Cyber Security Threat Management Associate Director
DTCC Enterprise Services India Private LimitedJob Description
Cyber Security Threat Management Associate Director
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
The Associate Director of Breach and Attack Simulation (BAS) lead the strategy, design, execution, and continuous maturation of DTCC’s adversary simulation and security control validation program. This role combines offensive security expertise, leadership, and cross-functional coordination to emulate real-world threat behaviors, validate preventive and detective controls, identify detection and response gaps, and drive measurable improvements in cyber resilience across on-premises, cloud, and hybrid environments.
Your Primary Responsibilities:
- Lead the Breach and Attack Simulation program, including strategy, roadmap, operating model, execution standards, and measurable success criteria.
- Design and execute realistic adversary emulation scenarios that validate security controls against current threat behaviors and organizational risk priorities.
- Map simulation activities and findings to MITRE ATT&CK and other relevant frameworks to support consistent reporting, prioritization, and control coverage analysis.
- Partner with SIEM, SOC, threat intelligence, endpoint, network, cloud, and security engineering teams to improve detection coverage, response readiness, and control effectiveness.
- Identify, assess, document, and track remediation of control gaps discovered through BAS exercises, red team collaboration, purple team engagements, and continuous validation activities.
- Oversee BAS platform use-cases, automation, scenario development, execution scheduling, test safety controls, and evidence collection.
- Translate threat intelligence, business risks, and control requirements into repeatable simulation scenarios that safely test enterprise defenses.
- Develop executive-ready reports, metrics, and risk narratives that communicate control performance, detection gaps, remediation progress, and cyber resilience improvements.
- Establish actionable metrics and risk thresholds to measure BAS program effectiveness, detection maturity, control coverage, and remediation outcomes.
- Coordinate purple team activities to ensure simulation findings are converted into improved detections, response playbooks, tuning actions, and control enhancements.
- Provide leadership, coaching, and technical direction to BAS engineers and cross-functional contributors supporting adversary simulation activities.
- Manage stakeholder engagement, including requirements gathering, exercise scoping, risk approvals, communications, and post-exercise readouts.
- Ensure simulation activities are conducted safely, ethically, and in alignment with approved rules of engagement, change management, and operational risk requirements.
- Build strong relationships across technology, cybersecurity, risk, compliance, audit, and business stakeholders to drive remediation accountability and program adoption.
- Support audit, regulatory, and control assurance requests by providing evidence of security control validation, remediation tracking, and program governance.
- Continuously improve BAS processes, procedures, playbooks, templates, and reporting standards to increase repeatability, scalability, and operational maturity.
- Stay current with adversary tactics, techniques, and procedures, emerging attack trends, and BAS industry practices to inform program priorities.
- Contribute to cybersecurity strategy, control lifecycle activities, and enterprise resilience initiatives related to threat-informed defense validation.
- Fulfill additional cybersecurity engineering, threat defense, control validation, and special project responsibilities as assigned.
Qualifications:
- Minimum of 6 years of related experience
- Bachelor's degree preferred or equivalent experience
Talents Needed for Success:
- At least 10 years of cybersecurity experience, including offensive security, security engineering, incident response, detection engineering, or control validation responsibilities.
- Minimum 5 years of leadership or program ownership experience in breach and attack simulation, red team, purple team, threat defense, or security control assurance programs.
- Bachelor’s degree in computer science, cybersecurity, information technology, engineering, or a related discipline; equivalent experience may be considered.
- Relevant certifications such as CISSP, OSCP, OSCE, GPEN, GCIH, GCIA, CRTO, CEH, CISM, or cloud security certifications are preferred.
- Deep expertise in Breach and Attack Simulation, adversary emulation, red team operations, purple team collaboration, and continuous security control validation.
- Strong understanding of MITRE ATT&CK, cyber kill chain concepts, threat-informed defense, detection engineering, and control coverage assessment.
- Hands-on experience with BAS platforms, SIEM technologies, EDR/XDR tools, SOAR workflows, vulnerability management, cloud security, and security telemetry sources.
- Knowledge of attacker tactics, techniques, and procedures across identity, endpoint, network, application, cloud, and data platforms.
- Ability to write and review test plans, rules of engagement, attack narratives, remediation plans, executive summaries, technical reports, and control assurance evidence.
- Strong leadership, stakeholder management, communication, project management, and executive presentation skills.
Actual salary is determined based on the role, location, individual experience, skills, and other considerations.We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you’ll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It’s the chance to make a difference at a company that’s truly one of a kind.
Learn more about Clearance and Settlement by clicking here.
Experience Level
Mid LevelJob role
Job requirements
About company
Similar jobs you can apply for
Hardware & Network Engineer
Field Service Engineer (IT Hardware)
Axiom Infotech Private LimitedHDO Engineer
Bharti Airtel Services
Computer Hardware Engineer
Maxima Computers NeedsField Installation Engineer
Airtel
Engineering Trainee
Mtandt Rentals LtdField Installation Engineer
V5 GlobalYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 6 to 31 years are eligible to apply for this job. You can apply for more jobs in Chennai to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Chennai at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Chennai . Through apna, you can find jobs in 64 cities across India. Join NOW!