Information Security Lead - Offensive and Threat Intel

ANB Bank

$72K — $107K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of relevant experience in offensive security and operations
  • Preferred college degree or equivalent education/experience
  • Expertise in Windows/Active Directory and cloud environments like Azure
  • Hands-on experience with C2 frameworks and credential attack methods
  • Strong understanding of detection engineering concepts and telemetry
  • Exceptional communication skills for translating findings to business risk
  • Relevant advanced certifications (e.g., OSCP, GXPN, CISSP) in good standing

Responsibilities

  • Own and define the offensive security strategy and programs
  • Plan and execute adversary emulation and red team operations
  • Design and maintain operator environments and tooling
  • Produce detailed post-operation reports and track remediation
  • Enforce compliance with governance and safety protocols
  • Lead continuous improvement initiatives in offensive operations
  • Integrate threat intelligence into testing and validation activities

Benefits

  • Minimum 4 Weeks of Paid Time Off (PTO)
  • 11 Paid Holidays
  • Medical, Dental, and Vision Insurance
  • 401(k) plan with discretionary company match
  • Employee Referral Incentives
  • Tuition Reimbursement Program
  • Employee Assistance Program (EAP)
Full Job Description
Hiring Pay Range: $35.00 - $51.50 per hour
    • This position may be eligible to receive an additional $1.00 per hour if approved for the Spanish Communication Assistant Program.
    • The hiring pay range for this position is commensurate with the level of relevant experience and education.


Health & Wellness Benefits (Subject to Eligibility Requirements)
  • Minimum 4 Weeks of Paid Time Off (PTO)
  • 11 Paid Holidays
  • Medical, Dental, and Vision Insurance
  • Health Savings (HSA), Flexible Spending (FSA), and dependent care spending accounts
  • Company provided Life, AD&D, and Disability Insurance with supplementation options
  • 401(k) plan with discretionary company match and profit sharing
  • Discretionary annual bonus and employee referral incentives
  • Employee Assistance Program (EAP)
  • Tuition Reimbursement Program
  • Spanish Communication Assistant Program Incentive


Summary
  • The Offensive Operations Team Lead owns the strategy, execution, and continuous improvement of the organization's offensive security program. This role directs red team operations, adversary emulation, targeted penetration testing, and purple team exercises to measurably improve detection, response, and hardening across on-premises and cloud environments. The role partners closely with all other aspects of Information Security and relevant parties within the organization to validate control effectiveness and reduce risk to critical business services. Responsible for implementation and administration of corporate Information Security Systems as listed below


Essential Duties and Responsibilities
  • Offensive Operations Program Ownership
    • Define and maintain the offensive security strategy, roadmap, playbooks, SLAs, and rules of engagement (ROE).
    • Own intake and scoping for engagements; prioritize based on business impact, threat intel, and control validation needs.
    • Ensure all activities align with legal, regulatory, and corporate policy requirements, including operational safety and privacy controls.
  • Red Team & Adversary Emulation
    • Plan and execute realistic, threat-informed operations mapping to MITRE ATT&CK, targeting identity, endpoints, network, applications, and cloud services.
    • Develop and maintain adversary emulation plans, chained attack paths, and objective-based scenarios for critical business processes.
    • Oversee exploitation research and proof-of-concept development (privilege escalation, lateral movement, persistence) with strict safeguards and de-confliction.
    • Lead purple team exercises to drive measurable detections and response playbook improvements with Detection Engineering and SOC teams.
  • Tooling, Infrastructure & Automation
    • Design, secure, and maintain operator environments (segmented labs, cloud resources, and approved tooling).
    • Evaluate and integrate offensive tools (e.g., BloodHound, Burp Suite, custom scripts) and maintain an internal, access-controlled repository.
    • Develop automation to streamline reconnaissance, validation, artifact collection, reporting, and metrics.
  • Collaboration, Communication & Reporting
    • Produce clear post-operation reports with technical detail, business impact, exploited control gaps, and prioritized remediation.
    • Partner with relevant parties to translate findings into backlog items; track remediation and validate fixes.
    • Provide executive-level updates and program metrics demonstrating risk reduction and control effectiveness over time.
    • Support Incident Response by advising on attacker TTPs, containment strategies, and root cause analysis when appropriate.
  • Governance, Safety & Compliance
    • Enforce ROE, change control, maintenance windows, de-confliction, and kill-switch procedures to protect production systems.
    • Document methodologies, tool usage, and operational decisions; maintain evidence handling and data retention practices.
    • Periodically review program compliance with legal, regulatory, and internal policy obligations (e.g., GLBA/PCI/FFIEC as applicable).
  • Continuous Improvement & Innovation
    • Track emerging threat actor behaviors, new exploits, and research; proactively test controls against evolving TTPs.
    • Upskill the team across identity, cloud, application, and social engineering domains; lead internal workshops and demos.
    • Establish and maintain a safe disclosure process for internally discovered vulnerabilities.
  • Threat Intelligence Integration
    • Consume and analyze internal and external threat intelligence to identify relevant adversary behaviors, emerging vulnerabilities, and likely attack paths targeting the financial sector.
    • Translate threat intelligence into actionable offensive testing objectives, adversary emulation plans, and targeted validation activities.
    • Maintain alignment between offensive operations and intelligence-driven priority threats, including nation-state TTPs, ransomware groups, and financially motivated actors.
    • Ensure operational findings feed back into Information Security threat models and detection logic.
    • Track exploit releases, zero-day disclosures, cloud-identity abuse techniques, and industry reports to proactively schedule offensive testing before weaponization impacts the organization.
    • Produce periodic intelligence-driven risk reports for leadership, highlighting threat trends, likely impacts, and recommended offensive validation activities.
  • Ensuring management is made aware of critical events and situations within the department.
  • Maintains a current knowledge and understanding of requirements, policies, configurations, and procedures related to the Information Security team.
  • Maintains a current knowledge and consistent compliance with Bank Secrecy Act (BSA) requirements, as well as knowledge and consistent compliance with other banking regulations and Bank policies and procedures related to the position.
  • Delivers quality of service as defined by department standards.
  • Maintains confidentiality as defined by department standards.
  • Supports the company's Mission, Vision, and Values.
  • Other duties may be assigned.


Education and/or Experience
  • Seven years of related experience and/or training.
  • Preferred college degree; or equivalent combination of education and experience.
  • Demonstrated expertise in Windows/Active Directory, identity attack paths (Kerberos/NTLM/LDAP/SSO), and cloud (Azure/Microsoft 365 a plus).
  • Hands-on proficiency with C2 frameworks, EDR/XDR evasion techniques, password/credential attack methods, and lateral movement.
  • Strong understanding of detection engineering concepts, logging/telemetry, and purple team collaboration.
  • Exceptional communication skills with the ability to translate complex findings into business-aligned risk narratives.
  • Performs several, if not all, of the above duties with minimal direction and supervision.
  • Several industry standard Information Security advanced certifications (OSCP, GXPN, CISSP, etc) in good standing and appropriate training and experience required.


Work Schedule: Monday - Friday, 8:00am - 5:00pm

Anticipated Date of Application Window Closure: 09/26/2026 (or until filled)

Similar Jobs

More Jobs at ANB Bank

More Information Technology Jobs

Find similar Information Security Lead - Offensive and Threat Intel jobs: