Skip to main content
KOHO

Senior Purple Team Engineer

RemoteCanada, Türkiye only
Published
Role
Security
Experience
Senior
Employment
Full-time
CAD 160k–CAD 190k/yr
Check eligibility

Open to CA, TR only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer in Canada for incident response, adversarial simulations, DFIR, and deception engineering. Must have hands-on AWS, MITRE ATT&CK/cyber kill chain knowledge, and experience building deception programs and operating offensive security techniques.

Core skills

AWSMITRE ATT&CK

What you'll do

  • Own and lead incident response readiness across KOHO, starting with the security team through regular tabletop exercises and playbook reviews.
  • Plan and execute adversarial simulations, including scoping engagements, operating within rules of engagement, conducting offensive operations, and delivering findings that drive security improvements.
  • Expand incident response readiness across KOHO and build response playbooks for marketing, data, legal, people and culture, risk, and other teams.
  • Conduct tabletop exercises with C-level leadership to test risk acceptance and organizational limitations.
  • Document lessons learned, operational improvements, and playbook updates.
  • Execute all documented improvements.
  • Lead incident response and DFIR during cybersecurity incidents.
  • Conduct post-incident documentation to determine contributing factors and lessons learned.
  • Design and deploy internal deception assets to detect lateral movement, insider threats, and unauthorized access across KOHO's environment.
  • Build external-facing deception capabilities, including fake credentials, canary tokens embedded in customer-facing surfaces, and decoy infrastructure seeded in breach databases and other attacker-accessible surfaces.
  • Instrument deception assets to generate actionable threat intelligence and feed findings back into detection logic, playbooks, and the broader threat model.
  • Build the triage and response workflow for deception-triggered alerts into existing SOC operations, from signal to investigation to lessons learned.

What they require

  • Bachelor’s degree in computer science, technology management, or a related technical or management field.
  • Self-starter who can build programs from the ground up and build operations.
  • Hands-on experience and working understanding of AWS.
  • Experience designing and deploying deception programs covering both internal detection assets and external-facing deception infrastructure.
  • Strong knowledge of MITRE ATT&CK and the cyber kill chain.
  • Hands-on experience planning and executing adversarial simulations, including scoping engagements, defining rules of engagement, and delivering post-engagement reporting.
  • Experience operating offensive security tooling and techniques to emulate real-world threat actor behaviour.

Benefits

  • Asynchronous collaboration.
  • Flexible hours.
  • Remote-first setup built around autonomy and high trust.
  • Work-life integration.
  • Inclusive and accessible environment.

KOHO is on a mission to make financial services better for every Canadian, offering financial products designed to help users spend smart, save more, and build wealth.

Fintech

Details

Apply routeDom
CAD 160k–CAD 190k/yr