Haystack
← Back to Jobs
Remote
Temporary/Casual
Operations & Project Management
TS

Purple/Blue Team Lead

Talent Smart LimitedUnited Kingdom🇬🇧United KingdomPosted 30 Sept 2026

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Remote
Location
United Kingdom
GCPMachine LearningSplunkGoogle CloudLLMPenetration TestingStakeholder Management

Job Description

To be considered, you must have AI & Advanced Threat Defence experience (purple or blue team)

Job Title
Security Purple Team Lead - Blue Team, AI & Advanced Threat Defence - Contract

Contract Length

2 months initial

Overview
We are seeking an experienced Security Purple Team Lead to join a major cybersecurity programme within a leading financial services organisation.

While this is a Purple Team role, the current requirement has a stronger emphasis on Blue Team activity. The successful candidate will bring strong defensive security experience across threat detection, detection engineering, threat hunting and security operations, while having sufficient understanding of offensive security and Red Team techniques to translate simulated attacks and threat intelligence into improved defensive controls.

The organisation is also significantly expanding its use of AI and cloud technologies. Experience of securing AI environments would therefore be highly advantageous, with knowledge of Google Cloud Platform (GCP) and Vertex AI considered a distinct advantage.

Key Responsibilities

  • Lead Purple Team activity with a strong focus on improving Blue Team detection and response capabilities.
  • Work closely with SOC, Cyber Defence, Threat Intelligence, Incident Response and Security Engineering teams.
  • Translate Red Team findings, penetration testing results and adversary behaviours into practical defensive improvements.
  • Develop, tune and optimise detection rules, security use cases, alerts and response playbooks.
  • Lead threat hunting activity across complex enterprise and cloud environments.
  • Use MITRE ATT&CK to identify gaps in detection coverage and prioritise improvements.
  • Support adversary simulation and Purple Team exercises to validate whether existing controls can identify and respond to realistic attack techniques.
  • Improve SIEM, EDR/XDR and security analytics capabilities.
  • Analyse security telemetry to identify suspicious behaviours, emerging threats and weaknesses in existing controls.
  • Develop measurable Purple Team outcomes demonstrating improvements in detection coverage and response effectiveness.
  • Work with cloud and AI engineering teams to strengthen security monitoring across modern technology environments.
  • Support the development of security controls and detection capabilities for AI platforms and workloads.
  • Mentor security analysts and engineers and help mature the organisation's overall defensive security capability.

Essential Skills & Experience

  • Strong Blue Team background across security operations, cyber defence, threat hunting or detection engineering.
  • Previous Purple Team experience, or demonstrable experience working closely with Red Teams to improve defensive capabilities.
  • Strong knowledge of adversary behaviours, attack techniques and MITRE ATT&CK.
  • Experience developing and tuning security detections and use cases.
  • Strong experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel or equivalent.
  • Experience with EDR/XDR technologies and endpoint security telemetry.
  • Strong understanding of incident investigation and response.
  • Ability to translate offensive security findings into actionable defensive controls.
  • Experience operating within large, complex enterprise environments.
  • Strong stakeholder management and the ability to work across offensive, defensive, engineering and risk teams.

AI & Cloud Experience - Highly Desirable

Experience securing or monitoring AI and machine learning environments would be particularly valuable. This could include AI workloads, LLM applications, model access, APIs, data flows and emerging AI-specific security threats.

Experience with Google Cloud Platform (GCP) would be a significant advantage, particularly security monitoring, logging, IAM and threat detection within GCP environments.

Hands-on knowledge of Vertex AI would be a distinct advantage, including understanding how AI models and applications are deployed, accessed, monitored and secured within an enterprise environment.

Experience with AI security risks such as prompt injection, data leakage, credential misuse, API abuse, excessive permissions and abnormal model usage would also be valuable.

Financial Services Experience

Previous experience within banking or financial services is highly desirable. Candidates should ideally understand the security challenges associated with large-scale, highly regulated environments, including operational resilience, regulatory expectations, sensitive data and complex technology estates.

Key Deliverables

  • Improved Blue Team detection and response capability.
  • Identification and remediation of gaps in security monitoring and detection coverage.
  • Enhanced threat hunting and detection engineering capabilities.
  • Effective translation of Red Team and adversary simulation findings into defensive improvements.
  • Mature Purple Team operating practices and measurable security outcomes.
  • Improved monitoring and security controls across cloud and AI environments.
  • Development of security detection capabilities supporting GCP and AI platforms, including Vertex AI where applicable.

Similar jobs