Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
RBC

Senior Security Specialist – Attack Path Management

RBC

Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.

Posted 9/6/2026full-timeToronto • 🇨🇦 CanadaSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cloud and on-premises security, particularly with Active Directory, Entra/Azure, AWS, and GCP. Proficient in analyzing attack paths, validating data accuracy, and collaborating with cross-functional teams to enhance security measures.

Highest-signal resume keywords
BloodHound Enterprise OperationActive Directory SecurityCloud Security EngineeringDevOps/CI-CD ToolingPenetration Testing

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
BloodHound CiphersPowerShellC#PythonNetwork ProtocolsIdentity and Access ManagementContainer SecurityThreat Emulation FrameworksCross-Platform Attack AnalysisPaaS/SaaS Operations
Soft Skills
Relationship BuildingCommunicationCollaborationGoal SettingProblem Solving
Tools & Technologies
JenkinsGitHub ActionsTerraformCloudFormationAnsibleKubernetesLinuxWindows
Certifications & Qualifications
BloodHound Operator CertificationOffensive Security CertificationsCloud Security Specialties
Industry Keywords
Red Team OperationsBlue Team OperationsPurple Team MethodologiesMITRE ATT&CKThreat DetectionIncident ResponseRegulated EnvironmentsComplex Production Environments

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudGoogle Cloud PlatformJenkinsKubernetesLinuxPythonTerraform

About the role

Key responsibilities & impact
  • Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps, and PAM platforms
  • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact
  • Validate data collection accuracy and ensure attack path fidelity
  • Extend attack path coverage into CI/CD pipelines, secrets management, IAM tooling, and other platforms with OpenHound
  • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage
  • Assist the Red Team in building realistic attack paths for covert operations and adversary emulation exercises
  • Build relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams
  • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders
  • Work in complex and critical environments that power the economy
  • Collaborate with offensive, defensive, and threat hunting security experts to refine and expand skills

Requirements

What you’ll need
  • 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments
  • Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar)
  • Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation
  • Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications
  • Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments
  • Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings
  • Working knowledge of Linux and Windows operating systems
  • Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team), and purple teaming methodologies
  • Ability to reverse-engineer or emulate TTPs from threat intel reports
  • Ability to analyze and identify complex cross-platform attack vectors
  • Hands-on experience with AD and/or cloud-focused penetration testing, threat simulation, or detection/response in regulated or complex production environments
  • PaaS/SaaS operational know-how, including SLAs, load balancing, high availability, OS patching, networking, and security patch management
  • Offensive/defensive security certifications or cloud security specialties are nice-to-have
  • BloodHound Operator Certification (BHOC) is nice-to-have
  • Above average performance; competitive and passionate; ability to set ambitious but achievable goals and surpass them
  • Proven ability to build, grow, and maintain relationships both internally and externally

Benefits

Comp & perks
  • Comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Dedicated budget for annual training and conference attendance
  • Leaders who support your development through coaching, training, and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • Flexible work/life balance options including a hybrid-remote working environment
  • Opportunities to do challenging work
  • Opportunities to take on progressively greater accountabilities
  • Opportunities to build close relationships with various cyber security teams
  • Opportunity to attend industry-leading public and private training sessions