3rd Party Risk Management Cyber Security Purple Team Analyst

2 weeks ago


Springfield, United States Hybrid Pathways Full time
Job DescriptionJob Description

About the opportunity:

Hybrid Pathways is seeking a highly skilled and motivated Third-Party Risk Management Cyber Security Purple Team Analyst to join a dynamic team. As a Third-Party Risk Management Purple Team Analyst, you will play a crucial role in enhancing the customer’s organization's overall cybersecurity posture by integrating with the third-party risk management team to evaluate critical supply chain vendors’ real-world cyber threats, evaluating their security controls, and collaborating with both the supplier and other cyber security functions. The ideal candidate will possess a strong understanding of cyber threats, penetration testing methodologies, and defensive security strategies to be able to evaluate a vendor’s security posture. Must have a technical mindset and be a technically curious person that can be creative with solutions. 

Responsibilities:

1. Evaluate Suppliers’ Security Posture with a Purple Team Mindset

    • Identify different existing and non-existing threat intelligence sources within the organization and outside the organization to help identify the security posture of a critical supplier (e.g., threat intelligence feeds, SASE technology data, third party identity data, email reputation data, etc.).
    • Work with cross-functional teams to aggregate the data into the third-party risk management platform

2. Threat Simulation:

    • Develop realistic attack scenarios to feed the threat model for a supplier’s security posture.
    • Identify vulnerabilities to the customer from the threat model with knowledge of ethical hacking and penetration testing techniques.

3. Continuous Improvement:

  • Stay abreast of the latest cyber threats, vulnerabilities, and industry best practices.
  • Propose and implement improvements to security controls based on findings from simulations and assessments.

4. Security Assessments:

    • Conduct security assessments on various systems, applications, and infrastructure components that are related to third party suppliers within the customer’s environment.

5. Training and Knowledge Sharing:

    • Provide training and knowledge sharing sessions to the wider security team.
    • Mentor and guide junior team members in understanding advanced cyber threats and defensive strategies related to third party IT risk management.

Required Skills                                                                  

    • Proven experience in cybersecurity, including penetration testing and ethical hacking.
    • Red teaming techniques, tactics, and procedures.
    • Third party risk management experience or exposure.
    • Vulnerability assessment.
    • Hands-on experience with security tools and frameworks.
    • Strong understanding of cyber threats, attack vectors, and defensive strategies.
    • Proficiency in scripting and programming languages (e.g., Python, PowerShell).
    • Excellent communication and collaboration skills.
    • Ability to lead, influence, and make recommendations to client.

Preferred Skills

  • Proven experience in cybersecurity, including penetration testing and ethical hacking.
  • Hands-on experience with security tools and frameworks.

Preferred Education

  • Bachelor's degree in Computer Science, Information Security, or a related field. Relevant certifications (e.g., CISSP, CEH, OSCP) are a plus.

About Us:       

Hybrid Pathways is a New England-based IT professional services company that assists mid-to-large enterprises with the implementation of secure IT environments that span on-premises and public cloud platforms. Be a part of a fast-paced, growing organization focused on doing great projects for great people.    

EEO Statement:

Hybrid Pathways is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, marital status, national origin, genetics, disability, age, or veteran status. 

Powered by JazzHR

XA3b9tY8Gb



  • Springfield, United States Elevance Health Full time

    Cloud Cyber Security Analyst (Data Protection/DevOps) Location: This position will work a hybrid model (remote & office). The ideal candidate will live within 50 miles of one of our Elevance Health PulsePoint locations. The Cloud Cyber Security Analyst (Data Protection/DevOps) is responsible for providing services in support of data protection controls as...


  • Springfield, United States Transportation Security Administration Full time

    This Intelligence Operations Specialist position is located within Operations Support (OS), Intelligence & Analysis (I&A), Transportation Analysis Division (TAD), Transportation Security Administration (TSA), Department of Homeland Security (DHS). Additional duties include but are not limited to: Monitors, researches, reports, and initiates products and...


  • Springfield, United States CALIBRE Full time

    CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a Vulnerability Assessment Analyst (Mid-level) that will perform assessments of systems and networks within a Government enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. The...


  • Springfield, United States Zachary Piper Solutions Full time

    To serve the DoD Joint Operations Center (DJOC) at Ft. Meade, Maryland, Zachary Piper Solutions is looking for a Cyber Operations Analyst. We are looking for somebody who can provide situational awareness of the operational environment by utilizing operational data and cyber threat intelligence. To help protect the environment, the team is in need of...


  • Springfield, United States CALIBRE Systems Full time

    Job Description CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a Vulnerability Assessment Analyst (Mid-level) that will perform assessments of systems and networks within a Government enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local...


  • Springfield, United States CALIBRE Systems Full time

    Job Description CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a Vulnerability Assessment Analyst (Mid-level) that will perform assessments of systems and networks within a Government enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local...


  • Springfield, United States Calibre Inc Full time

    CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a Vulnerability Assessment Analyst (Mid-level) that will perform assessments of systems and networks within a Government enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. The...


  • Springfield, United States Calibre Inc Full time

    CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a Vulnerability Assessment Analyst (Mid-level) that will perform assessments of systems and networks within a Government enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. The...

  • FedRAMP SOC Analyst

    3 days ago


    Springfield, United States Elevance Health Full time

    FedRAMP SOC Analyst Location: This position will work a hybrid model (remote & office). The ideal candidate will live within 50 miles of one of our Elevance Health PulsePoint locations. The FedRAMP SOC Analyst will be responsible for providing the first line of defense against cyber threats. Your core focus will be cybersecurity operations, incident...


  • Springfield, United States Strategic ASI Full time

    Our client is seeking Senior Endpoint Security Engineer to join their team in either Springfield, VA, or St. Louis, MO. What You'll Get to Do: Our Endpoint Security team is rapidly growing! This is one of several New positions that we have added to the program. This is an exceptional opportunity for a TS/SCI-cleared professional to join an incredibly...


  • Springfield, Illinois, United States Transportation Security Administration Full time

    This Intelligence Operations Specialist position is located within Operations Support (OS), Intelligence & Analysis (I&A), Transportation Analysis Division (TAD), Transportation Security Administration (TSA), Department of Homeland Security (DHS).Additional duties include but are not limited to:Monitors, researches, reports, and initiates products and...


  • Springfield, United States TENICA and Associates LLC Full time

    Data Science Cyber Systems Engineer - Careers At Tenica and Associates Share with friends or Subscribe! Back To Openings Data Science Cyber Systems Engineer Department: Govt Customer-Springfield Location: Springfield, VA START YOUR APPLICATION Position Description: The Cyber Data Science Engineer provides support to the customer in the area of Cyber...


  • Springfield, United States TSA (Transportation Security Administration) Full time

    Overview Intelligence Operations Specialist (Cyber Analysis) Open & closing dates - 05/09/2024 to 05/23/2024 - Pay scale & grade - SV G - Appointment type Salary - $82,764.00 to $153,354.00 PA - Work schedule Location - Springfield, VirginiaDuties Summary - Securing Travel, Protecting People - At the Transportation Security Administration, you will...

  • Risk Analyst

    3 weeks ago


    Springfield, United States Associated Electric Cooperative Full time

    Discover a POWERful career at Associated Electric! Our organization offers challenging and rewarding work with career development and internal mobility opportunities - all within a family friendly and community centric culture. Our purpose is simple - to provide safe, reliable and affordable energy for our member-owners. At Associated Electric, one of the...

  • Program Analyst

    3 weeks ago


    Springfield, United States Transportation Security Administration Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure...


  • Springfield, United States SITEC Consulting Full time

    Job DescriptionJob DescriptionPosition Overview:Candidate will provide CSOC Tier 3 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 3 services includes malware and implant analysis, and forensic artifact handling and...


  • Springfield, United States SITEC Consulting Full time

    Job DescriptionJob DescriptionSummary:Provide CSOC Tier 3 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 3 services includes malware and implant analysis, and forensic artifact handling and analysis. The employee...


  • Springfield, United States Department Of Homeland Security Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit...


  • Springfield, Illinois, United States Department Of Homeland Security Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure and...

  • CSOS Analyst

    7 days ago


    Springfield, United States CACI International Full time

    Coordinate and implement tasks, performing analysis, and building/documenting response activities required during cyber security incident response, including but not limited to actions such as implementing containment measures, IP blocks, domain bloc Analyst, Contracts, Operations, Government, Technology, Security