Senior Security Specialist - Attack Path Management (Global Security)
JobgetherThis position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Specialist - Attack Path Management (Global Security) based in Canada.
This role focuses on identifying and reducing identity-driven security risks across complex enterprise environments. You will operate and continuously improve attack path management capabilities spanning on-premises Active Directory, Entra/Azure, AWS, GCP, DevOps platforms, and privileged access management systems. You will analyze attack paths, Tier Zero exposures, and critical choke points to prioritize remediation based on real-world exploitability and business impact. The position also offers opportunities to expand coverage across CI/CD, secrets management, IAM, and other emerging technologies. You will collaborate closely with Red, Blue, and Purple Teams as well as cloud, identity, detection, and incident response specialists. This is a highly collaborative environment where strong technical judgment, communication, and offensive security expertise can directly strengthen enterprise resilience.
Accountabilities:
- Operate, continuously tune, and improve BloodHound Enterprise to map identity-based attack paths across Active Directory, Entra/Azure, AWS, GCP, DevOps platforms such as GitHub, PAM environments, and other enterprise technologies.
- Analyze attack path data to identify critical choke points, Tier Zero exposures, and high-risk identity relationships, prioritizing remediation according to exploitability and business impact.
- Validate the accuracy and completeness of data collection to ensure attack path analysis accurately represents the underlying environment.
- Expand attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms using OpenHound and custom collectors.
- Help design, build, adapt, and maintain custom tooling that enriches attack path intelligence beyond standard platform capabilities.
- Support Red Team activities by developing realistic attack paths for covert operations, adversary emulation, and threat simulation exercises.
- Build strong working relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, Incident Response, SOC, and other cybersecurity teams.
- Communicate attack path exposures, identity risk trends, remediation progress, and security findings clearly to technical teams, internal stakeholders, and business audiences.
- Contribute to security initiatives across complex and critical enterprise environments while continuously improving attack path management practices and capabilities.
Requirements
- 3+ years of experience in enterprise on-premises and cloud security or engineering, with hands-on knowledge of Active Directory and Entra/Azure, AWS, and/or GCP environments.
- Strong understanding of identity and access management, network protocols, common security misconfigurations, and attack paths spanning AD, cloud, and DevOps environments.
- Experience with DevOps and CI/CD technologies such as Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or comparable tooling.
- Proficiency with BloodHound Ciphers and PowerShell, C#, and/or Python, with the ability to build, customize, or automate security tools and workflows.
- Familiarity with containerized environments such as Kubernetes, including RBAC models and associated security implications.
- Experience working in or supporting Red Team, Blue Team, and/or Purple Team operations within enterprise environments.
- Working knowledge of both Linux and Windows operating systems.
- Strong analytical, strategic-thinking, decision-making, problem-solving, and attention-to-detail skills, with the ability to identify complex cross-platform attack vectors.
- Excellent communication skills, including the ability to translate technical security findings into clear, high-impact messages for both technical and non-technical stakeholders.
- A collaborative mindset and demonstrated ability to build, maintain, and strengthen relationships across cybersecurity and technology teams.
- Offensive or defensive security certifications such as OSCP, CPTS, CAPE, GXPN, MCRTP, ACRTP, GCRTP, and/or cloud security certifications are valued.
- BloodHound Operator Certification (BHOC) is a plus.
- Familiarity with MITRE ATT&CK, Caldera, Atomic Red Team, purple teaming methodologies, and the ability to reverse-engineer or emulate threat actor TTPs from threat intelligence reports is advantageous.
- Hands-on experience with AD or cloud penetration testing, threat simulation, detection and response, or security operations in regulated or highly complex production environments is preferred.
- Knowledge of PaaS/SaaS operational practices, including SLAs, load balancing, high availability, OS patching, networking, and security patch management, is an advantage.
- A high-performance mindset, passion for cybersecurity, willingness to take on challenging problems, and ability to set ambitious but achievable goals are important for success.
Benefits
- Comprehensive total rewards program that may include bonuses, flexible benefits, competitive compensation, commissions, and stock where applicable.
- Dedicated annual budget for professional training and conference attendance.
- Access to industry-leading public and private cybersecurity training to deepen offensive, defensive, and threat-hunting expertise.
- Coaching, mentorship, and development opportunities supported by experienced leaders.
- Exposure to complex and critical enterprise environments where cybersecurity plays an important role in protecting systems that support the broader economy.
- Opportunity to collaborate with highly skilled offensive security, defensive security, and threat-hunting professionals.
- Hybrid-remote working environment designed to support flexibility and work-life balance.
- Dynamic, collaborative, progressive, and high-performing team culture.
- Opportunities to make a meaningful security impact and take on progressively greater responsibilities.
- Opportunities to build strong relationships across a broad range of cybersecurity and technology teams.
- Full-time, salaried position with a standard 37.5-hour work week.
- Work location options include Toronto or Vancouver, Canada.