Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)
GartnerAbout the role
Hiring near our Irving, TX Center of Excellence
About Gartner IT:
Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients. We make a broad organizational impact by delivering cutting-edge technology solutions that power Gartner. Gartner IT values its culture of nonstop innovation, an outcome-driven approach to success, and the notion that great ideas can come from anyone on the team.
About the role
Gartner information security teams are a group of passionate information security professionals dedicated to Protecting, Detecting, and Responding to threats. Our team is filled with lifelong learners who are consistently researching ways to better defend and stay ahead of the threats of tomorrow. We are a collaborative group, where good ideas come together whether they come from the most experienced or the newest members of the team.
As a Lead Purple Team Engineer on the Security Operations team, you will spearhead collaborative offensive and defensive security initiatives to identify and validate vulnerabilities in Gartner’s security controls, procedures and infrastructure. You will use your extensive knowledge of attacker tools and techniques (red team) to improve our capability to detect and respond to threats (blue team). You will play a key role in defending Gartner’s network and intellectual properties. Our team is filled with lifelong learners who are consistently researching ways to better defend and stay ahead of the threats of tomorrow. We are a collaborative, flexible group, where good ideas are brought forth and acted upon, whether they come from the most experienced or the newest members of the team.
What you will do:
Lead Purple Team operations by designing, planning and executing purple team exercises and activities that simulate real-world attack scenarios to test and improve detection and response capabilities.
Work closely with teams such as the Security Operations Center (SOC), Threat Intelligence, and Detection Engineering to help identify and remediate gaps in existing controls
Develop new, and tune existing attack emulations based on use-cases and strategy, drawing from threat intelligence and current events
Play a key role in Threat Modeling exercises
Assist and support SOC analysts during ad-hoc Incident Response activities
Build and maintain tools and scripts to support purple team activities, including automation of attack simulations and telemetry analysis
Assist in the development of innovative and cutting-edge detection content aligned with ATT&CK, Cyber Kill Chain, and various other cyber security frameworks
Bring your own ideas and solutions to a fast-paced, growing, and evolving team centered around operational excellence
Act as a mentor to junior team members, promote knowledge sharing and contribute to the strategic direction of the Security Operations team.
What you will need:
5+ years of relevant Information Security or Penetration Testing experience
Deep understanding of offensive techniques and tools
Knowledge of MITRE ATT&CK, Cyber Kill Chain or other behavioral information security frameworks
Python, Bash, PowerShell or other scripting language experience
Bachelor’s in Computer Science, Information Security, Engineering, or commensurate experience in Information security is preferred
Extensive experience in purple/red teaming with a strong technical foundation in offensive security and adversary emulation.
Ability to design, build and scale automated security validation processes
Experience with Attack Emulation Platforms
Background in cybersecurity incident analysis and investigation
Experience utilizing security tools such as EDR (including live response), web proxy, WAF and email security tools
Knowledge of cloud environments (AWS, Azure, GCP)
Digital Forensics and Incident Response (DFIR) skills
Ability to query using various query languages such as SPL, SQL, KQL
Ability to communicate effectively and possess excellent prioritization skills.
Ability to automate tasks and code solutions to repetitive problems (Python, PowerShell, Bash)
Nice to have:
Penetration Testing skills
Experience working closely with defenders/Blue Team to identify and resolve problems
Experience implementing integrations between tools utilizing APIs
Experience using SIEM or XDR for log analysis and alert creation
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s