1

Purple Team Jobs (NOW HIRING)

Build and maintain detailed incident response runbooks, integrating lessons learned from purple team exercises * Conduct root cause analysis and lead retrospectives that drive measurable improvements ...

Build and maintain detailed incident response runbooks, integrating lessons learned from purple team exercises * Conduct root cause analysis and lead retrospectives that drive measurable improvements ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Red Team Manager

Johnston, RI

$112K - $152K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Red Team Manager

Westwood, MA

$124K - $167K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Red Team Manager

Johnston, RI · On-site

$112K - $152K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Red Team Manager

Westwood, MA · On-site

$124K - $167K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Red Team Manager

Irving, TX

$106K - $144K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Red Team Manager

Boston, MA

$120K - $163K/yr

Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations. Assess risks introduced by AI ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Showing results 21-40

Purple Team information

See salary details

$8

$19

$35

How much do purple team jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for purple team in the United States is $19.04, according to ZipRecruiter salary data. Most workers in this role earn between $13.22 and $21.15 per hour, depending on experience, location, and employer.

What is a purple team?

A Purple Team job involves bridging the gap between Red Team (offensive security) and Blue Team (defensive security) operations. Professionals in this role collaborate with both teams to enhance an organization's overall security posture by simulating attacks, identifying vulnerabilities, and improving detection and response capabilities. Their goal is to ensure that defensive measures are continuously tested and refined based on real-world attack scenarios. This role requires strong knowledge of cybersecurity threats, penetration testing, and incident response.

How does a purple team contribute to improving an organization's cybersecurity posture?

A Purple Team plays a unique and strategic role by facilitating collaboration between offensive security experts (Red Team) and defensive teams (Blue Team), helping organizations identify and address vulnerabilities more efficiently. They conduct controlled attack simulations, analyze real-world threat scenarios, and work directly with defenders to strengthen detection and response processes. The team’s efforts often lead to developing stronger security controls and more resilient incident response strategies. For job seekers, this means engaging in diverse projects, learning from both adversarial and defense perspectives, and playing a direct role in enhancing overall cyber defense capabilities.

What are the key skills and qualifications needed to thrive in the purple team position, and why are they important?

To thrive as a Purple Team member, you need a deep understanding of both offensive (red team) and defensive (blue team) cybersecurity techniques, with expertise in penetration testing, threat detection, and incident response. Familiarity with tools such as SIEM platforms, vulnerability scanners, attack simulation frameworks, and certifications like CISSP, CEH, or OSCP are highly valued. Strong problem-solving abilities, effective communication, and the capability to work collaboratively with both security and IT teams are crucial soft skills. These combined skills enable Purple Team professionals to bridge gaps between offensive and defensive security, improving organizational resilience against cyber threats.

More about Purple Team jobs

What cities are hiring for Purple Team jobs?

Cities with the most Purple Team job openings:

What are the most commonly searched types of Purple Team jobs?

The most popular types of Purple Team jobs are:

What states have the most Purple Team jobs?

States with the most job openings for Purple Team jobs include:

What job categories do people searching Purple Team jobs look for?

The top searched job categories for Purple Team jobs are:

Infographic showing various Purple Team job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 20% Part Time, and 3% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $39,603 per year, or $19 per hour.

Cybersecurity Lead

A10 Networks, Inc.

San Jose, CA • On-site

Full-time

Re-posted 4 days ago


Job description

Cybersecurity Lead
The Cybersecurity Lead serves as a hands-on technical leader responsible for uniting offensive and defensive security operations to continually improve the company's ability to detect, respond to, and recover from cyber threats.
This role will lead the Blue Team in managing and enhancing security monitoring tools, detection pipelines, and incident response processes, while also coordinating Red Team simulations that measure and improve the company's defensive posture.
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the mission to emulate adversaries, strengthen controls, and transform findings into actionable defense improvements.
Key Responsibilities:
Blue Team Operations and Tool Management
  • Lead and oversee the management, configuration, and tuning of security detection and response platforms, including:
    • SIEM (e.g., Splunk, PANW, or Azure Sentinel)
    • EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft Defender)
    • SOAR automation platforms
    • Network IDS/IPS, NDR, and threat intelligence platforms (TIPs)

  • Ensure all detection tools are integrated for end-to-end visibility across endpoints, cloud environments, and production systems
  • Define standards for log collection, parsing, and correlation to enhance alert accuracy and reduce false positives
  • Drive continuous tuning of detection rules, signatures, and use cases to align with MITRE ATT&CK and emerging threats
  • Collaborate with IT and Engineering teams to ensure security telemetry is fully integrated into cloud and CI/CD environments
  • Oversee threat hunting, alert triage, and incident response playbook execution across the security stack
  • Partner with DevOps and infrastructure teams to embed security monitoring hooks into hybrid environments and new deployments

Red Team and Offensive Security
  • Design and conduct controlled adversary emulation exercises to test detection and response capabilities
  • Execute attack chains including phishing, privilege escalation, persistence, and lateral movement using real-world TTPs
  • Develop and maintain custom adversary scripts and payloads to simulate targeted threats
  • Provide detailed post-exercise reports with actionable defensive improvement recommendations
  • Collaborate with Blue Team engineers to operationalize detections based on Red Team findings

Incident Response and Continuous Improvement
  • Lead or co-lead major incident response efforts, coordinating containment, investigation, and recovery
  • Build and maintain detailed incident response runbooks, integrating lessons learned from purple team exercises
  • Conduct root cause analysis and lead retrospectives that drive measurable improvements in detection and resilience
  • Integrate threat intelligence and forensic insights into detection content and defensive playbooks.
  • Plan and execute adversarial simulations that validate threat detection, alert fidelity, and incident response readiness
  • Develop the roadmap for continuous improvement of detection coverage, response automation, and control validation
  • Serve as a technical escalation point for complex investigations, guiding both Red and Blue Team staff
  • Translate technical results into executive-level insights that demonstrate risk reduction and readiness improvement

Qualifications:
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with proven leadership across Blue, Red, or Purple Team operations
  • Demonstrated ownership of enterprise security detection tools, including SIEM, EDR/XDR, SOAR, and threat intel platforms
  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and threat emulation frameworks.
  • Deep technical expertise in one or more of the following areas:
    • Endpoint and network forensics
    • Cloud security monitoring (AWS, Azure, GCP)
    • Scripting and automation (Python, PowerShell, Bash)
    • Security engineering in hybrid or production environments
  • Proven ability to lead incident response and purple team exercises from start to finish
  • Certifications such as OSCP, GCFA, GCIH, GPEN, GXPN, or GCTI highly desirable
  • Strong communication and leadership skills, with ability to engage both executive stakeholders and technical teams

Preferred Experience:
  • Experience in enterprise or production-scale environments, ideally within SaaS, networking, or hybrid cloud infrastructures
  • Familiarity with DevSecOps practices, CI/CD pipeline security, and cloud-native monitoring
  • Prior experience mentoring Blue Team analysts and managing tool life cycles and vendor relationships
  • Exposure to purple team automation frameworks (e.g., AttackIQ, Caldera, Scythe)

AI Use Guidelines for Interviews: Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process.
Why Join Us:
This role sits at the intersection of offensive and defensive cybersecurity where every exercise directly strengthens the company's real-world resilience. As Cybersecurity Lead, you'll shape how attacks are simulated, how detections evolve, and how incidents are contained ensuring the organization stays one step ahead of its adversaries.
A10 Networks is an equal opportunity employer and a VEVRAA federal subcontractor. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. A10 also complies with all applicable state and local laws governing nondiscrimination in employment.
#LI-AN1 - Hybrid
Targeted compensation guideline: $140,000 - $185,000. Compensation will vary based on number of factors, including market demand for specific skills, role type, job level, and individual qualifications. Final salary offers are determined by considerations including, but not limited to, subject matter expertise, demonstrated skill level, relevant experience, geographic location, education, certifications, and training.