Define and execute purple team sprints that materially and demonstrably improve TP ICAP's ability to prevent and detect modern attacks.
Simulate both established and emerging attacker TTPs and personally build the respective detection rules and response procedures.
Through the delivery of purple team sprints, identify opportunities to reduce TP ICAP's attack surface using preventative controls.
Work in tandem with the SOC to:
Tune existing rules and increase alert fidelity/decrease alert fatigue
Include analysts on the purple team journey, aiding in staff retention
Train analysts in modern attacker TTPs and the 'attacker mindset'
Work with the Security Engineering team as necessary to support the deployment and tuning of security-related tooling, particularly those that pertain to prevention and detection.
Develop processes for attack surface monitoring and constant validation through automation.
Act as an escalation point for the SOC and assist with incident response.
Feed into prioritisation of sprint focus areas.
Experience/Competencies
Practical experience emulating sophisticated cyber-attacks, likely in a Purple or Red Team capacity.
Active contributor to offensive security research and/or tooling, perhaps presenting this research at industry-recognised conferences and forums.
Able to evade defensive controls such as EDR and AV, tailoring open-source tooling and rolling your own where required.
Experience working closely with the SOC to build detection capability.
Strong knowledge of offensive security and modern attacker TTPs.
Familiarity with Mitre ATT&CK.
Development/automation experience.
Familiarity with AWS is preferred.
Role Band & Level: Manager / 6
#LI-Hybrid #LI-MID
Not The Perfect Fit?
Company Statement
Location
UK - 135 Bishopsgate - London
Benefits
Vision insurance
Additional Information
The TP ICAP Group is a world leading provider of market infrastructure.
Our purpose is to provide clients with access to global financial and commodities markets, improving price discovery, liquidity, and distribution of data, through responsible and innovative solutions.
Through our people and technology, we connect clients to superior liquidity and data solutions.
The Group is home to a stable of premium brands. Collectively, TP ICAP is the largest interdealer broker in the world by revenue, the number one Energy & Commodities broker in the world, the world's leading provider of OTC data, and an award winning all-to-all trading platform.
The Group operates from more than 60 offices in 27 countries. We are 5,300 people strong. We work as one to achieve our vision of being the world's most trusted, innovative, liquidity and data solutions specialist.
Role Overview:
TP ICAP are seeking an experienced Red/Purple team operator to assist the Adversary Emulation Manager with elevating TP ICAP's prevention and detection capability.