Senior Cybersecurity Engineer – Adversary Operations, Innovation & Purple Team Operations
HybridWarren, Michigan, United States
Job Summary
Lead tactical purple team operations by executing adversary emulations that test current capabilities, processes, and documentation while driving new cyber detection. Design and run strategic, multi-step exercises validating detections and team response across the enterprise, utilizing MSV-based testing and custom tooling for cloud and platform validation. Develop innovative adversary tooling including custom C2, payload development, and automation to support annual red exercises and continuous visibility testing. Partner with Detection Engineering and Incident Response to translate findings into improved integrations and threat hunting outcomes. Produce clear technical documentation and recommendations that feed operational improvements. This role supports innovation in cloud, SaaS, endpoint, and AI-related tactics within the Adversary Operations team.
Required Qualifications
- Significant hands-on experience in cybersecurity operations, adversary emulation, purple teaming, red teaming, threat hunting, or detection engineering
- Strong understanding of attacker tactics, techniques, and procedures and the ability to translate them into repeatable testing scenarios
- Experience with endpoint, cloud, network, and logging technologies used to validate detections and visibility gaps across enterprise environments
- Experience building or using offensive and validation tooling such as payloads, C2 frameworks, automation, scripting, and infrastructure for safe adversary testing
- Ability to collaborate across verticals and help coordinate actions that improve Cyber Defense outcomes at scale
- Strong written and verbal communication skills with the ability to document findings, explain operational risk, and influence detection and response improvements
- Must be able to report to a specific location at least 3 times a week
- Must not require GM immigration sponsorship
Desired Qualifications
- Experience with MSV or similar security validation tooling and the ability to create custom repeat actions for visibility validation
- Experience in cloud and SaaS adversary tactics, including web and API attack paths
- Experience supporting automotive, manufacturing, or other complex operational environments where security validation spans multiple technology domains
- Familiarity with ATT&CK-aligned reporting, detection engineering feedback loops, and enterprise purple team programs
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.