Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Austin, TX · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Austin, TX · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise. * Build repeatable validation workflows using MSV and ...
Service Owner, Cybersecurity Operations (Hiring Our Heroes Corporate Fellow) - Remote
Rahway, NJ · On-site
... adversary emulation and red team engagements. The team focuses on identifying real-world attack paths across enterprise, cloud, and operational environments to measure risk exposure and strengthen ...
Service Owner, Cybersecurity Operations (Hiring Our Heroes Corporate Fellow) - Remote
Rahway, NJ · On-site
... adversary emulation and red team engagements. The team focuses on identifying real-world attack paths across enterprise, cloud, and operational environments to measure risk exposure and strengthen ...
Senior Manager Purple Team
Malvern, PA · On-site
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Senior Manager Purple Team
Malvern, PA · On-site
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Senior Manager Purple Team
Dallas, TX · On-site
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
Senior Manager Purple Team
Dallas, TX · On-site
Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and ...
... Adversary emulation - Develop complex, multi-stage exercise scenarios - Facilitate AARs to capture lessons learned, capability gaps, and individual performance metrics - Other duties as directed ...
... Adversary emulation - Develop complex, multi-stage exercise scenarios - Facilitate AARs to capture lessons learned, capability gaps, and individual performance metrics - Other duties as directed ...
Senior Engineer - Threat Hunting
Chicago, IL · On-site
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate real-world detection and response effectiveness * Identifying systemic detection and response ...
Senior Engineer - Threat Hunting
Chicago, IL · On-site
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate real-world detection and response effectiveness * Identifying systemic detection and response ...
Red Team Lead/Engineer
Bethesda, MD · On-site
Responsibilities : • Lead and execute Red Team and adversary emulation operations that simulate real-world attacker behaviors. • Conduct recurring testing activities to assess detection gaps ...
Red Team Lead/Engineer
Bethesda, MD · On-site
Responsibilities : • Lead and execute Red Team and adversary emulation operations that simulate real-world attacker behaviors. • Conduct recurring testing activities to assess detection gaps ...
Senior Engineer - Threat Hunting
Chicago, IL · On-site
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate real-world detection and response effectiveness * Identifying systemic detection and response ...
New
Senior Engineer - Threat Hunting
Chicago, IL · On-site
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate real-world detection and response effectiveness * Identifying systemic detection and response ...
New
Senior Engineer - Threat Hunting
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate realworld detection and response effectiveness * Identifying systemic detection and response ...
Senior Engineer - Threat Hunting
$107K - $147K/yr
Medical
Dental
Vision
Retirement
PTO
Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate realworld detection and response effectiveness * Identifying systemic detection and response ...
Lead Engineer - Red Team
Brooklyn Park, MN · On-site
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
New
Lead Engineer - Red Team
Brooklyn Park, MN · On-site
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
New
This role will focus on realistic adversary emulation, initial access, C2 infrastructure, operational security, endpoint telemetry, evasion research, Active Directory, cloud identity, and offensive ...
This role will focus on realistic adversary emulation, initial access, C2 infrastructure, operational security, endpoint telemetry, evasion research, Active Directory, cloud identity, and offensive ...
Lead Engineer - Red Team
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
Lead Engineer - Red Team
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
Sr. Consultant - Cloud Red Team Blue Team (Remote)
$60 - $81.75/hr
Medical
Retirement
PTO
You will conduct Cloud Red Team Blue Team (CRTBT) engagements as a Red Teamer, performing cloud-focused adversary emulation techniques against customer environments while the CrowdStrike Blue Teamer ...
Sr. Consultant - Cloud Red Team Blue Team (Remote)
$60 - $81.75/hr
Medical
Retirement
PTO
You will conduct Cloud Red Team Blue Team (CRTBT) engagements as a Red Teamer, performing cloud-focused adversary emulation techniques against customer environments while the CrowdStrike Blue Teamer ...
Cyber Hunt Senior Analyst with Security Clearance
Hampton, VA · On-site
$165K - $185K/yr
Advise on threat modeling, adversary emulation, and Purple Team exercises to validate and strengthen the agency's defensive posture. * Support interagency collaboration and national-level threat ...
Cyber Hunt Senior Analyst with Security Clearance
Hampton, VA · On-site
$165K - $185K/yr
Advise on threat modeling, adversary emulation, and Purple Team exercises to validate and strengthen the agency's defensive posture. * Support interagency collaboration and national-level threat ...
Lead Engineer - Red Team
Brooklyn Park, MN · On-site
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
Lead Engineer - Red Team
Brooklyn Park, MN · On-site
$132K - $238K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks
Adversary Emulation information
See salary details
$39.66 - $42.70
2% of jobs
$42.70 - $45.74
8% of jobs
$45.74 - $48.78
9% of jobs
$51.43 is the 25th percentile. Wages below this are outliers.
$48.78 - $51.81
6% of jobs
$51.81 - $54.85
11% of jobs
$54.85 - $57.89
7% of jobs
The median wage is $59.75 / hr.
$57.89 - $60.93
9% of jobs
$60.93 - $63.96
16% of jobs
$64.59 is the 75th percentile. Wages above this are outliers.
$63.96 - $67
24% of jobs
$67 - $70.04
4% of jobs
$70.04 - $73.08
2% of jobs
$39
$58
$73
How much do adversary emulation jobs pay per hour?
What is adversary emulation?
What is the difference between Adversary Emulation vs Penetration Tester?
| Aspect | Adversary Emulation | Penetration Tester |
|---|---|---|
| Credentials | Cybersecurity certifications, threat intelligence knowledge | Security certifications, ethical hacking certifications |
| Work Environment | Simulates real-world adversary tactics in controlled environments | Identifies vulnerabilities through controlled testing |
| Industry Usage | Used in threat simulation, red teaming, and advanced security assessments | Used in vulnerability assessments and security audits |
Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.
What are the key skills and qualifications needed to thrive in adversary emulation?
What are the typical challenges faced by professionals in adversary emulation roles?
What cities are hiring for Adversary Emulation jobs?
Cities with the most Adversary Emulation job openings:
What states have the most Adversary Emulation jobs?
States with the most job openings for Adversary Emulation jobs include:
What job categories do people searching Adversary Emulation jobs look for?
The top searched job categories for Adversary Emulation jobs are:

Job description
The Senior Manager, Purple Team Operationsleads Vanguard's Purple Team programwithin the Offensive Security & Fraud Testing (OSFT)organization. This role is responsible for building and scaling a threat-informed validation program that partners Offensive Security, the CSOC, Detection Engineering, and Fraud Detection teams to continuously improve Vanguard's detection, response, and resilience capabilities.
Unlike offensive security operations that primarily assess security readiness through covert adversary emulation, the Purple Team function focuses on collaborative validation of controls, detections, and response processes. The team's mission is to ensure that identified detection gaps are translated into measurable defensive improvements and that Vanguard can detect, investigate, and respond to relevant adversary behaviors across the enterprise.
Successin this role is measured by the effectiveness of Vanguard's detection and response capabilities: improved detection coverage, reduced detection gaps, faster response times, stronger collaboration across offensive and defensive teams, and measurable improvements in cyber resilience.
Job Description
Key Responsibilities- Purple Team Program Leadership: Define and execute the strategic visionfor Vanguard's Purple Team program, aligning threat-informed defense validation activities to enterprise cyber risk priorities. Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and evolving industry threats.
- Team Management & Development: Lead and develop a geographically distributed team of Purple Team operators focused on adversary emulation, detection validation, and defensive capability improvement. Drive hiring, coaching, mentoring, and career development while fostering a culture of continuous learning, innovation, and collaboration between offensive and defensive security teams.
- Detection Validation & Threat-Informed Testing: Oversee Purple Team operations that validate security controls, detection content, response playbooks, and investigative procedures across the enterprise. Ensure testing is aligned to known adversary TTPs and frameworks such as MITRE ATT&CK and MITRE ATLAS. Drive repeatable validation methodologies that assess prevention, detection, investigation, and response capabilities.
- Offensive Security Partnership & Remediation Closure: Partner closely with Offensive Security teams to translate findings from Red Team operations, penetration tests, and adversarial AI assessments into Purple Team validation activities. Ensure previously identified detection gaps are remediated, tested, and validated before closure. Establish feedback loops that improve both offensive and defensive program effectiveness.
- CSOC & Detection Engineering Collaboration: Serve as the primary liaison between OSFT, CSOC, Threat Detection Engineering, Fraud Detection, and Cyber Threat Intelligence teams. Coordinate collaborative exercises that validate new detections, response workflows, telemetry coverage, and security monitoring capabilities. Drive alignment on adversary emulation priorities and detection engineering roadmaps.
- Reporting & Metrics: Establish measurable metrics to demonstrate security improvement and operational effectiveness. Track and communicate detection coverage, ATT&CK technique validation rates, mean-time-to-detect improvements, detection fidelity, response effectiveness, and remediation progress. Present findings, trends, and strategic recommendations to senior leadership and governance forums.
- Threat Intelligence Integration: Partner with Cyber Threat Intelligence teams to ensure Purple Team exercises emulate relevant financial industry adversaries, fraud threats, ransomware groups, insider threats, and emerging AI-enabled attack techniques. Translate intelligence into actionable validation scenarios that strengthen Vanguard's security posture.
- Strategic Innovation & Program Maturity: Continuously evolve the Purple Team capability by introducing new validation methodologies, automation, adversarial AI testing approaches, cloud-native security validation, attack-path simulation, and continuous control validation capabilities. Drive innovation while ensuring exercises remain aligned with business objectives and risk priorities.
- Purple Team & Detection Expertise: 10+ years of experience in cybersecurity with significant experience in Purple Teaming, Detection Engineering, Threat Hunting, Incident Response, Red Teaming, or Adversary Simulation. Deep understanding of attacker methodologies, detection technologies, security telemetry, and defensive operations.
- Leadership & Program Management: 3+ years leading security teams, Purple Team programs, Detection Engineering functions, Incident Response capabilities, or equivalent technical organizations. Demonstrated ability to develop teams, manage strategic initiatives, and deliver measurable cybersecurity outcomes across multiple stakeholders.
- Threat-Informed Defense Expertise: Strong knowledge of MITRE ATT&CK, MITRE ATLAS, adversary emulation methodologies, detection engineering practices, threat hunting frameworks, and modern SOC operations. Experience designing and executing threat-informed validation programs at enterprise scale.
- Security Operations & Detection Engineering Knowledge: Deep familiarity with SIEM, EDR, NDR, cloud security monitoring, threat intelligence platforms, deception technologies, automation workflows, and modern detection engineering practices. Experience evaluating detection coverage and improving security monitoring effectiveness.
- AI & Automation Familiarity: Experience leveraging AI/ML technologies, automation frameworks, and security analytics to enhance threat detection, adversary simulation, or security operations. Understanding of how generative AI impacts both attacker tradecraft and defensive capabilities.
- Cross-Functional Leadership & Communication: Exceptional communication and stakeholder management skills with the ability to influence technical teams, security leadership, and executive stakeholders. Proven experience driving collaboration across Offensive Security, CSOC, Fraud, Risk, Engineering, and Threat Intelligence teams.
- Education & Certifications: Bachelor's degree in Computer Science, Cybersecurity, or relateddiscipline (or equivalent experience). Relevant certifications (e.g., CISSP, GCFA. GCTI, GMON, GCIA, CRTO, CARTP, OSCP, CREST Certifications) that demonstrate both offensive technical depth and security management knowledge are strongly preferred.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.About Vanguard
At Vanguard, we don't just have a mission-we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
About Vangard
Sourced by ZipRecruiter
Company size
11 - 50 Employees
Headquarters location
Tacoma, WA, US
Year founded
2001