Director - Offensive Security & Assurance
Listed on 2026-09-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Director, Offensive Security & Assurance
Function: Proactive Threat Operations, Cybersecurity
Role OverviewThe Director, Offensive Security & Assurance will lead Aon's global offensive security and security assurance capabilities within Proactive Threat Operations (PTO). This role is responsible for proactively identifying exploitable security weaknesses, validating defensive controls against real-world adversary techniques, and driving findings through to measurable improvements in Aon's security posture.
This leader will evolve traditional penetration testing and pointintime assessments toward a more continuous, threat informed model incorporating adversary emulation, purple teaming, attackpath analysis, control validation, and targeted security assurance. A core objective of the role is to answer, on an ongoing basis:
Can an attacker successfully exploit this path today, and if so, what are we doing to eliminate it?
The Director will partner closely with Threat Intelligence, Threat Hunting, Vulnerability & Exposure Management, Applied Security Research, AC3/SOC, Security Engineering, Identity & Access Management, Cloud, application security, and broader technology teams. Success will be measured by validated risks identified, attack paths eliminated, controls improved, detections strengthened, and remediation verified - not simply the number of assessments completed or findings produced.
Aon is in the business of better decisionsAt Aon, we shape decisions for the better to protect and enrich the lives of people around the world.
As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed.
What the day will look like- Lead the global Offensive Security & Assurance capability within Proactive Threat Operations.
- Define the offensive security strategy, operating model, priorities, standards, and technical roadmap.
- Evolve traditional penetration testing toward continuous adversary validation and recurring purpleteam operations.
- Develop and maintain threat informed adversary emulation scenarios based on relevant threat intelligence, incidents, emerging techniques, and Aonspecific exposures.
- Plan, conduct, and oversee testing across endpoint, identity, Active Directory, Entra , cloud, SaaS, network, applications, APIs, browser, and broader enterprise attack paths.
- Build and mature a purpleteam capability that connects offensive testing directly with AC3/SOC detection and response.
- Partner with Threat Intelligence to translate adversary activity into realistic offensive testing scenarios.
- Partner with Threat Hunting to identify hypotheses and attack paths that warrant proactive validation.
- Partner with Vulnerability & Exposure Management to determine whether vulnerabilities and exposures are actually exploitable in Aon's environment.
- Validate whether remediation actions and compensating controls meaningfully eliminate identified attack paths.
- Require retesting and technical evidence before material offensivesecurity findings are considered closed.
- Identify opportunities to eliminate attack paths through architecture, configuration, identity, endpoint, cloud, network, or application control changes.
- Establish continuous controlvalidation exercises around Aon's highestrisk attack scenarios.
- Develop repeatable adversaryemulation playbooks mapped to MITRE ATT&CK and observed threat behavior.
- Improve detection engineering by providing AC3/SOC with telemetry, behaviors, techniques, and test evidence derived from offensive exercises.
- Collaborate with Applied Security Research to develop offensive tooling, automation, testing frameworks, and novel securityassessment techniques.
- Maintain appropriate testing governance, authorization processes, safety controls, and rules of engagement for offensive activity.
- Manage internal testing capabilities and external penetration testing/redteam partners where required, ensuring third party assessments supplement internal capabilities rather than serving as the primary operating model.
- Provide senior leadership with clear, concise reporting on exploitable risk, defensive effectiveness, remediation progress, and systemic control weaknesses.
- Recruit, develop, and mentor offensive security practitioners and build deep technical capability within the team.
This is more than a traditional offensive security leadership role. You'll lead the evolution of Aon's global offensive security program, moving beyond…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).