Source Job

$120,000–$142,500/yr
Canada

  • Own and lead incident response readiness across KOHO, including tabletop exercises and playbook reviews.
  • Plan and execute adversarial simulations and build deception engineering programs from the ground up.
  • Lead incident response/DFIR during cybersecurity incidents and conduct post-incident documentation.

Incident Response AWS MITRE ATT&CK

20 jobs similar to Senior Purple Team Engineer

Jobs ranked by similarity.

UK 5w PTO

  • Research and create defensive security labs and crisis simulation content for the platform.
  • Work with the Product team on innovations and deploy new features.
  • Compile technical research into clear content for both technical and non-technical audiences.

Immersive Labs provides a cyber resilience platform that simulates real-world threats to test skills and measure performance. Founded in 2017, the company has grown to over 300 employees globally, secured over £150 million in funding, and been voted a best place to work.

$120,000–$155,000/yr
US

  • Perform Red Team engagements including stealth and purple teaming to simulate advanced cyber attacks and test security posture.
  • Collaborate with blue team members in real time to identify and address security gaps, and document findings for technical and executive audiences.
  • Stay current on attack vectors, develop new tools and techniques, and provide technical leadership to junior team members.

NBCUniversal is a leading media and entertainment company, creating world-class content across film, television, streaming, and theme parks. As a subsidiary of Comcast, we employ a global workforce and foster an inclusive culture focused on innovation and community.

$235,000–$280,000/yr
US

  • Lead a team of Attack and Full-Stack Engineers to design and scale offensive capabilities for the NodeZero platform.
  • Drive external attack strategy across public-facing infrastructure, SaaS platforms, and enterprise software.
  • Partner with Product and Design to translate field insights into productized capabilities and roadmap.

Horizon3.ai is a fast-growing, remote cybersecurity company focused on enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. The team is a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, and results.

US Unlimited PTO

  • Lead investigation and response for security incidents, suspicious activity, and emerging threats.
  • Design, implement, and improve security monitoring, detection, and response capabilities across AWS.
  • Develop detection rules, conduct post-incident reviews, and partner with teams to strengthen security controls.

CoLab is an AI platform that helps mechanical engineering teams bring life-changing products to market faster by driving stronger engineering decisions. Founded in 2019 and based in St. John's, Newfoundland, CoLab has grown rapidly, earning recognition on Deloitte's Fast 50 and Fast 500 lists.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

$96,798–$125,268/yr
Canada

  • Monitor security events and provide technical analysis on alerts
  • Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
  • Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.

$172,279–$249,640/yr
US Canada

  • Build and maintain SIEM for log collection and detection rules across corporate and production environments.
  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
  • Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.

Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.

$200,000–$250,000/yr
US Unlimited PTO

  • Lead detection engineering innovation by reimagining how unlimited AI capacity transforms SOC workflows.
  • Partner with engineering teams to encode expert detection knowledge into product, designing scoring rubrics for AI-generated content.
  • Stay current on emerging threats and conduct original research to develop novel AI-assisted detection approaches.

Dropzone's mission is to scale cybersecurity beyond human limits by augmenting security engineers with AI specialists. We are an award-winning, venture-backed company disrupting the $200B+ cybersecurity market with a team experienced in cybersecurity, AI/ML, and SaaS.

$155,000–$155,000/yr
US

  • Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, and compromise assessments across onsite and remote environments.
  • Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks and response methodologies.
  • Develop and deliver advisory services including incident response planning workshops, maturity assessments, and tabletop exercises to advance customer readiness.

Dragos is a global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services. They have a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

US

  • Lead the strategy, design, and operation of a Cyber Fusion Center including SOC, incident response, and security engineering.
  • Oversee SOC operations across internal teams and external MSSPs, leveraging AI-enabled platforms.
  • Drive operational excellence in monitoring, detection, and response, ensuring alignment with frameworks like MITRE ATT&CK.

PDMI provides pharmacy data processing and scalable solutions for private label Pharmacy Benefit Managers, health plans, and hospital systems. The company has been voted Best Employer in Ohio for five consecutive years and offers a collaborative, remote-friendly culture.

UK

  • Lead and support the response to all security events and incidents across Twilio's global infrastructure, services, and applications.
  • Work cross-collaboratively to solve challenges related to a broad spectrum of threat actors and improve security posture.
  • Own the security incident lifecycle, participate in on-call rotation, and conduct post-incident betterments.

Twilio shapes the future of communications with innovative solutions for hundreds of thousands of businesses, empowering millions of developers worldwide. The company embraces a remote-first work culture and a strong culture of connection and global inclusion, fostering a vibrant and diverse team.

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

$83,922–$116,586/yr
UK

  • Design and automate controls, detection mechanisms, and tooling to improve Information Security of Algolia's infrastructure and products.
  • Partner with engineering and product teams to integrate Information Security into new features, systems, and development pipelines.
  • Conduct Information Security risk assessments and threat models of core systems, services, and third-party vendors.

Algolia is a pioneer and market leader in AI Search, empowering 17,000+ businesses with blazing-fast, predictive search experiences. The company raised $150M in Series D funding, quadrupling its valuation to $2.25B, and has a global team with offices in Paris, NYC, London, Sydney, and Bucharest.

$172,279–$249,640/yr
US Canada

  • Partner with engineering teams to review cloud and compute architecture design changes.
  • Establish threat models for cloud and compute paved roads to identify security risks.
  • Write code for automations that support security requirements like threat detection and incident containment.

Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.

US

  • Design, build, and operate an AI-augmented red teaming harness using frontier LLM APIs.
  • Conduct adversarial testing across four attack perspectives to discover and chain vulnerabilities.
  • Assume ownership of security stage-gates within our CI/CD pipeline.

We provide a cloud-native platform called Silo that enables digital analysts to securely and anonymously investigate threats. We serve over 750 organizations and value integrity, collaboration, and innovation.

$130,000–$185,000/yr
US

  • Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
  • Build security tooling and automation, contributing to development of internal applications and scripts.
  • Execute incident response efforts by identifying, investigating, and remediating security incidents.

BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.

US Unlimited PTO

  • Deliver attack-oriented professional services including penetration testing, red teaming, and social engineering for clients.
  • Author comprehensive assessment deliverables detailing technical execution, core deficiencies, and remediation strategies.
  • Contribute to practice development and marketing initiatives through research, speaking, and tool creation.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations minimize risk. The company has over 1,200 employees and focuses on a collaborative, enjoyable workplace atmosphere.

$135,000–$160,000/yr
US

  • Build tools, automation, and infrastructure for scalable adversarial testing of AI systems.
  • Build and maintain realistic security test environments using cloud infrastructure and automation tools like Terraform.
  • Collaborate with red teamers and engineers to reproduce, investigate, and remediate vulnerabilities.

10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They operate in a fast-paced, high-growth startup environment with a collaborative and builder-oriented culture.

$129,500–$144,300/yr
Canada Unlimited PTO

  • Lead security architecture across AWS and colocation, defining secure patterns and controls.
  • Partner with engineering teams to threat model, review designs, and promote secure-by-design.
  • Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.

NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.

Global

  • Lead and coordinate major incident war rooms from initiation through service restoration, driving cross-functional collaboration.
  • Provide timely executive-level updates and maintain accurate incident documentation, leveraging AI tools for efficiency.
  • Participate in a 24x7 on-call rotational support model for enterprise production incidents.

Miratech is a global IT services and consulting company that helps visionaries change the world by supporting digital transformation for large enterprises. With nearly 1,000 full-time professionals and a 99% project success rate, they maintain a culture of relentless performance and operate in 25 countries worldwide.