Director – Offensive Security & Assurance
Aon - Utah, United States
Hiring: Director – Offensive Security & Assurance Company: Aon Location: Utah, United States Job Posted Time: 2026-09-17 00:40:22 Employment Type: Full-time Target Skills & Keywords : AWS, Azure, GCP, Penetration Testing, SOC, SaaS, TestNG About the job Experience: •Extensive experience (typically 8+ years) in offensive security, penetration testing, red teaming, or adversary emulation, with a strong track record leading complex security testing programs in large, global environments. •Demonstrated experience building and/or maturing offensive security or red‑team capabilities, including strategy, operating model, and technical roadmap. •Deep technical expertise across several of the following domains: endpoint security, identity and access management (including Active Directory and Entra ID), cloud platforms (e.g., Azure, AWS, GCP), SaaS, enterprise networks, web and API applications, and browser‑based attack techniques. •Strong familiarity with threat‑informed defense approaches and frameworks such as MITRE ATT&CK, plus experience incorporating threat intelligence into offensive testing. •Proven experience running purple‑team exercises and collaborating closely with SOC, threat hunting, and detection engineering teams to validate and improve detections and response. Required Skills: •Aon is in the business of better decisions •As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed. •What The Day Will Look Like •Lead the global Offensive Security & Assurance capability within Proactive Threat Operations. •Define the offensive security strategy, operating model, priorities, standards, and technical roadmap. •Evolve traditional penetration testing toward continuous adversary validation and recurring purple‑team operations. •Develop and maintain threat‑informed adversary emulation scenarios based on relevant threat intelligence, incidents, emerging techniques, and Aon‑specific exposures. •Plan, conduct, and oversee testing across endpoint, identity, Active Directory, Entra ID, cloud, SaaS, network, applications, APIs, browser, and broader enterprise attack paths. Qualifications: •Relevant industry certifications (e.g., OSCP, OSEP, OSCE, GX‑PN, GX‑RTA, CREST, CISSP, or similar) are desirable but not required. •Prior experience working in or closely with global organizations and distributed teams. •Bachelor’s degree in Computer Science or equivalent years of industry experience. •For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances. •Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate. •Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time. •The salary range for this position (intended for U.S. applicants) is [$133000 to $175000] annually. The actual salary will vary based on applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant’s geographic location. •A summary of all the benefits offered for this position: Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!