1

Adversary Emulation Jobs in Tennessee (NOW HIRING)

Adversary Emulation information

What is adversary emulation?

Adversary emulation is a cybersecurity practice in which security professionals simulate real-world cyber attackers, or adversaries, to test and improve an organization’s defenses. By mimicking the tactics, techniques, and procedures (TTPs) used by actual threat actors, adversary emulation helps organizations identify vulnerabilities, assess detection and response capabilities, and strengthen their overall security posture. These exercises are often based on threat intelligence and frameworks like MITRE ATT&CK to ensure realistic scenarios.

What are the key skills and qualifications needed to thrive in adversary emulation?

To thrive in Adversary Emulation, you need deep knowledge of cybersecurity, attack methodologies, and penetration testing, often supported by degrees in computer science or related certifications such as OSCP or CISSP. Familiarity with tools like Cobalt Strike, Metasploit, and SIEM platforms is commonly required. Analytical thinking, creativity, and strong communication skills are essential to mimic real-world threats and report findings clearly. These skills are crucial for accurately simulating adversary tactics, identifying security gaps, and helping organizations strengthen their cyber defenses.

What are the typical challenges faced by professionals in adversary emulation roles?

Adversary Emulation specialists often encounter the challenge of staying ahead of rapidly evolving attack techniques and threat actor behaviors. They must continuously update their knowledge and adapt their methodologies to realistically mimic current adversaries, which requires ongoing research and collaboration with threat intelligence teams. Additionally, balancing the realism of simulated attacks with organizational risk tolerance and ensuring minimal disruption during assessments can be complex. Working closely with security operations, incident response, and IT teams is essential to maximize the value of each engagement and provide actionable insights for improving defenses.

What is the difference between Adversary Emulation vs Penetration Tester?

AspectAdversary EmulationPenetration Tester
CredentialsCybersecurity certifications, threat intelligence knowledgeSecurity certifications, ethical hacking certifications
Work EnvironmentSimulates real-world adversary tactics in controlled environmentsIdentifies vulnerabilities through controlled testing
Industry UsageUsed in threat simulation, red teaming, and advanced security assessmentsUsed in vulnerability assessments and security audits

Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.

What are popular job titles related to Adversary Emulation jobs in Tennessee?

For Adversary Emulation jobs in Tennessee, the most frequently searched job titles are:

What job categories do people searching Adversary Emulation jobs in Tennessee look for?

The top searched job categories for Adversary Emulation jobs in Tennessee are:

What cities in Tennessee are hiring for Adversary Emulation jobs?

Cities in Tennessee with the most Adversary Emulation job openings:

Infographic showing various Adversary Emulation job openings in Tennessee as of July 2026, with employment types broken down into 99% Full Time, and 1% Part Time. Highlights an 99% Physical, and 1% Remote job distribution.

Cybersecurity Threat Engineer

Creative Arts Agency (CAA)

Nashville, TN • On-site

Full-time

Re-posted 29 days ago


Key responsibilities

  • Support leadership with enterprise-wide vulnerability identification, assessment, and remediation programs across infrastructure, cloud, and applications.

  • Provide continuous visibility to new and emerging threats against existing security controls; ensuring controls remain effective to changing business and threat landscapes.

  • Support the Offensive Security Lifecycle via management of internal and external Cyber Threat and Offensive Security assessments.


Job description

Job Description

Who We Are

Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA's diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world's top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.
The Role

Strategic and technically adept cybersecurityprofessionalwith deepexpertiseinVulnerabilityManagement,OffensiveSecurity, and advanced threat detection. AsLeadof Cyber ThreatEngineering,this individual willberesponsible fordriving proactive defense initiatives thatidentifyand mitigate risks before they can be exploited. Experienced in leading red and purple team operations, orchestrating vulnerability assessments, and integrating threat intelligence to inform remediation and hardening strategies. Skilled in aligning offensive security insights with enterprise risk managementand Incident Response Strategies, improving security posture through automation, and fostering a culture of continuous testing and improvement. Recognized for building high-performing teams that bridge the gap between adversary emulation and defensive readiness to ensure comprehensive protection across digital assets.

We are looking for candidates whohave apassionforcyber security, threat detection,riskmitigation,andautomation. You willprovideinsightinourefforts to build and support a defensibleenvironment where we are able to detect,containand respond quickly to threats, vulnerabilitiesand compromisein ways that serve to enablethetechnologyneedsofahighly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud servicesalong withthe challenges of integrating those services into our security practice.

Responsibilities

  • Support leadership withenterprise-wide vulnerability identification, assessment, and remediation programs across infrastructure, cloud, and applications.

  • Provide continuous visibility to new and emerging threats against existing securitycontrols;ensuring controlsremaineffectivetochanging business and threat landscapes.

  • Work across the Tech department to enhance security posture capabilities to limit security misconfigurations through secure configuration standards,monitoring,and remediation.

  • Integrate automated scanning and vulnerability intelligence into CI/CD and asset management systems.

  • Translate offensive findings into actionable security improvements anddetection ofengineering use cases.

  • Collaborate with defensive teams tovalidatesecurity controls and improve resilience through continuous testing.

  • Support the Offensive Security Lifecycle via management ofinternal and externalCyber Threat and Offensive Security assessments.

  • Partner closelywithIncident Response teams to enhancedetection oflogic, playbooks, and threat-hunting capabilities.

Qualifications

  • Aminimum of6years' experience delivering information security solutions, ideally withAmixed focus onoffensive and defensive security roles.

  • bachelor'sor master's degree in a relevant field of work

  • Hands on experience inCyber Threat and Offensive Securityoperationsto test andvalidatethe effective operation of securitycontrols,measuring the ability to stop threats and attacks at the earliest point in the kill chain

  • Proventrack recordworking as both an individual contributor andleadin the areas ofCyberThreat,VulnerabilityManagement, orIncidentResponse

  • Strong understanding of the fundamental operations of servers, operating systems, networks,cloudapplicationsand infrastructurealong withanadvancedunderstanding of the key controls required for secure operation of these systems

  • experience scriptingin at least one of the following languages: PowerShell, Python, JavaScript

  • experiencein aligning threat and vulnerability management efforts to frameworksand controlobjectives-MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP,

  • Experience integrating thefollowing toolsand capabilitiesintoa successfulthreat and vulnerabilityprogram - Security OrchestrationAutomation and Response, Security Information andEvent Management, Vulnerability Scanning,SecurityThreat Feeds,Red TeamTooling

Location

This role is hybrid, based in our Nashville office.

Compensation

The annual base salary for this position is in the range of $111,000 - $133,000 in Nashville. This position is also eligible for benefits and a discretionary bonus. Ultimately, the salary may vary based upon, but not limited to, relevant experience, time in the role, business sector, and geographic location, among other criteria. Please talk with a CAA Recruiter to learn more.
#LI-MS1

Creative Artists Agency, LLC (the "Company") is committed to a policy of Equal Employment Opportunity and will not discriminate on the basis of race (inclusive of traits historically associated with race, including hair texture and protective hairstyles), color, religion, creed, gender or sex (including pregnancy, childbirth, breastfeeding or related medical conditions), national origin, ancestry, age, physical disability, mental disability, medical condition, genetic information, family and medical care leave status, military or veteran status, marital status, family status, sexual orientation, gender identity, gender expression, political affiliation, an employee's or their dependent's reproductive health decision making (e.g., the decision to use or access a particular drug, device or medical service), or any other characteristic protected by applicable law.The absence of a permanent address is not a bar to employment. The Company does not discriminate against individuals based on housing status, including the absence of a fixed address.The Company also complies with the Americans with Disabilities Act and applicable state and local laws with regard to providing reasonable accommodation for qualified individuals with disabilities.CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.