ForgeApply · Job listing
Manager, Threat (Red Team)
The Coca-Cola Company
Tailor your resume for this The Coca-Cola Company job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for The Coca-Cola Company's site. Free trial, no card required.
About this role
Job Description Summary:
Overview
The Manager, Threat Simulation & Red Team is The Coca-Cola Company's hands-on operator for adversary simulation, breach and attack simulation (BAS), and deception technologies. This role tests the Company's detection and response capabilities by emulating real-world adversary behavior, running continuous attack simulations, and deploying deception technologies that expose gaps in the Company's defensive posture. The goal is not traditional penetration testing or application security, but rather validating that the SOC, detection engineering, and incident response teams can see, catch, and stop real attacks.
Reporting to the Senior Manager, Cyber Threat, this is an individual-contributor role focused on deep technical execution. The Manager designs and runs threat simulation exercises mapped to real adversary tradecraft, operates breach and attack simulation platforms, deploys and manages honeypots and honeytokens, and delivers clear, evidence-based assessments of defensive gaps. The role partners closely with Cybersecurity Operations, Detection Engineering, and Threat Intelligence to turn simulation findings into measurable improvements in the Company's ability to detect and respond to threats.
Key Responsibilities
Adversary Simulation & Purple Teaming
• Design and execute adversary simulation exercises that test the Company's detection, alerting, and response capabilities against realistic attack scenarios.
• Develop threat simulation scenarios mapped to MITRE ATT&CK techniques and informed by current threat intelligence on adversaries relevant to the Company.
• Conduct purple team exercises in partnership with SOC and detection engineering teams, collaboratively identifying detection gaps and validating improvements.
• Simulate full attack chains, including initial access, lateral movement, privilege escalation, persistence, and data exfiltration, to test end-to-end defensive coverage.
Breach and Attack Simulation (BAS)
• Operate and optimize breach and attack simulation platforms (such as Mandiant Security Validation, AttackIQ , or SafeBreach ) to provide continuous, automated validation of security controls.
• Define and maintain a library of attack simulations aligned to the Company's threat profile and detection priorities.
• Analyze BAS results to identify detection gaps, control failures, and configuration drift, and work with detection engineering to remediate findings.
• Produce regular reporting on control effectiveness, detection coverage, and trends over time.
Deception Technology
• Design, deploy, and manage deception technologies, including honeypots, honeytokens, and decoy assets, across the Company's environment.
• Integrate deception alerts into SOC workflows, ensuring timely triage and investigation of deception-triggered events.
• Continuously evolve the deception program to reflect changes in the Company's environment, adversary behavior, and detection priorities.
Detection Gap Analysis & Improvement
• Maintain a structured view of the Company's detection coverage mapped to MITRE ATT&CK, identifying gaps and prioritizing improvements.
• Partner with Detection Engineering and Cybersecurity Operations to translate simulation findings into new or improved detection rules, playbooks, and response procedures.
• Track remediation of detection gaps and validate that improvements are effective through follow-up testing.
Reporting & Continuous Improvement
• Produce clear, evidence-based reports on simulation results, detection coverage, and defensive gap trends for Cyber Threat leadership and the CISO.
• Continuously improve simulation methodologies, tooling, and processes based on evolving adversary tradecraft and lessons learned.
• Stay current with industry developments in adversary simulation, BAS, deception technology, and detection engineering.
Qualifications
• Minimum 5 years of progressive cybersecurity experience, with significant focus on adversary simulation, red teaming, purple teaming, or detection validation.
• Hands-on experience with breach and attack simulation platforms such as Mandiant Security Validation, AttackIQ , SafeBreach , or similar tools.
• Strong working knowledge of adversary tradecraft, MITRE ATT&CK framework, and the ability to design realistic attack simulations based on current threat intelligence.
• Experience with deception technologies, including honeypots, honeytokens, and decoy infrastructure design and deployment.
• Demonstrated ability to conduct purple team exercises and work collaboratively with SOC and detection engineering teams to improve detection coverage.
• Proficiency with common offensive security tools and techniques (Cobalt Strike, Metasploit, custom C2 frameworks) used in adversary simulation contexts.
• Strong understanding of SIEM, EDR, network monitoring, and detection engineering concepts, sufficient to evaluate detection gaps and recommend improvements.
• Excellent written and verbal communication skills, with the ability to produce clear, evidence-based simulation reports for technical and executive audiences.
• Relevant certifications such as OSCP, GPEN, GCIH, GXPN, CRTO, or CRTL are preferred.
• Scripting and automation skills (Python, PowerShell, or equivalent) for developing custom simulation tools and automating testing workflows.
Education
• Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical field required .
• Master's degree or relevant professional certification (OSCP, GPEN, GCIH, or equivalent) highly desirable.
Reporting Relationship
Reports to the Senior Manager, Cyber Threat, within the Cyber Defense team of the Chief Information Security Office (CISO) organization.
No direct reports.
Location
Atlanta, GA (Global Headquarters
Salary insight
This posting doesn't disclose pay. Across 444 Atlanta jobs with disclosed salaries on ForgeApply, the median is $132k.
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this The Coca-Cola Company role before you apply.
Tailor my resume for this jobSimilar jobs
- Manager, Threat Remediation — Pfizer (Internaljobs) · New York City, New York, United States | Collegeville, Pennsylvania, United States
- Manager, Threat Remediation — Pfizer · New York City, New York, United States | Collegeville, Pennsylvania, United States
- Manager, Threat Intelligence — The Coca-Cola Company · Atlanta, GA
- Area Manager, Red Team — Scaleai · Dallas, TX
- Engineering Manager, Red Team — Doordashusa · Remote
- Manager, Threat Detection Engineering — Vanguard · Malvern, PA | Dallas/Ft. Worth, TX
- Sr. Manager, Threat Engineering — Toryburch · Jersey City, NJ
- Senior Security Researcher (Red Team) — Pindropsecurity · Remote
More like this: More jobs at The Coca-Cola Company · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview