NorthMark Strategies
Director of Offensive Security
Dallas, TX · Director
No sponsorshipDetected 21 days ago
Cloud PlatformsKubernetesCI/CDPlatform EngineeringCybersecurityPenetration TestingSIEMDetection EngineeringJiraSupply ChainResearchLeadershipCommunication
About the role
- This is not a scheduled pentest function or a compliance-checkbox red team.
- This function operates as an independent line of assurance within the Security organization, with a direct reporting relationship to the CISO.
- To preserve objectivity, assessment findings are delivered to the CISO without editorial review by the teams whose controls or systems are under evaluation.
Responsibilities
- Build and run a continuous red team program against the production NMC² environment: HPC clusters, multi-tenant Kubernetes, bare-metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface itself (SIEM, EDR, IAM, PAM)
- Own the purple team feedback loop: every undetected TTP becomes a tracked detection engineering deliverable with owner and SLA, every detected-but- unresponded TTP becomes a tracked IR playbook deliverable
- Lead threat-led penetration testing of the HPC-specific attack surface: Slurm and workload manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross-tenant lateral movement in shared compute, and scientific software supply chain compromise
- Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross-account and cross-tenant escape attempts, container breakout chains, service mesh bypass, admission controller evasion, and secrets management integrity
- Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial design reviews that the CISO signs off on before build
- Manage the external pentest and red team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation tracking system
- Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit development capability, with clear controls on tool custody, source code management, and destruction protocols
- Prior experience building an offensive security function from scratch, not inheriting an existing one
Requirements
- Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking, not report-and-walk-away engagements
- Demonstrated ability to execute offensive work against production with appropriate authorization, blast radius control, and executive communication discipline
Nice to have
- OSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications
- CISSP alone is not sufficient evidence of hands-on offensive capability
- HPC, bare-metal, or hyperscale data center offensive assessment experience
- Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research
- Background in threat intelligence consumption for adversary emulation planning (CTI-led red teaming)
- Experience with sovereign cloud, export-controlled, or financial services customer environments
Skills
- Security Engineering, Platform Engineering, and Security Architecture receive findings as remediation owners.
Benefits
- Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
- Company-Paid Lunch Stipend: Lunch is provided via GrubHub
- Time Off: 25 days of Paid Time Off plus 12 company holidays
- Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple team execution models
Company info
- Lunch is provided via GrubHub
- financially motivated access brokers (e.g., TTP sets associated with initial access brokers targeting financial services customers), APT groups with demonstrated interest in research computing and scientific workloads, and insider threat scenarios covering privileged operator abuse
- Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers (e.g., TTP sets associated with initial access brokers targeting financial services customers), APT groups with demonstrated interest in research computing and scientific workloads, and insider threat scenarios covering privileged operator abuse
- Exceptional written communication: findings must stand up to scrutiny from engineering leadership who will push back, and from auditors and customers who will consume the output
Equal opportunity
- NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER.
- THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW.
- THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.
Visa & Work Authorization
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Apply directly at NorthMark Strategies →Create a free account for alerts like thisView NorthMark Strategies immigration profile
This listing is sourced directly from NorthMark Strategies's careers page and normalized into a canonical job model.