Director of Offensive Security
NorthMark Compute & Cloud · Software
Dallas, TX · Onsite · full_time
CLI Career Level
VP-equivalent
Moderate confidence
Opportunity Score
74/100
Above average
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Aug 20, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — Director of Security (US)
CLI Take
Broader than the title suggests
This role reads VP-equivalent despite being advertised as “Director of Offensive Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Chief Information Security Officer and carries board-level exposure. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
74/100 — above average opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 5 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
VP-equivalent — The employer lists this as “Director of Offensive Security”. CLI reads it as VP-equivalent because the role shows reports to the CISO, board-level exposure expected.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Board-level exposure is expected in the role.
What to probe before applying
- The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Scoring components · Above average
Compensation is not disclosed and there is no comparable set to place it against.
The role reports to the CISO.
Scope: no enterprise, global or multi-unit remit is described.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Board-level exposure is expected in the role.
The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Employer scale: not established.
Team size: not disclosed.
Budget ownership: not disclosed.
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
No compensation disclosed and insufficient comparable data to estimate.
The mandate
The Director of Offensive Security is tasked with building and leading a permanent, continuous adversarial validation program that emulates sophisticated threat actors against the company's production HPC and cloud infrastructure. Unlike traditional pentesting, this leader will operate an independent line of assurance, delivering evidence-backed assessments of control efficacy directly to the CISO to drive remediation across engineering teams.
Reporting to the CISO, this role leads an independent offensive security function responsible for the production environment including HPC clusters and multi-tenant Kubernetes. The remit covers red teaming, purple team feedback loops, and external vendor management for the entire NMC² infrastructure.
Scope
- Reports to Chief Information Security Officer
- Board-level exposure expected
Domains and regulation
- Cyber Defense
- Cloud Security
- Infrastructure Security
- Application Security
- Research Data Security
Requirements
Must have
- 15+ years in offensive security with depth in network, cloud, red team, app exploitation, or hardware/firmware attack research
- 5+ years leading offensive security teams with accountability for hiring and managing operational security of red team infrastructure
- Demonstrated red team leadership against mature environments (SOC, EDR, and IR functions present)
- Deep operational fluency with MITRE ATT&CK v15 and emulation frameworks like MITRE CALDERA or Atomic Red Team
- Hands-on capability with C2 frameworks (Cobalt Strike, Mythic, Sliver) and custom tool development
- Strong command of Kubernetes and cloud IAM offensive tradecraft, including multi-tenant isolation testing
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Building a standing offensive capability from scratch rather than inheriting an existing function
- Operating continuous red team campaigns against live production environments (HPC and Kubernetes) without disrupting scientific research or production workloads
- Maintaining objectivity and independence while delivering unedited findings that challenge the efficacy of internal Security and Platform engineering teams
- Validating isolation in high-performance computing environments including InfiniBand fabric, GPU firmware, and Slurm workload managers
Not stated in the posting: Compensation range not disclosed; Specific team size or headcount budget not disclosed.
About NorthMark Compute & Cloud
- Industry
- Software
Full company profile for NorthMark Compute & Cloud →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.