Job Description:
About the job
Cyber Defence
Within Group Security, the Cyber Defense department provides the entities and markets with first line of defense services. Under Cyber Defense, Security Operations Center (Security Operations Centre) is designed to prevent, detect, and react to cyber threats.
Position Main activities
Security Operations Center (SOC) delivers the following capabilities to the AXA entities around the globe: Security Incident Detection, Threat Hunting, Security Incident Response and Threat Intelligence.
The SOC Purple Team Expert is a senior, hands-on practitioner who brings offensive and defensive teams together to measurably improve prevention, telemetry, detection, investigation, and response.
Main missions
Your responsibilities include:
Threat-led exercise planning: Translate threat intelligence, recent incidents, material business risks, and detection-coverage gaps into prioritized hypotheses, exercise objectives, rules of engagement, and measurable success criteria.-
Adversary emulation and control validation: Design and execute safe, authorized campaigns and atomic tests across endpoint, identity, email, network, and cloud attack surfaces. Emulate relevant adversary behaviors and map activity to MITRE ATT&CK techniques.
-
Detection engineering partnership: Work directly with detection engineers and threat hunters to validate telemetry, create and tune analytics, reduce blind spots and false negatives, and verify the quality of KQL queries, correlation rules, and behavioral detections.
-
End-to-end SOC readiness: Assess whether alerts are generated, enriched, triaged, escalated, investigated, contained, and documented as intended. Exercise both technical controls and operational procedures, including automated response playbooks.
-
Remediation and re-testing: Record evidence and root causes, agree practical actions with control owners, prioritize findings by threat relevance and business impact, track closure, and independently re-test until the expected outcome is demonstrated.
-
Automation and capability development: Develop reusable test content, telemetry replay, orchestration, reporting, and platform integrations using Python, PowerShell, Bash, APIs, version control, and CI/CD practices.
-
Measurement and reporting: Maintain ATT&CK-aligned coverage views and report on control performance, detection pass rate, time to validate priority TTPs, remediation progress, and recurring gaps. Communicate technical evidence and risk clearly to senior stakeholders.
-
Collaboration and mentoring: Facilitate purple-team workshops, after-action reviews, and knowledge-sharing sessions. Coach SOC analysts and engineers in adversary behavior, test design, evidence collection, and sustainable detection improvement
Expected skills & experience
We are looking for someone with the following experience and skills:
Experience
-
At least 5 years of hands-on experience across offensive security, adversary emulation, penetration testing, detection engineering, threat hunting, incident response, or closely related disciplines.
-
At least 3 years of practical red-team or purple-team experience, including planning and safely executing threat-led exercises in enterprise environments.
-
Demonstrated experience turning test results into improved telemetry, detections, investigation procedures, response playbooks, and validated remediation.
-
Experience working with distributed teams and stakeholders in a large, regulated, or multi-entity organization is strongly preferred.
Education
-
University degree in information security, computer science, engineering, or an equivalent combination of professional training and relevant work experience.
Technical skills
-
Adversary tradecraft: Strong knowledge of attack paths and post-exploitation behaviors across Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, networks, and cloud services.
-
Threat-informed defense: Deep working knowledge of MITRE ATT&CK and the ability to convert threat intelligence into realistic, scoped, and measurable test scenarios.
-
SOC technologies: Proficiency with SIEM, EDR/XDR, SOAR, network security monitoring, email security, identity telemetry, and cloud security logging. Microsoft Sentinel, Defender XDR, and Kusto Query Language (KQL) expertise are strongly preferred.
-
Emulation frameworks: Hands-on experience with adversary-emulation, breach-and-attack simulation, command-and-control, and atomic testing frameworks. Ability to select the lightest safe technique that satisfies the test objective.
-
Detection validation: Ability to trace expected telemetry from source to analytics and analyst workflow, identify collection and parsing defects, validate rule logic, and distinguish control failure from test failure.
-
Engineering and automation: Advanced scripting in Python and working proficiency in PowerShell and/or Bash; experience with APIs, Git, CI/CD, infrastructure or content as code, and structured test data.
-
Analysis and communication: Ability to explain complex attack chains, control gaps, and business impact through concise reports, clear visual evidence, and practical remediation guidance.
Soft skills / transversal skills
-
Collaborative mindset and the credibility to work constructively with SOC analysts, detection engineers, incident responders, threat intelligence teams, platform owners, and technical control owners.
-
Strong analytical judgment and problem-solving skills, including the ability to troubleshoot ambiguous failures and prioritize work by risk and evidence.
-
Ability to lead work independently while contributing actively to a fast-paced, international, and multidisciplinary team.
-
Excellent written and verbal communication skills; fluent professional English is required.
-
Relevant offensive-security, incident-response, threat-hunting, or cloud-security certifications such as GCDA/GCIH/GPEN, OSEP/OSCP+, CRTO or equivalent practical credentials.
-
Experience with threat-intelligence-led testing methodologies such as TIBER-EU, CBEST, or comparable regulated-sector frameworks.
-
Experience developing or integrating internal adversary-emulation platforms, validation pipelines, or detection-as-code repositories.
-
Knowledge of security-control frameworks and purple-team measurement approaches, including ATT&CK coverage quality rather than technique-count metrics alone.
What we offer
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.
About the entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
-
State-of-the-art Data Technology to drive customer experience
-
State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
-
High-Performing Global Team for stronger partnerships with AXA entities
About AXA
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.