Manager, Security Posture Validation
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Responsibilities
About the Team
The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise.
VnV operates across a continuous security lifecycle:
Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions.
About the Role
We are seeking a Manager of Security Posture Validation to build the technology and processes that prove — continuously and at scale — that USDS security controls actually work. This is a builder-leader role: you will own the strategy and delivery of an in-house continuous control-validation capability, turning adversary tradecraft into automated, repeatable tests and translating the results into an authoritative, leadership-facing view of our security posture.
You will lead a specialized team spanning red team, purple team, and control-validation engineering, and drive the success of an internal platform (with an executive-facing dashboard layer) that serves as the single source of truth for control health across cloud infrastructure, web resources, and mobile applications. The mission: replace point-in-time, tool-by-tool testing with a continuously running validation engine that measures control coverage and efficacy over time, quantifies SLAs and remediation velocity, and tells us — with evidence — how good we are and how good we want to be.
You will bridge deep technical exploitation (red teaming) and systematic control validation, ensuring USDS maintains a world-class, measurable defense-in-depth posture.
- Team Leadership & Development:
Lead, mentor, and grow a specialized team of offensive security and privacy engineers. Foster a culture of continuous research, innovation, and ethical hacking. - Build the Validation Platform:
Own the vision, roadmap, and delivery of an in-house continuous control-validation capability (an attack-and-breach-simulation engine plus an authoritative posture dashboard). Replace commercial point-solutions with proprietary tooling that exercises controls with real adversary techniques and produces status, coverage, and efficacy signal over time. - Operationalize Red & Purple Team:
Run adversary-emulation and purple-team exercises as a primary input to the platform — converting validated attack paths and TTPs into automated, repeatable validation content, and partnering with detection and IR teams to prove and close coverage gaps across OCI, AWS, and Azure. - Stakeholder Management:
Act as the primary interface for Executive leadership, Legal, Risk & Compliance, and Engineering. Translate complex technical vulnerabilities into actionable business risks. - Methodology & Governance:
Define and maintain Standard Operating Procedures (SOPs) and Rules of Engagement (ROE) for testing modern tech stacks (Kubernetes, Serverless, Mobile). - Build Automation & Continuous Controls Monitoring:
Design automated, CI/CD-integrated and on-demand validation pipelines so control testing is continuous and self-service. Onboard controls (e.g., HIDS, WAF, and beyond) into continuous attack-and-breach simulation, produce documented coverage and efficacy mappings, and expand validation across assurance domains including content assurance, data lineage, and privacy controls. Remain hands-on, guiding complex exploitation, reverse engineering, and custom tooling. - Remediation Advocacy:
Collaborate with Blue Teams and Control Owners to track findings through to completion, providing pragmatic, risk-appropriate recommendations to correct flaws and misconfigurations. - Posture Dashboards & Metrics:
Turn validation results into an authoritative, leadership-accessible view of security posture — SLA/SLI compliance, trends, remediation velocity, and per-control coverage and efficacy — so leadership always knows how good we are and how good we want to be, and discrepancies are detected and remediated quickly.
Minimum Qualifications
- Experience:
8+ years in offensive security or privacy disciplines (Red…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).