yoinka

Manager, Threat (Red Team)

Coca-Cola

US - GA - AtlantaMidH-1B sponsor company
Sign in to applyVerified 1h ago
Location
US - GA - Atlanta
Work model
On-Site
Level
Mid
H-1B history
3 approvals (FY2023)
Posted
15h ago

Skills

Cybersecurity

About this role

Overview

The Manager, Threat Simulation & Red Team is The Coca-Cola Company's hands-on operator for adversary simulation, breach and attack simulation (BAS), and deception technologies. This role tests the Company's detection and response capabilities by emulating real-world adversary behavior, running continuous attack simulations, and deploying deception technologies that expose gaps in the Company's defensive posture. The goal is not traditional penetration testing or application security, but rather   validating   that the SOC, detection engineering, and incident response teams can see, catch, and stop real attacks.   Reporting to the Senior Manager, Cyber Threat, this is an individual-contributor role focused on deep technical execution. The Manager designs and runs threat simulation exercises mapped to real adversary tradecraft,   operates   breach and attack simulation platforms, deploys and manages honeypots and honeytokens, and delivers clear, evidence-based assessments of defensive gaps. The role partners closely with Cybersecurity Operations, Detection Engineering, and Threat Intelligence to turn simulation findings into measurable improvements in the Company's ability to detect and respond to threats.

Key Responsibilities

Adversary Simulation & Purple Teaming   Design and execute adversary simulation exercises that test the Company's detection, alerting, and response capabilities against realistic attack scenarios.   Develop threat simulation scenarios mapped to MITRE ATT&CK techniques and informed by current threat intelligence on adversaries relevant to the Company.   Conduct purple team exercises in partnership with SOC and detection engineering teams, collaboratively   identifying   detection gaps and validating improvements.   Simulate full attack chains, including initial access, lateral movement, privilege escalation, persistence, and data exfiltration, to test end-to-end defensive coverage.   Breach and Attack Simulation (BAS)   Operate and   optimize   breach and attack simulation platforms (such as Mandiant Security Validation,   AttackIQ , or   SafeBreach ) to provide continuous, automated validation of security controls.   Define and   maintain   a library of attack simulations aligned to the Company's threat profile and detection priorities.   Analyze BAS results to   identify   detection gaps, control failures, and configuration drift, and work with detection engineering to remediate findings.   Produce regular reporting on control effectiveness, detection coverage, and trends over time.   Deception Technology   Design, deploy, and manage deception technologies, including honeypots, honeytokens, and decoy assets, across the Company's environment.   Integrate deception alerts into SOC workflows, ensuring   timely   triage and investigation of deception-triggered events.   Continuously evolve the deception program to reflect changes in the Company's environment, adversary behavior, and   detection   priorities.   Detection Gap Analysis & Improvement   Maintain a structured view of the Company's detection coverage mapped to MITRE ATT&CK,   identifying   gaps and prioritizing improvements.   Partner with Detection Engineering and Cybersecurity Operations to translate simulation findings into new or improved detection rules, playbooks, and response procedures.   Track remediation of detection gaps and   validate   that improvements are effective through follow-up testing.   Reporting & Continuous Improvement   Produce clear, evidence-based reports on simulation results, detection coverage, and defensive gap trends for Cyber Threat leadership and the CISO.   Continuously improve simulation methodologies, tooling, and processes based on evolving adversary tradecraft and lessons learned.   Stay current with industry developments in adversary simulation, BAS, deception technology, and detection engineering.   Qualifications

Manager, Threat (Red Team) at Coca-Cola, US - GA - Atlanta | Yoinka