> Markdown version of [/jobs/ext/2599753-cyber-threat-emulation-operator-lead](https://www.wearedevelopers.com/jobs/ext/2599753-cyber-threat-emulation-operator-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Emulation Operator, Lead - **Company:** Toyota Motor Sales, U.S.A., Inc. - **Location:** Plano, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Cyber Security, Emulators, Team Foundation Server, Red Team (Cyber Security), Data Streaming, Large Language Models, Multi-Agent Systems, Mitre Att&ck, Cyber Threat Analysis, Purple Team (Cyber Security), Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.juju.com/job/00000000glspg3 ## About the Role Toyota Financial Services (TFS) Information Security is seeking a passionate and highly motivated **Cyber Threat Emulation Lead** to build the next generation of threat emulation capabilities for a global enterprise. This is a hands-on technical opportunity for an experienced offensive security practitioner who wants to develop new capabilities, not simply operate an existing red team program. You will design and execute sophisticated adversary simulations while building AI-assisted and agentic tooling that changes how offensive security testing is performed. You will have the opportunity to experiment with emerging attack techniques, develop custom tooling, orchestrate multi-stage attack workflows, and apply artificial intelligence to increase the speed, adaptability, and scale of threat emulation., + Extensive experience in red teaming, adversary simulation, penetration testing, or offensive security. + Demonstrated ability to plan and lead complex, end-to-end security engagements in an enterprise environment. + Strong knowledge of modern attack techniques across identity, endpoints, networks, cloud platforms, applications, AI, and security infrastructure. + Hands-on experience developing offensive security tooling, automation, or agentic workflows. + Ability to communicate complex technical findings clearly to both technical and non-technical audiences. + Sound judgment, integrity, and familiarity with the governance and operational safeguards required when conducting offensive security activity. + Bachelor's Degree from an accredited institution, or equivalent experience Added bonus if you have + Relevant security certification (CRTO, OSCP, OSWE, CISSP) + Familiarity with security frameworks for attack (MITRE ATT&CK, Cyber Kill Chain), threat modeling (STRIDE, CVSS), and guidance (NIST, PCI). + Understanding of regulatory issuances, such as CFPB, GLBA and SOX, and their applicability to technologies, applications and privacy laws (GDPR & CCPA) and other legal and compliance privacy and information security requirements. + Advanced degree with a concentration in an IT related area. ## Description This role will help define the technical direction of the TFS threat emulation capability while remaining close to the keyboard. Working across the global TFS Group companies, you will touch complex enterprise, cloud, identity, application, and AI-enabled environments, to challenge real security controls and work directly with defenders to measurably improve them. This role is suited to an operator who enjoys researching emerging tradecraft, building tools, testing ideas in realistic environments, and turning successful prototypes into repeatable offensive security capabilities. What you'll be doing + Design and execute end-to-end red team and control test engagements that reproduce realistic adversary behaviors across identity, endpoint, network, application, cloud, container, and AI-enabled environments. + Develop custom offensive security tooling and reusable attack capabilities rather than relying exclusively on commercial testing platforms. + Build AI-assisted and agentic workflows for reconnaissance, attack-path discovery, campaign planning, vulnerability analysis, payload development, control validation, and post-exploitation emulation. + Engineer safe multi-agent systems capable of adapting attack-paths, interpreting results, and coordinating multi-stage adversary simulations at speed and scale. + Integrate large language models with internal telemetry and threat intelligence to prioritize and drive offensive security workflows. + Test AI-enabled applications and agentic systems, including model interfaces, retrieval pipelines, tool integrations, authorization boundaries, data flows, and indirect prompt-injection paths. + Work directly with SOC analysts, detection engineers, incident responders, and threat intelligence analysts to break, tune, retest, and improve security controls through purple team exercises. + Stay current on global cyber trends and attack techniques. Propose new research directions by applying relevant insights to the Toyota environment. + Mentor other offensive security practitioners while remaining actively involved in research, tooling development, and engagement execution. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Prototyping with Hardware and the Web](https://www.wearedevelopers.com/videos/651-prototyping-with-hardware-and-the-web) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)