Director – Offensive Security & Assurance

Aon CorporationAtchison, KS
Remote

About The Position

The Director, Offensive Security & Assurance will lead Aon’s global offensive security and security assurance capabilities within Proactive Threat Operations (PTO). This role is responsible for proactively identifying exploitable security weaknesses, validating defensive controls against real-world adversary techniques, and driving findings through to measurable improvements in Aon’s security posture. This leader will evolve traditional penetration testing and point‑in‑time assessments toward a more continuous, threat‑informed model incorporating adversary emulation, purple teaming, attack‑path analysis, control validation, and targeted security assurance. A core objective of the role is to answer, on an ongoing basis: Can an attacker successfully exploit this path today, and if so, what are we doing to eliminate it? The Director will partner closely with Threat Intelligence, Threat Hunting, Vulnerability & Exposure Management, Applied Security Research, AC3/SOC, Security Engineering, Identity & Access Management, Cloud, application security, and broader technology teams. Success will be measured by validated risks identified, attack paths eliminated, controls improved, detections strengthened, and remediation verified — not simply the number of assessments completed or findings produced.

Requirements

  • Extensive experience (typically 8+ years) in offensive security, penetration testing, red teaming, or adversary emulation, with a strong track record leading complex security testing programs in large, global environments.
  • Demonstrated experience building and/or maturing offensive security or red‑team capabilities, including strategy, operating model, and technical roadmap.
  • Deep technical expertise across several of the following domains: endpoint security, identity and access management (including Active Directory and Entra ID), cloud platforms (e.g., Azure, AWS, GCP), SaaS, enterprise networks, web and API applications, and browser‑based attack techniques.
  • Strong familiarity with threat‑informed defense approaches and frameworks such as MITRE ATT&CK, plus experience incorporating threat intelligence into offensive testing.
  • Proven experience running purple‑team exercises and collaborating closely with SOC, threat hunting, and detection engineering teams to validate and improve detections and response.
  • Experience designing and executing attack‑path analysis and control‑validation campaigns, and translating technical findings into actionable remediation and architectural improvements.
  • Strong understanding of security governance, testing authorization, safety controls, and rules of engagement for offensive security activities in production or production‑adjacent environments.
  • Experience managing external penetration‑testing/red‑team providers and integrating third‑party assessments with internal capabilities.
  • Excellent communication skills, including the ability to synthesize complex technical risk into clear, business‑relevant reporting for senior leadership.
  • Demonstrated leadership experience building, mentoring, and developing high‑performing technical teams.
  • Bachelor’s degree in Computer Science or equivalent years of industry experience.

Nice To Haves

  • Relevant industry certifications (e.g., OSCP, OSEP, OSCE, GX‑PN, GX‑RTA, CREST, CISSP, or similar) are desirable but not required.
  • Prior experience working in or closely with global organizations and distributed teams.

Responsibilities

  • Lead the global Offensive Security & Assurance capability within Proactive Threat Operations.
  • Define the offensive security strategy, operating model, priorities, standards, and technical roadmap.
  • Evolve traditional penetration testing toward continuous adversary validation and recurring purple‑team operations.
  • Develop and maintain threat‑informed adversary emulation scenarios based on relevant threat intelligence, incidents, emerging techniques, and Aon‑specific exposures.
  • Plan, conduct, and oversee testing across endpoint, identity, Active Directory, Entra ID, cloud, SaaS, network, applications, APIs, browser, and broader enterprise attack paths.
  • Build and mature a purple‑team capability that connects offensive testing directly with AC3/SOC detection and response.
  • Partner with Threat Intelligence to translate adversary activity into realistic offensive testing scenarios.
  • Partner with Threat Hunting to identify hypotheses and attack paths that warrant proactive validation.
  • Partner with Vulnerability & Exposure Management to determine whether vulnerabilities and exposures are actually exploitable in Aon’s environment.
  • Validate whether remediation actions and compensating controls meaningfully eliminate identified attack paths.
  • Require retesting and technical evidence before material offensive‑security findings are considered closed.
  • Identify opportunities to eliminate attack paths through architecture, configuration, identity, endpoint, cloud, network, or application control changes.
  • Establish continuous control‑validation exercises around Aon’s highest‑risk attack scenarios.
  • Develop repeatable adversary‑emulation playbooks mapped to MITRE ATT&CK and observed threat behavior.
  • Improve detection engineering by providing AC3/SOC with telemetry, behaviors, techniques, and test evidence derived from offensive exercises.
  • Collaborate with Applied Security Research to develop offensive tooling, automation, testing frameworks, and novel security‑assessment techniques.
  • Maintain appropriate testing governance, authorization processes, safety controls, and rules of engagement for offensive activity.
  • Manage internal testing capabilities and external penetration‑testing/red‑team partners where required, ensuring third‑party assessments supplement internal capabilities rather than serving as the primary operating model.
  • Provide senior leadership with clear, concise reporting on exploitable risk, defensive effectiveness, remediation progress, and systemic control weaknesses.
  • Recruit, develop, and mentor offensive security practitioners and build deep technical capability within the team.

Benefits

  • a 401(k) savings plan with employer contributions
  • an employee stock purchase plan
  • consideration for long-term incentive awards at Aon’s discretion
  • medical, dental and vision insurance
  • various types of leaves of absence
  • paid time off, including 12 paid holidays throughout the calendar year
  • 15 days of paid vacation per year
  • paid sick leave as provided under state and local paid sick leave laws
  • short-term disability and optional long-term disability
  • health savings account
  • health care and dependent care reimbursement accounts
  • employee and dependent life insurance and supplemental life and AD&D insurance
  • optional personal insurance policies
  • adoption assistance
  • tuition assistance
  • commuter benefits
  • an employee assistance program that includes free counseling sessions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service