> Markdown version of [/jobs/ext/1881642-purple-team-manager-defense-improvement-analysis](https://www.wearedevelopers.com/jobs/ext/1881642-purple-team-manager-defense-improvement-analysis). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Purple Team Manager (Defense Improvement Analysis) - **Company:** Capital One Financial Corporation - **Location:** Richmond, VA, United States - **Experience:** Experienced - **Salary:** $197,300.0 - $225,100.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Intrusion Detection and Prevention, Log Analysis, Scripting, Apache Spark, Cybercrime, Data Management, Purple Team (Cyber Security), Cyber Warfare, Databricks - **Published:** August 2, 2026 - **Apply:** https://www.juju.com/job/00000000gl5t4d ## About the Role + **High School Diploma, GED, or equivalent certification.** + **At least 4 years of information security experience.** + **At least 3 years of experience in Threat Hunting or Detection Engineering within a cloud or hybrid environment.** + **At least 2 years of experience analyzing EDR telemetry and bypass techniques.** Preferred Qualifications: + **2+ years of experience performing offensive security operations** + **2+ years experience with Databricks, Spark, or similar for security analytics.** + **4+ years of experience in log analysis, threat detection engineering, threat hunt, incident response, forensics** + **4+ years of experience with scripting and compiled languages** + **One or more of the following certifications: OSCP, OSCE, GPEN, GXPN, CRTO, GCFA, GCIH, OSTH, GDAT** At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization). ## Description At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors, who love to solve real problems and meet real customer needs. We want you to be curious and ask "what if?" Capital One started as an information strategy company that specialized in credit cards, and we have become one of the most impactful and disruptive players in the industry. Capital One's Offensive Security Purple Team reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment by conducting covert/overt adversary simulation and emulation. This position works closely with offensive and defensive partner teams to plan, coordinate, execute and report on detection gaps and control weaknesses to improve cyber defense across the enterprise. The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One's brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats. Responsibilities: + **Lead "Defense Improvement Analysis" (DIA): Deconstruct adversary simulation activities to identify control gaps and document the full lifecycle, from initial discovery to final technical resolution.** + **Engineering & Analytics: Perform advanced analysis of log events using big data tools to identify, recommend, and engineer specific solutions for threat detection and response.** + **Strategic Collaboration: Serve as the technical bridge between offensive and defensive stakeholders, translating complex adversary TTPs into durable defense strategies and actionable recommendations for both technical and executive audiences.** + **Operational Research: Continuously research emerging threat behaviors and automate repetitive post-exploitation analysis tasks to scale the team's ability to identify and address novel TTPs.** + **Infrastructure & Tooling: Build and maintain the technical infrastructure and lab environments required to support and evolve Purple Team activities.** ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cutting LLM Costs Without Cutting Quality: How to Beat Proprietary LLMs with Fine-Tuned Open Source](https://www.wearedevelopers.com/videos/100151-cutting-llm-costs-without-cutting-quality-how-to-beat-proprietary-llms-with-fine-tuned-open-source) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) - [Dev Digest 168: Hacking Postgres, Blocking Meta and Fixing CSS](https://www.wearedevelopers.com/magazine/588-dev-digest-168-hacking-postgres-blocking-meta-and-fixing-css) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)