Talent.com
NorthMark Strategies
Director of Offensive SecurityNorthMark Strategies • Dallas, TX, United States
Director of Offensive Security

Director of Offensive Security

NorthMark Strategies • Dallas, TX, United States
1 day ago
Job type
  • Full-time
Job description

Director Of Offensive Security

NorthMark Compute & Cloud (NMC) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients' research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

The Director of Offensive Security reports directly to the CISO and owns continuous adversarial validation of the NMC production environment. This is not a scheduled pentest function or a compliance-checkbox red team. You will build and run a standing offensive capability that operates against production with authorization, emulates named threat actors relevant to our customer base and infrastructure class, and produces independent, evidence-backed assessments of whether our controls work under realistic attack conditions.

This function operates as an independent line of assurance within the Security organization, with a direct reporting relationship to the CISO. To preserve objectivity, assessment findings are delivered to the CISO without editorial review by the teams whose controls or systems are under evaluation. Security Engineering, Platform Engineering, and Security Architecture receive findings as remediation owners.

Responsibilities:

  • Build and run a continuous red team program against the production NMC environment: HPC clusters, multi-tenant Kubernetes, bare-metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface itself (SIEM, EDR, IAM, PAM)
  • Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers (e.g., TTP sets associated with initial access brokers targeting financial services customers), APT groups with demonstrated interest in research computing and scientific workloads, and insider threat scenarios covering privileged operator abuse
  • Independently validate detection and response efficacy: every red team operation produces a detection coverage report measured against the SOC and IR functions, including time-to-detect, time-to-contain, and detection gap inventory by ATT&CK technique ID
  • Own the purple team feedback loop: every undetected TTP becomes a tracked detection engineering deliverable with owner and SLA, every detected-but-unresponded TTP becomes a tracked IR playbook deliverable
  • Run continuous attack surface validation against production, not just pre-production, with a documented rules-of-engagement framework, blast radius controls, and CISO-level authorization gates for destructive or high-risk techniques
  • Lead threat-led penetration testing of the HPC-specific attack surface: Slurm and workload manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross-tenant lateral movement in shared compute, and scientific software supply chain compromise
  • Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross-account and cross-tenant escape attempts, container breakout chains, service mesh bypass, admission controller evasion, and secrets management integrity
  • Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial design reviews that the CISO signs off on before build
  • Manage the external pentest and red team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation tracking system
  • Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit development capability, with clear controls on tool custody, source code management, and destruction protocols
  • Define and publish offensive security KPIs to CISO and board level: coverage against MITRE ATT&CK technique inventory, mean time to compromise from assumed-breach scenarios, control validation pass rate by control family, remediation velocity on P1 and P2 findings, and repeat finding rate
  • Issue formal assessment reports using CWE classification, CVSS v3.1 base and environmental scoring, and explicit exploitation evidence; findings are attestations, not suggestions
  • Champion an adversarial engineering culture across Platform and Security Engineering through documented attack patterns, regular internal briefings, and integration of offensive findings into developer tooling and CI/CD gates

Requirements:

  • 15+ years in offensive security with demonstrated hands-on depth across at least three of: network penetration testing, red team operations, cloud penetration testing, application exploitation, hardware and firmware attack research, or advanced adversary emulation
  • 5+ years leading offensive security teams, including direct accountability for hiring specialized offensive talent, managing operational security of red team infrastructure, and operating under formal rules of engagement against production systems
  • Demonstrated red team leadership against mature target environments: environments with functioning SOC, EDR, and IR capability, not greenfield pentest targets
  • Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple team execution models
  • Hands-on capability with production-grade offensive tooling: C2 frameworks (Cobalt Strike, Mythic, Sliver, or equivalent), exploitation frameworks, custom tool development, and operational security for red team infrastructure
  • Strong command of cloud and container offensive tradecraft: Kubernetes attack paths, cloud IAM privilege escalation chains, service mesh and sidecar abuse, and multi-tenant isolation testing
  • Fluency with CWE, CVSS v3.1 and v4.0, OWASP Top 10, SANS CWE Top 25, and the CIS Controls v8 Penetration Testing domain (Control 18)
  • Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking, not report-and-walk-away engagements
  • Demonstrated ability to execute offensive work against production with appropriate authorization, blast radius control, and executive communication discipline
  • Exceptional written communication: findings must stand up to scrutiny from engineering leadership who will push back, and from auditors and customers who will consume the output

Preferred:

  • OSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications; CISSP alone is not sufficient evidence of hands-on offensive capability
  • Prior experience building an offensive security function from scratch, not inheriting an existing one
  • HPC, bare-metal, or hyperscale data center offensive assessment experience
  • Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research
  • Background in threat intelligence consumption for adversary emulation planning (CTI-led red teaming)
  • Experience with sovereign cloud, export-controlled, or financial services customer environments

It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company's needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Benefits & Perks:

  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub
  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability
  • 401(k): Company will match 100% of your contributions up to 6%
  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays

EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS

Create a job alert for this search

Director of Offensive Security • Dallas, TX, United States

Similar jobs

Security Officer - Dallas (73678)

Inter-Con Security SystemsDallas, TX, United States
Full-time +1

Founded in 1973, Inter-Con Security Systems, Inc.US-owned security company, providing integrated security solutions to government and commercial customers on four continents.Inter-Con remains under... Show more

 • Promoted

Global Financial Crimes Alert Monitoring and Screening Director (AVP)

Morgan StanleyDallas, TX, United States
Full-time

Global Financial Crimes (GFC): US AML Alert Monitoring & Screening Professional.In the Legal & Compliance division, we assist the Firm in achieving its business objectives by facilitating and overs... Show more

 • Promoted

Security Lead - Industrial Control Systems (ICS)

ClifyXDallas, TX, United States
Full-time

Security Industrial Control Systems (ICS) Manager Southwest.Locations: Oklahoma City, AZ - Phoenix, CO - Denver, TX - Austin, TX - Dallas, TX Houston - Energy domain. Show more

 • Promoted

Director of Training

First Coast SecurityDallas, TX, United States
Full-time

OverviewJob Skills / RequirementsFirst Coast Security Solutions provides security services nationwide.We are seeking Director of Training.This role is responsible for the strategic development, imp... Show more

 • Promoted

Director of Quality & Risk Management

DataOneDallas, TX, United States
Full-time

DataOne employs the most talented, tenured and certified professionals in the industry.We have always maintained a customer- first business model, which has helped transform our organization into o... Show more

 • Promoted

Director of Quantum Security Initiatives

KPMGDallas, TX, United States
Full-time

The KPMG Advisory practice is committed to transformation and innovation, providing exceptional opportunities for professionals eager to advance their careers.We prioritize personal and professiona... Show more

 • Promoted

Director of Security

Highland Park UMCDallas, TX, United States
Full-time

This is a full time position that provides a salary commensurate with experience and outstanding benefits in a truth and grace filled work environment.The Director of Security is responsible for th... Show more

 • Promoted

2nd Shift Security Officer

FanaticsSunnyvale, TX, United States
Full-time

The Security Officer is responsible for ensuring the safety and security of personnel, assets, and facilities.This includes enforcing security policies, monitoring access control, and responding to... Show more

 • Promoted

Security & Risk Consulting Client Engagement Director - 1898 & Co.

Burns & McDonnellDallas, TX, United States
Full-time

Security & Risk Consulting Client Engagement Director.Burns & McDonnell, as we lead the charge in securing critical infrastructure and shaping the future of industrial cybersecurity.Our team partne... Show more

 • Promoted

Unarmed Security Officer FULLTIME - GARLAND/EAST DALLAS SOUTH DALLAS

Clarion SecurityDallas, TX, United States
Full-time

Unarmed Security Officer Fulltime - Garland/East Dallas/South DallasClarion Security LLC takes pride in building its culture of excellence one professional team member at a time.Not only do we hire... Show more

 • Promoted

Security Officer: P&G Mixing Center & Warehouse South Dallas Area (Ferris/Wilmer)

Denali Universal Services RecruitingFerris, TX, United States
Full-time

Security Officer: P&G Mixing Center & Warehouse South Dallas Area (Ferris/Wilmer).Under limited supervision, the Security Officer provides security and protection of work site(s), personnel and ass... Show more

 • Promoted

SECURITY OFFICER

SignalFrisco, TX, United States
Full-time

Signal - - Responsibilities: Conduct static security services for courtyards, offices, pools, and other high value areas to secure access points and protect property and residents; Write detailed ... Show more

 • Promoted

Security Operations Manager (Dallas Branch)

GuardTexas, Inc.Dallas, TX, United States
Full-time

Guardtexas Security Operations Manager.Join the guard company that specializes in Texas! Our name says it all - GuardTexas.We have been committed to serving the great state of Texas since 1976, pro... Show more

 • Promoted

VP, Global Head of Product Security and Risk

CircleDallas, TX, United States
Full-time

VP, Global Head Of Product Security & Risk.Circle is building the next generation of global financial infrastructure through programmable money, blockchain-based payments, and cloud-native APIs.As ... Show more

 • Promoted

Manager, Security Operation Center (Cyber Defense)

7-elevenDallas, TX, United States
Full-time

Manager, Security Operation Center (Cyber Defense).You will be responsible for all aspects of Cyber Defense within 7-Eleven, reporting to the Senior Manager of Information Security Operations.You w... Show more

 • Promoted

Senior Director Security

MavenirRichardson, TX, United States
Full-time

Mavenir is building the future of networks and pioneering advanced technology, focusing on the vision of a single, software-based automated network that runs on any cloud.As the industry's only end... Show more

 • Promoted

Global Security - Divisional Security Operations Lead

ChasePlano, TX, United States
Full-time

Divisional Security Operations LeadThe Global Security (GS) team protects the firm's people and assets, ensuring the safety of business operations through the implementation of technology, best-in-... Show more

 • Promoted

Security Operations Manager

MedixDallas, TX, United States
Part-time

Position SummaryThe Security Operations Manager is responsible for coordinating security staff operations, managing scheduling and payroll systems, overseeing onboarding and personnel documentation... Show more

 • Promoted

Asst. Security Manager

Rosewood HotelsDallas, TX, United States
Full-time

Security ManagerTo direct the daily operations of the security department.Act as the primary trainer of new security officers.Conduct refresher training on security operations and procedures for se... Show more

 • Promoted

Global Operations Security Center Manager

SecuritasPlano, TX, United States
Full-time

Job DescriptionGlobal Operations Security Center Manager - Full Time - Plano, TXReports To: Regional Director of Security OperationsSalary: $75,000-$95,000/YRIn-Office: Mon - Fri: 8AM - 5PMSummary:... Show more