← All roles
Director

Director of Offensive Security

NorthMark Compute & Cloud · Software

Dallas, TX · Onsite · full_time

CLI Career Level

VP-equivalent

Moderate confidence

Opportunity Score

74/100

Above average

Moderate confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 20, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — Director of Security (US)

CLI Take

Broader than the title suggests

This role reads VP-equivalent despite being advertised as “Director of Offensive Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Chief Information Security Officer and carries board-level exposure. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

74/100 — above average opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 5 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

VP-equivalent — The employer lists this as “Director of Offensive Security”. CLI reads it as VP-equivalent because the role shows reports to the CISO, board-level exposure expected.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Board-level exposure is expected in the role.

What to probe before applying

  • The posting reads closer to an individual contributor mandate: hands-on delivery expected.

Scoring components · Above average

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level57 · weight 12%

The role reports to the CISO.

Functional and geographic scopeNot disclosed · excluded from the score

Scope: no enterprise, global or multi-unit remit is described.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title25 · weight 10%

The posting reads closer to an individual contributor mandate: hands-on delivery expected.

Company scale and trajectoryNot disclosed · excluded from the score

Employer scale: not established.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

The Director of Offensive Security is tasked with building and leading a permanent, continuous adversarial validation program that emulates sophisticated threat actors against the company's production HPC and cloud infrastructure. Unlike traditional pentesting, this leader will operate an independent line of assurance, delivering evidence-backed assessments of control efficacy directly to the CISO to drive remediation across engineering teams.

Reporting to the CISO, this role leads an independent offensive security function responsible for the production environment including HPC clusters and multi-tenant Kubernetes. The remit covers red teaming, purple team feedback loops, and external vendor management for the entire NMC² infrastructure.

Scope

  • Reports to Chief Information Security Officer
  • Board-level exposure expected

Domains and regulation

  • Cyber Defense
  • Cloud Security
  • Infrastructure Security
  • Application Security
  • Research Data Security

Requirements

Must have

  • 15+ years in offensive security with depth in network, cloud, red team, app exploitation, or hardware/firmware attack research
  • 5+ years leading offensive security teams with accountability for hiring and managing operational security of red team infrastructure
  • Demonstrated red team leadership against mature environments (SOC, EDR, and IR functions present)
  • Deep operational fluency with MITRE ATT&CK v15 and emulation frameworks like MITRE CALDERA or Atomic Red Team
  • Hands-on capability with C2 frameworks (Cobalt Strike, Mythic, Sliver) and custom tool development
  • Strong command of Kubernetes and cloud IAM offensive tradecraft, including multi-tenant isolation testing

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Compensation range not disclosed; Specific team size or headcount budget not disclosed.

About NorthMark Compute & Cloud

Industry
Software
Company background compiled from public sources — treat as indicative.

Full company profile for NorthMark Compute & Cloud →

View original job description
The CompanyNorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.The PositionThe Director of Offensive Security reports directly to the CISO and owns continuous adversarial validation of the NMC² production environment. This is not a scheduled pentest function or a compliance-checkbox red team. You will build and run a standing offensive capability that operates against production with authorization, emulates named threat actors relevant to our customer base and infrastructure class, and produces independent, evidence-backed assessments of whether our controls work under realistic attack conditions.This function operates as an independent line of assurance within the Security organization, with a direct reporting relationship to the CISO. To preserve objectivity, assessment findings are delivered to the CISO without editorial review by the teams whose controls or systems are under evaluation. Security Engineering, Platform Engineering, and Security Architecture receive findings as remediation owners.ResponsibilitiesBuild and run a continuous red team program against the production NMC² environment: HPC clusters, multi-tenant Kubernetes, bare-metal provisioning infrastructure, customer network fabric, identity plane, and the internal control surface itself (SIEM, EDR, IAM, PAM) Execute adversary emulation campaigns aligned to MITRE ATT&CK v15 TTPs relevant to our threat model: financially motivated access brokers (e.g., TTP sets associated with initial access brokers targeting financial services customers), APT groups with demonstrated interest in research computing and scientific workloads, and insider threat scenarios covering privileged operator abuse Independently validate detection and response efficacy: every red team operation produces a detection coverage report measured against the SOC and IR functions, including time-to-detect, time-to-contain, and detection gap inventory by ATT&CK technique ID Own the purple team feedback loop: every undetected TTP becomes a tracked detection engineering deliverable with owner and SLA, every detected-but-unresponded TTP becomes a tracked IR playbook deliverable Run continuous attack surface validation against production, not just pre-production, with a documented rules-of-engagement framework, blast radius controls, and CISO-level authorization gates for destructive or high-risk techniques Lead threat-led penetration testing of the HPC-specific attack surface: Slurm and workload manager abuse, GPU driver and firmware attack paths, InfiniBand and RDMA fabric isolation, scheduler privilege escalation, cross-tenant lateral movement in shared compute, and scientific software supply chain compromise Own offensive validation of cloud and Kubernetes controls: IAM boundary testing, cross-account and cross-tenant escape attempts, container breakout chains, service mesh bypass, admission controller evasion, and secrets management integrity Drive threat modeling at design stage for new platform capabilities and major architecture changes, producing adversarial design reviews that the CISO signs off on before build Manage the external pentest and red team vendor portfolio: scoping, vendor selection, quality control of deliverables, and integration of external findings into the internal remediation tracking system Build and maintain the offensive tooling stack including custom implants, C2 infrastructure, and internal exploit development capability, with clear controls on tool custody, source code management, and destruction protocols Define and publish offensive security KPIs to CISO and board level: coverage against MITRE ATT&CK technique inventory, mean time to compromise from assumed-breach scenarios, control validation pass rate by control family, remediation velocity on P1 and P2 findings, and repeat finding rate Issue formal assessment reports using CWE classification, CVSS v3.1 base and environmental scoring, and explicit exploitation evidence; findings are attestations, not suggestions Champion an adversarial engineering culture across Platform and Security Engineering through documented attack patterns, regular internal briefings, and integration of offensive findings into developer tooling and CI/CD gates Requirements15+ years in offensive security with demonstrated hands-on depth across at least three of: network penetration testing, red team operations, cloud penetration testing, application exploitation, hardware and firmware attack research, or advanced adversary emulation 5+ years leading offensive security teams, including direct accountability for hiring specialized offensive talent, managing operational security of red team infrastructure, and operating under formal rules of engagement against production systems Demonstrated red team leadership against mature target environments: environments with functioning SOC, EDR, and IR capability, not greenfield pentest targets Deep operational fluency with MITRE ATT&CK v15 and ATT&CK Navigator for coverage mapping, adversary emulation planning using frameworks such as MITRE CALDERA or Atomic Red Team, and purple team execution models Hands-on capability with production-grade offensive tooling: C2 frameworks (Cobalt Strike, Mythic, Sliver, or equivalent), exploitation frameworks, custom tool development, and operational security for red team infrastructure Strong command of cloud and container offensive tradecraft: Kubernetes attack paths, cloud IAM privilege escalation chains, service mesh and sidecar abuse, and multi-tenant isolation testing Fluency with CWE, CVSS v3.1 and v4.0, OWASP Top 10, SANS CWE Top 25, and the CIS Controls v8 Penetration Testing domain (Control 18) Experience integrating offensive findings into engineering workflow systems (Jira or equivalent) with enforceable SLA tracking, not report-and-walk-away engagements Demonstrated ability to execute offensive work against production with appropriate authorization, blast radius control, and executive communication discipline Exceptional written communication: findings must stand up to scrutiny from engineering leadership who will push back, and from auditors and customers who will consume the output PreferredOSCP, OSEP, OSED, GXPN, GPEN, or CRTO certifications; CISSP alone is not sufficient evidence of hands-on offensive capability Prior experience building an offensive security function from scratch, not inheriting an existing one HPC, bare-metal, or hyperscale data center offensive assessment experience Published CVE credits, conference talks (DEF CON, Black Hat, Offensive Con, Recon), or public offensive research Background in threat intelligence consumption for adversary emulation planning (CTI-led red teaming) Experience with sovereign cloud, export-controlled, or financial services customer environments Apply Now

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.