Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA’s diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world’s top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.Job Description
The Role
Strategic and technically adept cybersecurity professional with deep expertise in Vulnerability Management, Offensive Security, and advanced threat detection. As Lead of Cyber Threat Engineering, this individual will be responsible for driving proactive defense initiatives that identify and mitigate risks before they can be exploited. Experienced in leading red and purple team operations, orchestrating vulnerability assessments, and integrating threat intelligence to inform remediation and hardening strategies. Skilled in aligning offensive security insights with enterprise risk management and Incident Response Strategies, improving security posture through automation, and fostering a culture of continuous testing and improvement. Recognized for building high-performing teams that bridge the gap between adversary emulation and defensive readiness to ensure comprehensive protection across digital assets.
We are looking for candidates who have a passion for cyber security, threat detection, risk mitigation, and automation. You will provide insight in our efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to threats, vulnerabilities and compromise in ways that serve to enable the technology needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practice.
Responsibilities
Support leadership with enterprise-wide vulnerability identification, assessment, and remediation programs across infrastructure, cloud, and applications.
Provide continuous visibility to new and emerging threats against existing security controls; ensuring controls remain effective to changing business and threat landscapes.
Work across the Tech department to enhance security posture capabilities to limit security misconfigurations through secure configuration standards, monitoring, and remediation.
Integrate automated scanning and vulnerability intelligence into CI/CD and asset management systems.
Translate offensive findings into actionable security improvements and detection of engineering use cases.
Collaborate with defensive teams to validate security controls and improve resilience through continuous testing.
Support the Offensive Security Lifecycle via management of internal and external Cyber Threat and Offensive Security assessments.
Partner closely with Incident Response teams to enhance detection of logic, playbooks, and threat-hunting capabilities.
Required Capabilities
A minimum of 6 years’ experience delivering information security solutions, ideally with A mixed focus on offensive and defensive security roles.
bachelor’s or master’s degree in a relevant field of work
Hands on experience in Cyber Threat and Offensive Security operations to test and validate the effective operation of security controls, measuring the ability to stop threats and attacks at the earliest point in the kill chain
Proven track record working as both an individual contributor and lead in the areas of Cyber Threat, Vulnerability Management, or Incident Response
Strong understanding of the fundamental operations of servers, operating systems, networks, cloud applications and infrastructure along with an advanced understanding of the key controls required for secure operation of these systems
experience scripting in at least one of the following languages: PowerShell, Python, JavaScript
experience in aligning threat and vulnerability management efforts to frameworks and control objectives - MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP,
Experience integrating the following tools and capabilities into a successful threat and vulnerability program – Security Orchestration Automation and Response, Security Information and Event Management, Vulnerability Scanning, Security Threat Feeds, Red Team Tooling
Skills Required
- Minimum 6 years' experience delivering information security solutions (offensive and defensive)
- Bachelor's or master's degree in a relevant field
- Hands-on experience in Cyber Threat and Offensive Security operations
- Proven track record as individual contributor and lead in Cyber Threat, Vulnerability Management, or Incident Response
- Strong understanding of servers, operating systems, networks, cloud applications and infrastructure and associated security controls
- Experience scripting in at least one: PowerShell, Python, JavaScript
- Experience aligning threat and vulnerability management to frameworks (MITRE ATT&CK, NIST CSF, ISO27001, CIS, OWASP)
- Experience integrating SOAR, SIEM, vulnerability scanning, threat feeds, and red team tooling into a threat and vulnerability program
Creative Artists Agency Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Creative Artists Agency and has not been reviewed or approved by Creative Artists Agency.
-
Healthcare Strength — Health coverage is considered strong and affordable, with low co-pays and solid plan options frequently highlighted. This makes core medical, dental, and vision coverage a standout part of the package.
-
Leave & Time Off Breadth — Time off is bolstered by an office shutdown around late December alongside standard vacation/holiday and sick time. This combination is viewed as a meaningful boost to practical time away from work.
-
Wellbeing & Lifestyle Benefits — Unique industry access such as screenings, event tickets, and on-site showcases are emphasized as meaningful lifestyle perks. These add distinctive non-cash value for those seeking entertainment exposure and networking.
Creative Artists Agency Insights
What We Do
Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Distinguished by its culture of collaboration and exceptional client service, CAA’s diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the world’s top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally. For more information, please visit www.caa.com.









