远程工作雷达

对抗性模拟负责人

Adversarial Simulation Lead

AI开发工程职能支持限定地区(需当地身份)
公司Ardent MC
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Ardent正在寻找一位对抗性模拟负责人加入我们的团队
这是一个远程职位,预计需要前往佛罗里达州塔拉哈西市

职位描述:
Ardent正在寻找一位对抗性模拟负责人,负责计划和执行受威胁信息驱动的受控模拟,以测试在现实操作条件下访问控制、监控和检测流程是否协同工作。该角色仅在机构特定的交战规则范围内执行明确授权的活动,并在可能广泛的多机构环境中优先考虑安全执行、冲突解除、证据严谨性和操作相关性。

职责和任务:

  • 将批准的控制目标转化为与选定杀伤链阶段和MITRE ATT&CK技术对齐的安全对手行为模拟和测试用例。
  • 开发涵盖授权系统、时间窗口、账户、技术、工具、禁止事项、通知、冲突解除、停止工作条件、证据处理和升级的机构特定交战规则输入。
  • 执行批准的访问控制压力测试、权限边界尝试、异常生成、端点/网络活动、漏洞验证和相关验证技术。
  • 与检测与监控分析师紧密协作,追踪从活动启动到遥测、警报、初步判断、升级和响应的事件。
  • 在测试前确认前提条件、回滚考虑因素、安全约束、沟通和停止条件,以最小化操作风险。
  • 捕获可重复的证据,包括命令或工具上下文、截图、数据包或事件数据、日志、时间戳、受影响资产、观察结果和分析笔记。
  • 执行根本原因分析并制定技术上可行的加固或检测改进建议,与事实性AUP报告明确分开。
  • 支持已批准修复发现的重新测试,并记录是否展示了预期的控制性能。
  • 参与研讨会和可重用的工作指南,解释模拟设计、证据和防御经验教训。

要求:

  • 信息安全、数字取证、信息技术、计算机科学或相关领域的学士学位。
  • 提供相关专业认证的证明,如CISSP、CISA、PMP、CEH或其他相关认证。
  • 7年对抗性模拟、渗透测试、威胁狩猎、数字取证、事件响应、漏洞管理等相关工作经验
查看英文原文

Ardent is seeking an Adversarial Simulation Lead to join our team.
This is a remote position with expected travel to Tallahassee, FL.
Position Description:
Ardent is seeking a Adversarial Simulation Lead to plan and execute controlled, threat-informed simulations that test whether access controls, monitoring, and detection processes function together under realistic operating conditions. The role performs only explicitly authorized activities within agency-specific, Rules of Engagement and prioritizes safe execution, deconfliction, evidentiary rigor, and operational relevance across a potentially broad multi-agency environment.
Responsibilities and Duties:

  • Translate approved control objectives into safe adversary-behavior simulations and test cases aligned to selected kill-chain stages and MITRE ATT&CK techniques.
  • Develop agency-specific Rules of Engagement inputs covering authorized systems, windows, accounts, techniques, tools, prohibitions, notifications, deconfliction, stop-work conditions, evidence handling, and escalation.
  • Execute approved access-control stress tests, privilege-boundary attempts, anomaly generation, endpoint/network activity, vulnerability validation, and related verification techniques.
  • Coordinate closely with the Detection & Monitoring Analyst to trace events from activity initiation through telemetry, alerting, triage, escalation, and response.
  • Minimize operational risk by confirming preconditions, rollback considerations, safety constraints, communications, and stop conditions before testing.
  • Capture reproducible evidence, including command or tool context, screenshots, packet or event data, logs, timestamps, affected assets, observed outcomes, and analytic notes.
  • Perform root-cause analysis and develop technically feasible hardening or detection-improvement recommendations, clearly separated from factual AUP reporting.
  • Support retesting of approved remediated findings and document whether expected control performance is demonstrated.
  • Contribute to workshops and reusable job aids explaining simulation design, evidence, and defensive lessons.

Requirements:

  • Bachelor’s degree in cybersecurity, digital forensics, information technology, computer science, or related field.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 7 years in adversary simulation, penetration testing, threat hunting, digital forensics, incident response, vulnerability assessment, or security engineering.
  • Demonstrated ability to conduct controlled testing in production-sensitive or regulated environments under formal authorization.
  • Hands-on knowledge of MITRE ATT&CK, identity and access control, endpoint and network telemetry, SIEM/EDR/XDR, vulnerability tools, cloud security, and evidence preservation.
  • Ability to explain operational consequences and mitigation options to technical and executive audiences.

Preferred Qualifications:

  • Experience leading purple-team exercises or adversary campaigns.
  • Experience testing Zero Trust or identity-centric controls.
  • Cloud, web application, API, Active Directory, firewall, and multi-tenant security operations experience.
  • GIAC penetration testing or forensic certifications.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.
Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

GIS项目经理

Ardent MCUnited StatesFull Time昨天
职能支持限定地区(需当地身份)

培训师,初级

Ardent MCUnited StatesFull Time昨天
AI限定地区(需当地身份)

← 返回全部职位