems, networks and applications, and manage the remediation of identified risks.
Qualifications

We’re Looking For

  • Minimum of 2 years of experience in cybersecurity.
  • Minimum of 5 years of experience in offensive security or red teaming.
  • Proficient experience with enterprise-grade BAS solutions.
  • Experience working with the MITRE ATT&CK Navigator, Atomic Red Team, and various SIEM products.
  • Excellent communication and presentation skills, with the ability to effectively convey complex concepts to technical and non-technical audiences.
  • Strong analytical and problem-solving abilities.
  • Ability to work independently and collaboratively in a fast-paced environment.

Bonus Qualifications

  • Relevant certifications or ability to obtain within a year: OSCP, OSEP, OSAI, CRTO, CRTL, CPTS, COAE.
  • Experience leading adversary simulations and emulations.
  • Experience in the financial sector.

Minimum Qualifications

  • 7+ years of relevant experience
  • Bachelors' Degree in Computer Science, IT or similar field of study or equivalent
How We’ll Have Your Back
  • Time Away: Program starts at 20 paid time off days in addition to 11 paid holidays and 8 hours of volunteer time off yearly (time off days are prorated based on start date and program varies based on full or part-time status and management level).
  • Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan pay downs and 529 educational save up assistance programs, tuition reimbursement, employee stock purchase plan, and financial learning center and financial coach access.
  • Supporting your Health & Well-being: flexible health and insurance options including medical, dental and vision, employee, spouse and child life insurance, short- and long-term disability, pre‑tax Health Savings Account with employer contributions, Healthcare FSA, critical illness, accident & hospital indemnity insurance, and a total well‑being program that helps you and your family stay on track physically, socially, emotionally, and financially.
  • Building a Family: adoption, surrogacy and fertility assistance as well as paid parental and caregiver leave, Dependent Day Care FSA back‑up child and adult/elder care days and childcare discounts.
  • Work-Life Integration: other benefits including Mentally Fit Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
  • Other Compensations: depending on the role for which you are considered, you may be eligible for travel allowances, relocation assistance, a signing bonus and/or equity.
Compensation

Base Pay Range $110,000.00 - $180,000.00
An individual's position in the range is determined by the specific role, the scope and responsibilities of the role, work experience, education, certification(s), training, and additional qualifications. We review internal pay, the competitive market, and business environment prior to extending an offer.

Incentive Compensation: This position is eligible to participate in our annual incentive plan.

Who We Are

Ally Financial is a customer‑centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial‑services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com.

Equal Opportunity

Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.

In accordance with the Americans with Disabilities Act, if after review of the position expectations, you believe that you may need a medical accommodation to fulfill the duties of this role, please email hrpolicy@ally.com with details of your accommodation request.

CCPA Notice

CCPA Notice

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Principal Engineer
Cloud Security Principal Engineer

Ally-Financial • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Time Away including paid holidays
401K retirement plan
Health, dental, vision coverage
+1
Fellow - AI Offensive Security Engineer
Fellow - AI Offensive Security Engineer

1611 Ally Bank • North Carolina

Hybrid
USD 135,000 - 235,000
Time Off & Holidays
401K with company match
Relocation assistance
Principal Security Architect – Data Protection and Workplace Security
Principal Security Architect – Data Protection and Workplace Security

Ally-Financial • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Senior Software Engineer
Senior Software Engineer

Ally-Financial • Detroit (MI)

On-site
USD 85,000 - 150,000
Senior Financial Analyst - Technology Finance
Senior Financial Analyst - Technology Finance

1611 Ally Bank • United States

Hybrid
USD 70,000 - 120,000
Time Off & Holidays
401K with company contributions
Health Insurance
+2
Manager, Customer Identity & Access Management - CIAM
Manager, Customer Identity & Access Management - CIAM

Ally • Jacksonville (FL)

Hybrid
USD 110,000 - 180,000
Time off & holidays
401(k) retirement plan
Relocation assistance
+1
Director, Customer Identity & Access Management - CIAM
Director, Customer Identity & Access Management - CIAM

Ally-Financial • Charlotte (NC)

Hybrid
USD 125,000 - 190,000
Paid time off
401K with matching
Health insurance
+3
Third Party Application Manager
Third Party Application Manager

Ally • Charlotte (NC)

On-site
USD 90,000 - 150,000
Analyst- Business Intelligence
Analyst- Business Intelligence

1001 Ally Financial Inc. • United States

Hybrid
USD 65,000 - 115,000
Paid time off
401(k) plan
Healthcare coverage
+3
Director, Customer Identity & Access Management - CIAM
Director, Customer Identity & Access Management - CIAM

Ally • Jacksonville (FL)

Hybrid
USD 125,000 - 190,000