Senior Manager Purple Team
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Senior Manager, Purple Team Operations
The Senior Manager, Purple Team Operations leads Vanguard's Purple Team program within the Offensive Security & Fraud Testing (OSFT) organization. This role is responsible for building and scaling a threat-informed validation program that partners Offensive Security, the CSOC, Detection Engineering, and Fraud Detection teams to continuously improve Vanguard's detection, response, and resilience capabilities.
Unlike offensive security operations that primarily assess security readiness through covert adversary emulation, the Purple Team function focuses on collaborative validation of controls, detections, and response processes. The team's mission is to ensure that identified detection gaps are translated into measurable defensive improvements and that Vanguard can detect, investigate, and respond to relevant adversary behaviors across the enterprise.
Success in this role is measured by the effectiveness of Vanguard's detection and response capabilities: improved detection coverage, reduced detection gaps, faster response times, stronger collaboration across offensive and defensive teams, and measurable improvements in cyber resilience.
Key Responsibilities- Purple Team Program Leadership:
Define and execute the strategic vision for Vanguard's Purple Team program, aligning threat-informed defense validation activities to enterprise cyber risk priorities. Develop annual roadmaps that prioritize adversary emulation, detection validation, control effectiveness testing, and threat-informed exercises based on intelligence, prior offensive operations, and evolving industry threats. - Team Management & Development:
Lead and develop a geographically distributed team of Purple Team operators focused on adversary emulation, detection validation, and defensive capability improvement. Drive hiring, coaching, mentoring, and career development while fostering a culture of continuous learning, innovation, and collaboration between offensive and defensive security teams. - Detection Validation & Threat-Informed Testing:
Oversee Purple Team operations that validate security controls, detection content, response playbooks, and investigative procedures across the enterprise. Ensure testing is aligned to known adversary TTPs and frameworks such as MITRE ATT&CK and MITRE ATLAS. Drive repeatable validation methodologies that assess prevention, detection, investigation, and response capabilities. - Offensive Security Partnership & Remediation Closure:
Partner closely with Offensive Security teams to translate findings from Red Team operations, penetration tests, and adversarial AI assessments into Purple Team validation activities. Ensure previously identified detection gaps are remediated, tested, and validated before closure. Establish feedback loops that improve both offensive and defensive program effectiveness. - CSOC & Detection Engineering
Collaboration:
Serve as the primary liaison between OSFT, CSOC, Threat Detection Engineering, Fraud Detection, and Cyber Threat Intelligence teams. Coordinate collaborative exercises that validate new detections, response workflows, telemetry coverage, and security monitoring capabilities. Drive alignment on adversary emulation priorities and detection engineering roadmaps. - Reporting & Metrics:
Establish measurable metrics to demonstrate security improvement and operational effectiveness. Track and communicate detection coverage, ATT&CK technique validation rates, mean-time-to-detect improvements, detection fidelity, response effectiveness, and remediation progress. Present findings, trends, and strategic recommendations to senior leadership and governance forums. - Threat Intelligence Integration:
Partner with Cyber Threat Intelligence teams to ensure Purple Team exercises emulate relevant financial industry adversaries, fraud threats, ransomware groups, insider threats, and emerging AI-enabled attack techniques. Translate intelligence into actionable validation scenarios that strengthen Vanguard's security posture. - Strategic Innovation & Program Maturity:
Continuously evolve the Purple Team capability by introducing new validation methodologies, automation, adversarial AI testing approaches, cloud-native security validation, attack-path simulation, and continuous control validation capabilities. Drive innovation while ensuring exercises remain aligned with business objectives and risk priorities.
- Purple Team & Detection Expertise: 10+ years of experience in cybersecurity with significant experience in Purple Teaming, Detection Engineering, Threat Hunting, Incident Response, Red Teaming, or Adversary Simulation. Deep understanding of attacker methodologies, detection technologies, security telemetry, and defensive operations.
- Leadership & Program Management: 3+ years leading security teams, Purple Team programs, Detection Engineering functions, Incident Response capabilities, or equivalent technical organizations. Demonstrated ability to develop…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).