Manager, Threat (Red Team)

Posted 3 Days Ago
Be an Early Applicant
Atlanta, GA, USA
In-Office
125K-148K Annually
Senior level
Food
The Role
Run adversary simulation, BAS, and deception programs to test detection and response capabilities. Design MITRE ATT&CK–mapped scenarios, operate BAS platforms, deploy honeypots/honeytokens, conduct purple team exercises, analyze detection gaps, and produce evidence-based reports to drive remediation with SOC and detection engineering.
Summary Generated by Built In

Job Description Summary:

Overview 

The Manager, Threat Simulation & Red Team is The Coca-Cola Company's hands-on operator for adversary simulation, breach and attack simulation (BAS), and deception technologies. This role tests the Company's detection and response capabilities by emulating real-world adversary behavior, running continuous attack simulations, and deploying deception technologies that expose gaps in the Company's defensive posture. The goal is not traditional penetration testing or application security, but rather validating that the SOC, detection engineering, and incident response teams can see, catch, and stop real attacks. 

Reporting to the Senior Manager, Cyber Threat, this is an individual-contributor role focused on deep technical execution. The Manager designs and runs threat simulation exercises mapped to real adversary tradecraft, operates breach and attack simulation platforms, deploys and manages honeypots and honeytokens, and delivers clear, evidence-based assessments of defensive gaps. The role partners closely with Cybersecurity Operations, Detection Engineering, and Threat Intelligence to turn simulation findings into measurable improvements in the Company's ability to detect and respond to threats. 

Key Responsibilities 

Adversary Simulation & Purple Teaming 

  • Design and execute adversary simulation exercises that test the Company's detection, alerting, and response capabilities against realistic attack scenarios. 

  • Develop threat simulation scenarios mapped to MITRE ATT&CK techniques and informed by current threat intelligence on adversaries relevant to the Company. 

  • Conduct purple team exercises in partnership with SOC and detection engineering teams, collaboratively identifying detection gaps and validating improvements. 

  • Simulate full attack chains, including initial access, lateral movement, privilege escalation, persistence, and data exfiltration, to test end-to-end defensive coverage. 

Breach and Attack Simulation (BAS) 

  • Operate and optimize breach and attack simulation platforms (such as Mandiant Security Validation, AttackIQ, or SafeBreach) to provide continuous, automated validation of security controls. 

  • Define and maintain a library of attack simulations aligned to the Company's threat profile and detection priorities. 

  • Analyze BAS results to identify detection gaps, control failures, and configuration drift, and work with detection engineering to remediate findings. 

  • Produce regular reporting on control effectiveness, detection coverage, and trends over time. 

Deception Technology 

  • Design, deploy, and manage deception technologies, including honeypots, honeytokens, and decoy assets, across the Company's environment. 

  • Integrate deception alerts into SOC workflows, ensuring timely triage and investigation of deception-triggered events. 

  • Continuously evolve the deception program to reflect changes in the Company's environment, adversary behavior, and detection priorities. 

Detection Gap Analysis & Improvement 

  • Maintain a structured view of the Company's detection coverage mapped to MITRE ATT&CK, identifying gaps and prioritizing improvements. 

  • Partner with Detection Engineering and Cybersecurity Operations to translate simulation findings into new or improved detection rules, playbooks, and response procedures. 

  • Track remediation of detection gaps and validate that improvements are effective through follow-up testing. 

Reporting & Continuous Improvement 

  • Produce clear, evidence-based reports on simulation results, detection coverage, and defensive gap trends for Cyber Threat leadership and the CISO. 

  • Continuously improve simulation methodologies, tooling, and processes based on evolving adversary tradecraft and lessons learned. 

  • Stay current with industry developments in adversary simulation, BAS, deception technology, and detection engineering. 

Qualifications 

  • Minimum 5 years of progressive cybersecurity experience, with significant focus on adversary simulation, red teaming, purple teaming, or detection validation. 

  • Hands-on experience with breach and attack simulation platforms such as Mandiant Security Validation, AttackIQ, SafeBreach, or similar tools. 

  • Strong working knowledge of adversary tradecraft, MITRE ATT&CK framework, and the ability to design realistic attack simulations based on current threat intelligence. 

  • Experience with deception technologies, including honeypots, honeytokens, and decoy infrastructure design and deployment. 

  • Demonstrated ability to conduct purple team exercises and work collaboratively with SOC and detection engineering teams to improve detection coverage. 

  • Proficiency with common offensive security tools and techniques (Cobalt Strike, Metasploit, custom C2 frameworks) used in adversary simulation contexts. 

  • Strong understanding of SIEM, EDR, network monitoring, and detection engineering concepts, sufficient to evaluate detection gaps and recommend improvements. 

  • Excellent written and verbal communication skills, with the ability to produce clear, evidence-based simulation reports for technical and executive audiences. 

  • Relevant certifications such as OSCP, GPEN, GCIH, GXPN, CRTO, or CRTL are preferred. 

  • Scripting and automation skills (Python, PowerShell, or equivalent) for developing custom simulation tools and automating testing workflows. 

Education 

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical field required. 

  • Master's degree or relevant professional certification (OSCP, GPEN, GCIH, or equivalent) highly desirable. 

Reporting Relationship 

Reports to the Senior Manager, Cyber Threat, within the Cyber Defense team of the Chief Information Security Office (CISO) organization. 

No direct reports. 

Location 

Atlanta, GA (Global Headquarters) 

Travel 

Estimated up to 10% travel, primarily domestic, with occasional travel for industry conferences, training, and vendor engagements. 

The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.

Skills:

Agile Methodology, Business Requirements, Communication, Computer Programming, Configuring (Inactive), Data Analysis, Financial Processing, Information Systems, Software Development, Structured Query Language (SQL), Systems Analysis, Systems Development Lifecycle (SDLC), Teamwork, Test Environments, Troubleshooting, Waterfall Model, Workflow Management

Pay Range:

United States of America: 124,600 USD - 148,200 USD

Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.

Annual Incentive Reference Value Percentage:

15

Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.

Location(s):

United States of America

City/Cities:

Atlanta

Travel Required:

00% - 25%

Relocation Provided:

No

Job Posting End Date:

August 14, 2026

Our Purpose and Growth Culture:

We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what’s possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors – curious, empowered, inclusive and agile – and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit Our Purpose and Vision to learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.

Skills Required

  • Minimum 5 years progressive cybersecurity experience with adversary simulation, red teaming, purple teaming, or detection validation.
  • Hands-on experience operating breach and attack simulation platforms (Mandiant Security Validation, AttackIQ, SafeBreach, or similar).
  • Strong working knowledge of adversary tradecraft and MITRE ATT&CK framework to design realistic attack simulations.
  • Experience designing, deploying, and managing deception technologies (honeypots, honeytokens, decoy assets).
  • Proficiency with offensive security tools and techniques (Cobalt Strike, Metasploit, custom C2 frameworks).
  • Strong understanding of SIEM, EDR, network monitoring, and detection engineering concepts.
  • Ability to conduct purple team exercises and collaborate with SOC and detection engineering teams.
  • Scripting and automation skills (Python, PowerShell, or equivalent) for custom simulation tooling and automation.
  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical field.
  • Relevant certifications (OSCP, GPEN, GCIH, GXPN, CRTO, CRTL) or a Master's degree.

The Coca-Cola Company Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about The Coca-Cola Company and has not been reviewed or approved by The Coca-Cola Company.

  • Retirement Support Retirement benefits are positioned as a standout, combining a 401(k) match with a company-funded cash-balance pension and an employee stock purchase plan match that together materially increase long-term package value.
  • Healthcare Strength Health coverage is described as broad and feature-rich, including national medical coverage plus specialized add-ons like virtual care, second opinions, oncology navigation, fertility support, and chronic-condition programs.
  • Leave & Time Off Breadth Time-off benefits are outlined with structured vacation accrual that increases with tenure and a holiday program that includes both set and floating days.

The Coca-Cola Company Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, GA
88,900 Employees
Year Founded: 1892

What We Do

The Coca-Cola Company (NYSE: KO) is a total beverage company, offering over 500 brands in more than 200 countries and territories. In addition to the company’s Coca-Cola brands, our portfolio includes some of the world’s most valuable beverage brands, such as AdeS soy-based beverages, Ayataka green tea, Dasani waters, Del Valle juices and nectars, Fanta, Georgia coffee, Gold Peak teas and coffees, Honest Tea, innocent smoothies and juices, Minute Maid juices, Powerade sports drinks, Simply juices, smartwater, Sprite, vitaminwater and ZICO coconut water.

Similar Jobs

Toast Logo Toast

Account Executive

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
Covington, GA, USA
5000 Employees
115K-185K Annually

Toast Logo Toast

Account Executive

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
Decatur, GA, USA
5000 Employees
115K-185K Annually

Wipfli Logo Wipfli

Senior Engineer

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
88K-118K Annually

Wipfli Logo Wipfli

Product Owner

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-144K Annually

Similar Companies Hiring

McCain Foods Thumbnail
Food • Retail • Agriculture • Manufacturing
Florenceville-Bristol, NB
20000 Employees
Munchkin, Inc. Thumbnail
Consumer Web • eCommerce • Food • Kids + Family • Design • Manufacturing
Milton, Ontario
325 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account