Information Security Lead - Offensive and Threat Intel, Cheyenne
Indexed description
Job Title: Information Security Lead - Offensive and Threat Intel
Location: 1912 Capitol Avenue, Cheyenne, WY 82001
Work Schedule: Monday - Friday, 8:00am - 5:00pm
Employee Type: Non-Exempt Full-Time
Hiring Pay Ranges: $35.00 - $51.50 per hour
The hiring pay range for this position is commensurate with the level of relevant experience and education.
This position may be eligible to receive an additional $1.00 per hour if approved for the Spanish Communication Assistant Program.
ANB Bank has financial strength embodied in $3 billion in assets and is a true community bank with an unwavering commitment to excellence. The bank helps each of its communities prosper through investment, sponsorship, philanthropy, and employee volunteerism. It is a passion ANB has for banking that makes the difference.
ANB Bank hires individuals who provide excellent customer service and build meaningful relationships with our customers and within our communities. ANB is committed to rewarding our team members who strengthen our company and culture. ANB offers competitive compensation and a comprehensive benefits package for this position.
Health & Wellness Benefits (Subject To Eligibility Requirements)
Minimum 4 Weeks of Paid Time Off (PTO)
11 Paid Holidays
Medical, Dental, and Vision Insurance
Health Savings (HSA), Flexible Spending (FSA), and dependent care spending accounts
Company provided Life, AD&D, and Disability Insurance with supplementation options
401(k) plan with discretionary company match and profit sharing
Discretionary annual bonus and employee referral incentives
Employee Assistance Program (EAP)
Tuition Reimbursement Program
Spanish Communication Assistant Program Incentive
Employee banking products
Summary
The Offensive Operations Team Lead owns the strategy, execution, and continuous improvement of the organization’s offensive security program. This role directs red team operations, adversary emulation, targeted penetration testing, and purple team exercises to measurably improve detection, response, and hardening across on-premises and cloud environments. The role partners closely with all other aspects of Information Security and relevant parties within the organization to validate control effectiveness and reduce risk to critical business services. Responsible for implementation and administration of corporate Information Security Systems as listed below.
Essential Duties And Responsibilities
Offensive Operations Program Ownership
Define and maintain the offensive security strategy, roadmap, playbooks, SLAs, and rules of engagement (ROE).
Own intake and scoping for engagements; prioritize based on business impact, threat intel, and control validation needs.
Ensure all activities align with legal, regulatory, and corporate policy requirements, including operational safety and privacy controls.
Red Team & Adversary Emulation
Plan and execute realistic, threat-informed operations mapping to MITRE ATT&CK, targeting identity, endpoints, network, applications, and cloud services.
Develop and maintain adversary emulation plans, chained attack paths, and objective-based scenarios for critical business processes.
Oversee exploitation research and proof-of-concept development (privilege escalation, lateral movement, persistence) with strict safeguards and de-confliction.
Lead purple team exercises to drive measurable detections and response playbook improvements with Detection Engineering and SOC teams.
Tooling, Infrastructure & Automation
Design, secure, and maintain operator environments (segmented labs, cloud resources, and approved tooling).
Evaluate and integrate offensive tools (e.g., BloodHound, Burp Suite, custom scripts) and maintain an internal, access-controlled repository.
Develop automation to streamline reconnaissance, validation, artifact collection, reporting, and metrics.
Collaboration, Communicat on & Reporting
Produce clear post-operation reports with technical detail, business impact, exploited control gaps, and prioritized remediation.
Partner with relevant parties to translate findings into backlog items; track remediation and validate fixes.
Provide executive-level updates and program metrics demonstrating risk reduction and control effectiveness over time.
Support Incident Response by advising on attacker TTPs, containment strategies, and root cause analysis when appropriate.
Governance, Safety & Compliance
Enforce ROE, change control, maintenance windows, de-confliction, and kill-switch procedures to protect production systems.
Document methodologies, tool usage, and operational decisions; maintain evidence handling and data retention practices.
Periodically review program compliance with legal, regulatory, and internal policy obligations (e.g., GLBA/PCI/FFIEC as applicable).
Continuous Improvement & Innovation
Track emerging threat actor behaviors, new exploits, and research; proactively test controls against evolving TTPs.
Upskill the team across identity, cloud, application, and social engineering domains; lead internal workshops and demos.
Establish and maintain a safe disclosure process for internally discovered vulnerabilities.
Threat Intelligence Integration
Consume and analyze internal and external threat intelligence to identify relevant adversary behaviors, emerging vulnerabilities, and likely attack paths targeting the financial sector.
Translate threat intelligence into actionable offensive testing objectives, adversary emulation plans, and targeted validation activities.
Maintain alignment between offensive operations and intelligence-driven priority threats, including nation-state TTPs, ransomware groups, and financially motivated actors.
Ensure operational findings feed back into Information Security threat models and detection logic.
Track exploit releases, zero-day disclosures, cloud-identity abuse techniques, and industry reports to proactively schedule offensive testing before weaponization impacts the organization.
Produce periodic intelligence-driven risk reports for leadership, highlighting threat trends, likely impacts, and recommended offensive validation activities.
Ensuring management is made aware of critical events and situations within the department.
Maintains a current knowledge and understanding of requirements, policies, configurations, and procedures related to the Information Security team.
Maintains a current knowledge and consistent compliance with Bank Secrecy Act (BSA) requirements, as well as knowledge and consistent compliance with other banking regulations and Bank policies and procedures related to the position.
Delivers quality of service as defined by department standards.
Maintains confidentiality as defined by department standards.
Supports the company’s Mission, Vision, and Values.
Other duties may be assigned.
Education and/or Experience
Seven years of related experience and/or training.
Preferred college degree; or equivalent combination of education and experience.
Demonstrated expertise in Windows/Active Directory, identity attack paths (Kerberos/NTLM/LDAP/SSO), and cloud (Azure/Microsoft 365 a plus).
Hands-on proficiency with C2 frameworks, EDR/XDR evasion techniques, password/credential attack methods, and lateral movement.
Strong understanding of detection engineering concepts, logging/telemetry, and purple team collaboration.
Exceptional communication skills with the ability to translate complex findings into business-aligned risk narratives.
Performs several, if not all, of the above duties with minimal direction and supervision.
Several industry standard Information Security advanced certifications (OSCP, GXPN, CISSP, etc) in good standing and appropriate training and experience required.
Equal Opportunity Employer / Affirmative Action / Minorities / Female / Disability / Veteran
ANB Bank
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search