> Markdown version of [/jobs/ext/1948990-purple-team-lead-sr-cyber-defense-analyst](https://www.wearedevelopers.com/jobs/ext/1948990-purple-team-lead-sr-cyber-defense-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Purple Team Lead/Sr Cyber Defense Analyst - **Company:** Indigo It - **Location:** Fort Liberty, NC, United States - **Experience:** Expert - **Salary:** $125,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Burp Suite, Cloud Computing, Cyber Security, Information Technology Consulting, Computer Telephony Integration, Emulators, Intrusion Detection and Prevention, Kali Linux, Knowledge Management, Nmap, Red Team (Cyber Security), Web Applications, Mitre Att&ck, Cyber Threat Analysis, Metasploit, Purple Team (Cyber Security), Cyber Warfare, Blue Team (Cyber Security) - **Published:** August 6, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17836586?backUrl=%2Fcareer%2F17836586%2FPurple-Team-Lead-Sr-Cyber-Defense-Analyst-North-Carolina-Fort-Bragg ## About the Role * 7+ years experience leading penetration testing, Red Team, or Purple Team operations within DoD or federal environments. * Strong understanding of offensive security methodologies, adversary emulation, and penetration testing frameworks. * Experience with network, web application, Active Directory, cloud, and endpoint security assessments. * Knowledge of MITRE ATT&CK, NIST Cybersecurity Framework, and DoD cyber operations. * Familiarity with common penetration testing and security assessment tools (e.g., Cobalt Strike, Metasploit, Burp Suite, Nmap, BloodHound, Impacket, Kali Linux). * Active DoD Secret clearance * Desired certifications: CISSP, CASP+ or CCNP ## Description Founded in 2001, Indigo IT is an award winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers' technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation's Veterans. Recognized on the Inc. 5000 list of America's fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today! The Purple Team Lead / Senior Penetration Tester is responsible for planning, coordinating, and executing advanced Purple Team operations that integrate offensive security testing with defensive validation in support of an Army contract This role conducts authorized adversary emulation and penetration testing to assess the effectiveness of cybersecurity controls, improve detection capabilities, and strengthen the organization's overall security posture., * Lead and execute Purple Team engagements that combine offensive penetration testing with real-time defensive monitoring and response validation. * Plan and conduct Computer Defense Assistance Program (CDAP) missions, including Network Assistance Visits (NAV), Network Damage Assessments (NDA), and Persistent Penetration Testing (PPT). * Perform authorized network, application, and infrastructure penetration testing to identify security weaknesses and validate defensive controls. * Simulate real-world adversary tactics, techniques, and procedures (TTPs) to assess detection, response, and recovery capabilities. * Collaborate closely with Blue Team, Cyber Threat Intelligence (CTI), and incident response personnel to validate security monitoring, detection rules, and response procedures. * Develop detailed technical findings, risk assessments, and remediation recommendations following each assessment. * Ensure all testing activities are conducted in accordance with approved Rules of Engagement (ROE), Army regulations, and applicable DoD cybersecurity policies. * Mentor junior cybersecurity personnel and contribute to the continuous improvement of Purple Team methodologies, tools, and operational procedures. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Prototyping with Hardware and the Web](https://www.wearedevelopers.com/videos/651-prototyping-with-hardware-and-the-web) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)