Cyber Threat Emulation Operator, Lead
Toyota North America
- Location
- Plano, Texas, 75024
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Posted
- 20h ago
About this role
Overview
Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us. An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment. Toyota does not offer support or sponsorship of job applicants for employment-based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration-related employment (e.g., H-1B, O-1, E-3, H-1B1, TN, F-1 OPT, F-1 STEM OPT, F-1 CPT, ‘job flexibility benefits’ [also known as I-140 or Adjustment of Status portability], etc.) now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future. Who we’re looking for Toyota Financial Services (TFS) Information Security is seeking a passionate and highly motivated Cyber Threat Emulation Lead to build the next generation of threat emulation capabilities for a global enterprise. This is a hands-on technical opportunity for an experienced offensive security practitioner who wants to develop new capabilities, not simply operate an existing red team program. You will design and execute sophisticated adversary simulations while building AI-assisted and agentic tooling that changes how offensive security testing is performed. You will have the opportunity to experiment with emerging attack techniques, develop custom tooling, orchestrate multi-stage attack workflows, and apply artificial intelligence to increase the speed, adaptability, and scale of threat emulation. This role will help define the technical direction of the TFS threat emulation capability while remaining close to the keyboard. Working across the global TFS Group companies, you will touch complex enterprise, cloud, identity, application, and AI-enabled environments, to challenge real security controls and work directly with defenders to measurably improve them. This role is suited to an operator who enjoys researching emerging tradecraft, building tools, testing ideas in realistic environments, and turning successful prototypes into repeatable offensive security capabilities. What you’ll be doing Design and execute end-to-end red team and control test engagements that reproduce realistic adversary behaviors across identity, endpoint, network, application, cloud, container, and AI-enabled environments. Develop custom offensive security tooling and reusable attack capabilities rather than relying exclusively on commercial testing platforms. Build AI-assisted and agentic workflows for reconnaissance, attack-path discovery, campaign planning, vulnerability analysis, payload development, control validation, and post-exploitation emulation. Engineer safe multi-agent systems capable of adapting attack-paths, interpreting results, and coordinating multi-stage adversary simulations at speed and scale. Integrate large language models with internal telemetry and threat intelligence to prioritize and drive offensive security workflows. Test AI-enabled applications and agentic systems, including model interfaces, retrieval pipelines, tool integrations, authorization boundaries, data flows, and indirect prompt-injection paths. Work directly with SOC analysts, detection engineers,