Sherwin-Williams

Red Team Lead

Sherwin-Williams  •  Cleveland, OH (Remote)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

The Threat Management Red Team Lead is a cybersecurity leader responsible for defining, building, and leading the enterprise adversary emulation program. This role establishes strategy aligned to business risk and threat intelligence while overseeing execution of complex, end-to-end attack simulations across the enterprise.

The Red Team Lead ensures the organization’s security controls are effectively validated against realistic threat scenarios and drives measurable improvements in detection and response capabilities. This role requires a blend of deep technical expertise, program leadership, and strong cross-functional coordination across SOC, Threat Intelligence, Detection Engineering, and Application Security.

This role reports directly to the Senior Manager – Threat Management

  • Define and lead the enterprise adversary simulation strategy aligned to business risk, threat intelligence, and emerging threats.
  • Build, mature, and continuously improve the Red Team program, including methodologies, tooling, and engagement frameworks.
  • Oversee planning and execution of complex attack scenarios across enterprise environments, ensuring realistic end-to-end adversary simulation.
  • Validate effectiveness of preventive, detective, and response controls through full attack chain execution.
  • Drive cross-team collaboration with SOC, Threat Intelligence, Detection Engineering, Application Security, and Security Champions to remediate gaps.
  • Lead purple team exercises to strengthen detection and response capabilities.
  • Ensure findings are tracked, prioritized by risk, remediated, and retested for validation.
  • Translate threat intelligence and business risk into prioritized adversary scenarios.
  • Deliver clear, risk-based reporting and metrics to leadership, highlighting control gaps and improvement areas.
  • Define and track key performance indicators (KPIs) to measure program effectiveness and security posture improvements.
  • Oversee selection, implementation, and operation of red team tooling and infrastructure.
  • Provide technical leadership and mentorship to Red Team operators.
  • Establish standards for tradecraft, documentation, and operational rigor.
  • Continuously evaluate and integrate new tools, techniques, and adversary tradecraft.

This is a remote position.

This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.

Job duties include contact with other employees and access confidential and proprietary information and/or other items of value, and such access may be supervised or unsupervised. The Company therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company’s staff, employees, and business relationships.

Education and Experience

Required:

  • Bachelor’s Degree (or foreign equivalent) or in lieu of a degree, at least 12 years in experience in the field of Information Technology or Business (work experience or a combination of education and work experience in the field of Information Technology or Business)
  • Relevant certifications such as OSCP, OSEP, CRTO, GXPN, GPEN, CISSP or similar are preferred.
  • 8+ years IT/Cybersecurity experience.
  • Proven experience leading or building a Red Team or adversary simulation program.
  • Strong expertise in adversary tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
  • Extensive experience planning and executing advanced red team operations in enterprise environments.
  • Experience coordinating across multiple security disciplines including SOC, Detection Engineering, and Incident Response.
  • Strong understanding of enterprise security architecture including identity, endpoints, networks, and cloud platforms.
  • Experience with full attack lifecycle including social engineering, lateral movement, persistence, and ransomware scenarios.
  • Strong communication skills with the ability to translate technical findings into business risk.
  • Must be legally authorized to work in the United States without company sponsorship
  • Must be at least eighteen (18) years of age

Preferred:

  • Experience with command-and-control frameworks (e.g., Sliver, Cobalt Strike, Mythic, or similar).
  • Familiarity with identity and Active Directory attack tooling (e.g., BloodHound, Impacket, Mimikatz).
  • Experience with cloud attack techniques and platforms.
  • Experience building and managing red team infrastructure and tooling ecosystems.
  • Exposure to adversary emulation validation platforms (e.g., SafeBreach).
  • Experience leading purple team or detection validation exercises.

At Sherwin-Williams, our purpose is to inspire and improve the world by coloring and protecting what matters. Our paints, coatings and innovative solutions make the places and spaces in our world brighter and stronger. Your skills, talent and passion make it possible to live this purpose, and for customers and our business to achieve great results. Sherwin-Williams is a place that takes its stability, growth and momentum and translates it to possibility for our people. Our people are behind the strength of our success, and we invest and support you in:

Life … with rewards, benefits and the flexibility to enhance your health and well-being

Career … with opportunities to learn, develop new skills and grow your contribution

Connection … with an inclusive team and commitment to our own and broader communities

It's all here for you... let's Create Your Possible

At Sherwin-Williams, part of our mission is to help our employees and their families live healthier, save smarter and feel better. This starts with a wide range of world-class benefits designed for you. From retirement to health care, from total well-being to your daily commute—it matters to us. A general description of benefits offered can be found at http://www.myswbenefits.com/. Click on “Candidates” to view benefit offerings that you may be eligible for if you are hired as a Sherwin-Williams employee.

Compensation decisions are dependent on the facts and circumstances of each case and will impact where actual compensation may fall within the stated wage range. The wage range listed for this role takes into account the wide range of factors considered in making compensation decisions including skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. The wage range, other compensation, and benefits information listed is accurate as of the date of this posting. The Company reserves the right to modify this information at any time, with or without notice, subject to applicable law.

Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable federal, state, and local laws including with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act where applicable.

Sherwin-Williams is proud to be an Equal Employment Opportunity employer.  All qualified candidates will receive consideration for employment and will not be discriminated against based on race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, pregnancy, genetic information, creed, marital status or any other consideration prohibited by law or by contract.

As a VEVRAA Federal Contractor, Sherwin-Williams requests state and local employment services delivery systems to provide priority referral of Protected Veterans.

Please be aware, Sherwin-Williams recruiting team members will never request a candidate to provide a payment, ask for financial information, or sensitive personal information like national identification numbers, date of birth, or bank account numbers during the application process.

Sherwin-Williams

About Sherwin-Williams

Our mission began more than 150 years ago in 1866 when Henry Sherwin and Edward Williams founded the company in Cleveland, Ohio. The duo went on to shape an industry and create a global legacy. That legacy continues on today as we look ahead and continue to innovate our future. With stores, distribution centers and facilities spanning the globe, we're able to deliver the best in paints, coatings and related products to the world. From our headquarters to our 130 distribution centers and more than 5,000 retail locations, we continue to grow in new and exciting ways.

Here, there's no one path to success. Our 64,000+ employees are diverse, innovative and passionate. Our employees worldwide bring their energy and unique perspectives to each new day. We believe in careers that grow with you and open up new opportunities. With the support of a global team, you can innovate, grow and discover a career where you can thrive and Create Your 𝗣𝗼𝘀𝘀𝗶𝗯𝗹𝗲™.

Equal Opportunity Employer of all protected statuses, including disability and veteran.

Industry
Chemicals & Materials
Company Size
10,000+ employees
Headquarters
Cleveland, OH
Year Founded
Unknown
Social Media