Get notified about similar jobs!

RBC

Senior Security Specialist - Attack Path Management (global Security)

RBC
Posted a day ago
Toronto, Ontario, CA (Hybrid)

Key Details

Top Skills Required

Google Cloud PlatformPenetration TestingCloud Security +22 more

Description

Job Description

What will you do?

  • Attack Path Operations
    • Operate and continuously tune BloodHound Enterprise to map identity attack paths across on-prem AD, Entra/Azure, AWS, GCP, DevOps (e.g., GitHub), and PAM platforms (and more!).
    • Analyze attack path data to identify choke points and Tier Zero exposures, prioritizing remediation by real-world exploitability and business impact.
    • Validate that data collection accurately reflects the true state of the environment, ensuring attack path fidelity.
  • Coverage Expansion
    • Extend attack path coverage into CI/CD pipelines (e.g., Jenkins), secrets management (e.g., HashiCorp), IAM tooling and more with OpenHound.
    • Help design custom collectors to enrich BloodHound attack path data beyond out-of-the-box coverage.
  • Red Team & Stakeholder Collaboration
    • Assist the Red Team in building realistic attack paths to support covert operations and adversary emulation exercises.
    • Build strong relationships with Cloud Engineering, Cloud Security, IAM, Threat Detection, and Incident Response teams.
    • Communicate attack path exposure, remediation progress, and identity risk trends to cloud operations, internal customers, the SOC, IR, and business stakeholders

Must Haves

  • 3+ years of on-premises and cloud security/engineering experience with Active Directory and Entra/Azure, AWS, or GCP in enterprise environments.
  • Understanding of DevOps/CI-CD tooling (Jenkins, GitHub Actions, Terraform, CloudFormation, Ansible, or similar).
  • Proficiency in BloodHound Ciphers and PowerShell, C#, or Python, with the ability to build or adapt tools and automation.
  • Familiarity with containerized environments (e.g., Kubernetes) and associated RBAC/security implications.
  • Solid understanding of network protocols, identity and access management, and common misconfigurations across AD, cloud, and DevOps environments.
  • Experience working in or supporting Red, Blue, and/or Purple Team operations in enterprise settings.
  • Working knowledge of Linux and Windows operating systems.

Nice-to-Have

  • Certifications

    • Offensive/defensive security certifications (OSCP, CPTS, CAPE, GXPN, MCRTP, ACRTP, GCRTP, etc.) and/or cloud security specialties (AWS/GCP/Azure).

    • BloodHound Operator Certification (BHOC), regardless of specialty.

  • Tradecraft & Methodology

    • Familiarity with MITRE ATT&CK, threat emulation frameworks (Caldera, Atomic Red Team), purple teaming methodologies, and the ability to reverse-engineer or emulate TTPs from threat intel reports.

    • Ability to analyze and identify complex cross-platform attack vectors.

  • Hands-on Experience

    • AD and/or cloud-focused penetration testing, threat simulation, or detection/response in regulated or complex production environments.

    • PaaS/SaaS operational know-how (SLAs, load balancing, high availability, OS patching, networking, security patch management).

  • Above average performance. You are competitive and passionate. You thrive on challenge and have a proven ability to set ambitious but achievable goals and surpass them.
  • A team player. At RBC we work together. You will be the type of person that brings that approach to your work. You will have a proven ability to build, grow, and maintain relationships both internally and externally.

What’s in it for you?

At a team level, you will have exposure to operating in complex and critical environments that power our economy. You will work with talented and driven offensive, defensive, and threat hunting security experts; refining and expanding your skillset. You will be given the opportunity to attend industry-leading public and private training sessions to take your skills to the next level.

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference in our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable;
  • Dedicated budget for annual training and conference attendance;
  • Leaders who support your development through coaching, training, and managing opportunities;
  • Ability to make a difference and lasting impact;
  • Work in a dynamic, collaborative, progressive, and high-performing team;
  • Flexible work/life balance options including a hybrid-remote working environment;
  • Opportunities to do challenging work;
  • Opportunities to take on progressively greater accountabilities; and
  • Opportunities to build close relationships with various cyber security teams.

Job Skills

Confidentiality, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security, Strategic Thinking

Additional Job Details

Address:

16 YORK ST:TORONTO

City:

Toronto

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2026-09-06

Application Deadline:

2026-09-25

Note:Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.

RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.

Job Details

Job Type
full time
Experience
3+ years

Required Skills

Google Cloud PlatformPenetration TestingCloud SecurityRelationship BuildingCWindowsActive DirectoryNetwork ProtocolsAWSAttack Path ManagementPythonTeamworkContinuous Integration and Continuous DeliveryDecision MakingBloodHound EnterpriseMITRE ATT&CKCommunicationStrategic ThinkingDevOpsLinuxIdentity and Access ManagementKubernetesThreat EmulationPowerShellMicrosoft Entra ID