{bc}
icims

Director – Offensive Security & Assurance

Aon Corporation
Remote, USA
Full-time
Senior · 8+ years experience
Remote
USD 133000-175000 yearly / year
Discovered Today
Active DirectoryEntra IDAzureAWSGCPMITRE ATT&CK
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Active DirectoryEntra IDAzure
Smart Apply

Full Job Posting

Director, Offensive Security & Assurance

Function: Proactive Threat Operations, Cybersecurity

Role Overview

The Director, Offensive Security & Assurance will lead Aon’s global offensive security and security assurance capabilities within Proactive Threat Operations (PTO). This role is responsible for proactively identifying exploitable security weaknesses, validating defensive controls against real-world adversary techniques, and driving findings through to measurable improvements in Aon’s security posture.

This leader will evolve traditional penetration testing and point‑in‑time assessments toward a more continuous, threat‑informed model incorporating adversary emulation, purple teaming, attack‑path analysis, control validation, and targeted security assurance. A core objective of the role is to answer, on an ongoing basis: Can an attacker successfully exploit this path today, and if so, what are we doing to eliminate it?

The Director will partner closely with Threat Intelligence, Threat Hunting, Vulnerability & Exposure Management, Applied Security Research, AC3/SOC, Security Engineering, Identity & Access Management, Cloud, application security, and broader technology teams. Success will be measured by validated risks identified, attack paths eliminated, controls improved, detections strengthened, and remediation verified — not simply the number of assessments completed or findings produced.

Aon is in the business of better decisions

At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.

As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed.

What the day will look like

Lead the global Offensive Security & Assurance capability within Proactive Threat Operations.

Define the offensive security strategy, operating model, priorities, standards, and technical roadmap.

Evolve traditional penetration testing toward continuous adversary validation and recurring purple‑team operations.

Develop and maintain threat‑informed adversary emulation scenarios based on relevant threat intelligence, incidents, emerging techniques, and Aon‑specific exposures.

Plan, conduct, and oversee testing across endpoint, identity, Active Directory, Entra ID, cloud, SaaS, network, applications, APIs, browser, and broader enterprise attack paths.

Build and mature a purple‑team capability that connects offensive testing directly with AC3/SOC detection and response.

Partner with Threat Intelligence to translate adversary activity into realistic offensive testing scenarios.

Partner with Threat Hunting to identify hypotheses and attack paths that warrant proactive validation.

Partner with Vulnerability & Exposure Management to determine whether vulnerabilities and exposures are actually exploitable in Aon’s environment.

Validate whether remediation actions and compensating controls meaningfully eliminate identified attack paths.

Require retesting and technical evidence before material offensive‑security findings are considered closed.

Identify opportunities to eliminate attack paths through architecture, configuration, identity, endpoint, cloud, network, or application control changes.

Establish continuous control‑validation exercises around Aon’s highest‑risk attack scenarios.

Develop repeatable adversary‑emulation playbooks mapped to MITRE ATT&CK and observed threat behavior.

Improve detection engineering by providing AC3/SOC with telemetry, behaviors, techniques, and test evidence derived from offensive exercises.

Collaborate with Applied Security Research to develop offensive tooling, automation, testing frameworks, and novel security‑assessment techniques.

Maintain appropriate testing governance, authorization processes, safety controls, and rules of engagement for offensive activity.

Manage internal testing capabilities and external penetration‑testing/red‑team partners where required, ensuring third‑party assessments supplement internal capabilities rather than serving as the primary operating model.

Provide senior leadership with clear, concise reporting on exploitable risk, defensive effectiveness, remediation progress, and systemic control weaknesses.

Recruit, develop, and mentor offensive security practitioners and build deep technical capability within the team.

How This Opportunity Is Different

This is more than a traditional offensive security leadership role. You'll lead the evolution of Aon's global offensive security program, moving beyond point-in-time assessments to continuous adversary validation, purple teaming, and attack-path elimination. Working alongside leaders across Threat Intelligence, SOC, Security Engineering, Cloud, Identity, and Application Security, you'll directly influence how Aon identifies, validates, and reduces cyber risk at scale while building a world-class team and capability.

Skills and Experience

  • Extensive experience (typically 8+ years) in offensive security, penetration testing, red teaming, or adversary emulation, with a strong track record leading complex security testing programs in large, global environments.
  • Demonstrated experience building and/or maturing offensive security or red‑team capabilities, including strategy, operating model, and technical roadmap.
  • Deep technical expertise across several of the following domains: endpoint security, identity and access management (including Active Directory and Entra ID), cloud platforms (e.g., Azure, AWS, GCP), SaaS, enterprise networks, web and API applications, and browser‑based attack techniques.
  • Strong familiarity with threat‑informed defense approaches and frameworks such as MITRE ATT&CK, plus experience incorporating threat intelligence into offensive testing.
  • Proven experience running purple‑team exercises and collaborating closely with SOC, threat hunting, and detection engineering teams to validate and improve detections and response.
  • Experience designing and executing attack‑path analysis and control‑validation campaigns, and translating technical findings into actionable remediation and architectural improvements.
  • Strong understanding of security governance, testing authorization, safety controls, and rules of engagement for offensive security activities in production or production‑adjacent environments.
  • Experience managing external penetration‑testing/red‑team providers and integrating third‑party assessments with internal capabilities.
  • Excellent communication skills, including the ability to synthesize complex technical risk into clear, business‑relevant reporting for senior leadership.
  • Demonstrated leadership experience building, mentoring, and developing high‑performing technical teams.

Preferred Qualifications

  • Relevant industry certifications (e.g., OSCP, OSEP, OSCE, GX‑PN, GX‑RTA, CREST, CISSP, or similar) are desirable but not required.
  • Prior experience working in or closely with global organizations and distributed teams.
  • Education : Bachelor’s degree in Computer Science or equivalent years of industry experience.
  • For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.
  • Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate.
  • Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
  • Pay Transparency Laws:
  • The salary range for this position (intended for U.S. applicants) is [$133000 to $175000] annually. The actual salary will vary based on applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant’s geographic location.
  • A summary of all the benefits offered for this position:
  • Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to: a 401(k) savings plan with employer contributions; an employee stock purchase plan; consideration for long-term incentive awards at Aon’s discretion; medical, dental and vision insurance, various types of leaves of absence, paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, paid sick leave as provided under state and local paid sick leave laws, short-term disability and optional long-term disability, health savings account, health care and dependent care reimbursement accounts, employee and dependent life insurance and supplemental life and AD&D insurance; optional personal insurance policies, adoption assistance, tuition assistance, commuter benefits, and an employee assistance p rogram that includes free counseling sessions. Eligibility for benefits is governed by the applicable plan documents and policies.
  • #LI-NS1
  • #LI-REMOTE

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Aon Corporation