Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Cyber Security Threat Management Associate Director

Yesterday Chennai, India

Job Description

Are you ready to make an impact at DTCC?

Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).


The Impact you will have in this role:

The Associate Director of Breach and Attack Simulation (BAS) lead the strategy, design, execution, and continuous maturation of DTCC's adversary simulation and security control validation program. This role combines offensive security expertise, leadership, and cross-functional coordination to emulate real-world threat behaviors, validate preventive and detective controls, identify detection and response gaps, and drive measurable improvements in cyber resilience across on-premises, cloud, and hybrid environments.

Your Primary Responsibilities:

  • Lead the Breach and Attack Simulation program, including strategy, roadmap, operating model, execution standards, and measurable success criteria.
  • Design and execute realistic adversary emulation scenarios that validate security controls against current threat behaviors and organizational risk priorities.
  • Map simulation activities and findings to MITRE ATT&CK and other relevant frameworks to support consistent reporting, prioritization, and control coverage analysis.
  • Partner with SIEM, SOC, threat intelligence, endpoint, network, cloud, and security engineering teams to improve detection coverage, response readiness, and control effectiveness.
  • Identify, assess, document, and track remediation of control gaps discovered through BAS exercises, red team collaboration, purple team engagements, and continuous validation activities.
  • Oversee BAS platform use-cases, automation, scenario development, execution scheduling, test safety controls, and evidence collection.
  • Translate threat intelligence, business risks, and control requirements into repeatable simulation scenarios that safely test enterprise defenses.
  • Develop executive-ready reports, metrics, and risk narratives that communicate control performance, detection gaps, remediation progress, and cyber resilience improvements.
  • Establish actionable metrics and risk thresholds to measure BAS program effectiveness, detection maturity, control coverage, and remediation outcomes.
  • Coordinate purple team activities to ensure simulation findings are converted into improved detections, response playbooks, tuning actions, and control enhancements.
  • Provide leadership, coaching, and technical direction to BAS engineers and cross-functional contributors supporting adversary simulation activities.
  • Manage stakeholder engagement, including requirements gathering, exercise scoping, risk approvals, communications, and post-exercise readouts.
  • Ensure simulation activities are conducted safely, ethically, and in alignment with approved rules of engagement, change management, and operational risk requirements.
  • Build strong relationships across technology, cybersecurity, risk, compliance, audit, and business stakeholders to drive remediation accountability and program adoption.
  • Support audit, regulatory, and control assurance requests by providing evidence of security control validation, remediation tracking, and program governance.
  • Continuously improve BAS processes, procedures, playbooks, templates, and reporting standards to increase repeatability, scalability, and operational maturity.
  • Stay current with adversary tactics, techniques, and procedures, emerging attack trends, and BAS industry practices to inform program priorities.
  • Contribute to cybersecurity strategy, control lifecycle activities, and enterprise resilience initiatives related to threat-informed defense validation.
  • Fulfill additional cybersecurity engineering, threat defense, control validation, and special project responsibilities as assigned.

Want more jobs like this?

Get Management jobs in Chennai, India delivered to your inbox every week.

Job alert subscription


Qualifications:

  • Minimum of 6 years of related experience
  • Bachelor's degree preferred or equivalent experience


Talents Needed for Success:

  • At least 10 years of cybersecurity experience, including offensive security, security engineering, incident response, detection engineering, or control validation responsibilities.
  • Minimum 5 years of leadership or program ownership experience in breach and attack simulation, red team, purple team, threat defense, or security control assurance programs.
  • Bachelor's degree in computer science, cybersecurity, information technology, engineering, or a related discipline; equivalent experience may be considered.
  • Relevant certifications such as CISSP, OSCP, OSCE, GPEN, GCIH, GCIA, CRTO, CEH, CISM, or cloud security certifications are preferred.
  • Deep expertise in Breach and Attack Simulation, adversary emulation, red team operations, purple team collaboration, and continuous security control validation.
  • Strong understanding of MITRE ATT&CK, cyber kill chain concepts, threat-informed defense, detection engineering, and control coverage assessment.
  • Hands-on experience with BAS platforms, SIEM technologies, EDR/XDR tools, SOAR workflows, vulnerability management, cloud security, and security telemetry sources.
  • Knowledge of attacker tactics, techniques, and procedures across identity, endpoint, network, application, cloud, and data platforms.
  • Ability to write and review test plans, rules of engagement, attack narratives, remediation plans, executive summaries, technical reports, and control assurance evidence.
  • Strong leadership, stakeholder management, communication, project management, and executive presentation skills.


Actual salary is determined based on the role, location, individual experience, skills, and other considerations.We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

About Us

With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 20 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC's subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC's Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually. To learn more, please visit us at www.dtcc.com or connect with us on LinkedIn , X , YouTube , Facebook and Instagram .

DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you'll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It's the chance to make a difference at a company that's truly one of a kind.

Learn more about Clearance and Settlement by clicking here .

About the Team

Our Risk Management teams work to protect the safety and soundness of our systems and are responsible for identifying, managing, measuring and mitigating a spectrum of key risk types including credit, market, liquidity, systemic, operational and technology in all existing and new products, activities, processes and systems.

The Technology Risk Management department is responsible for setting strategic direction in the areas of IT Risk and Information Security. They are accountable for maintaining DTCC's corporate security policies and control standards and acting as an operational arm for monitoring threat intelligence.

Client-provided location(s): Chennai, India
Job ID: DTCC-214048
Employment Type: FULL_TIME
Posted: 2026-07-21T20:00:42

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • FSA
    • HSA With Employer Contribution
    • Long-Term Disability
    • HSA
    • Pet Insurance
    • Mental Health Benefits
  • Parental Benefits

    • On-site/Nearby Childcare
    • Adoption Assistance Program
    • Family Support Resources
    • Birth Parent or Maternity Leave
    • Non-Birth Parent or Paternity Leave
    • Return-to-Work Program
  • Work Flexibility

    • Hybrid Work Opportunities
    • Work-From-Home Stipend
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • On-Site Cafeteria
    • Commuter Benefits Program
    • Company Outings
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
    • Volunteer Time Off
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Financial Counseling
    • Pension
  • Professional Development

    • Work Visa Sponsorship
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Tuition Reimbursement
    • Learning and Development Stipend
    • Promote From Within
    • Mentor Program
    • Shadowing Opportunities
    • Access to Online Courses
    • Lunch and Learns
    • Internship Program
    • Professional Coaching
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)
    • Unconscious Bias Training