Job Description
Who We Are
Creative Artists Agency (CAA) is the leading entertainment and sports agency, with global expertise in filmed and live entertainment, digital media, publishing, sponsorship sales and endorsements, media finance, consumer investing, fashion, trademark licensing, and philanthropy. Ā Distinguished by its culture of collaboration and exceptional client service, CAAās diverse workforce identifies, innovates, and amplifies opportunities for the people and organizations that shape culture and inspire the world. Ā The trailblazer of the agency business, CAA was the first to build a sports business, create an investment bank, launch a venture fund, found technology start-up companies, establish a philanthropic arm, build a business in China, and form a brand marketing services division, among other innovations. Named Most Valuable Sports Agency by Forbes for eight consecutive years, CAA represents more than 2,000 of the worldās top athletes in football, baseball, basketball, hockey, soccer, in addition to coaches, on-air broadcasters, and sports personalities and works in the areas of broadcast rights, corporate marketing initiatives, social impact, and sports properties for sales and sponsorship opportunities. Founded in 1975, CAA is headquartered in Los Angeles, and has offices in New York, Nashville, Memphis, Chicago, Miami, London, Munich, Geneva, Stockholm, Shanghai, and Beijing, among other locations globally.
The Role
Strategic and technically adept cybersecurityĀ professionalĀ with deepĀ expertiseĀ inĀ VulnerabilityĀ Management,Ā OffensiveĀ Security, and advanced threat detection. AsĀ LeadĀ of Cyber ThreatĀ Engineering,Ā this individual willĀ beĀ responsible forĀ driving proactive defense initiatives thatĀ identifyĀ and mitigate risks before they can be exploited. Experienced in leading red and purple team operations, orchestrating vulnerability assessments, and integrating threat intelligence to inform remediation and hardening strategies. Skilled in aligning offensive security insights with enterprise risk managementĀ and Incident Response Strategies, improving security posture through automation, and fostering a culture of continuous testing and improvement. Recognized for building high-performing teams that bridge the gap between adversary emulation and defensive readiness to ensure comprehensive protection across digital assets.Ā
Ā
We are looking for candidates whoĀ have aĀ passionĀ forĀ cyber security, threat detection,Ā riskĀ mitigation,Ā andĀ automation. You willĀ provideĀ insightĀ inĀ ourĀ efforts to build and support a defensibleĀ environment where we are able to detect,Ā containĀ and respond quickly to threats, vulnerabilitiesĀ and compromiseĀ in ways that serve to enableĀ theĀ technologyĀ needsĀ ofĀ aĀ highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud servicesĀ along withĀ the challenges of integrating those services into our security practice.Ā
Ā
ResponsibilitiesĀ
Support leadership withĀ enterprise-wide vulnerability identification, assessment, and remediation programs across infrastructure, cloud, and applications.Ā
Provide continuous visibility to new and emerging threats against existing securityĀ controls;Ā ensuring controlsĀ remainĀ effectiveĀ toĀ changing business and threat landscapes.Ā
Work across the Tech department to enhance security posture capabilities to limit security misconfigurations through secure configuration standards,Ā monitoring,Ā and remediation.Ā
Integrate automated scanning and vulnerability intelligence into CI/CD and asset management systems.Ā
Translate offensive findings into actionable security improvements andĀ detection ofĀ engineering use cases.Ā
Collaborate with defensive teams toĀ validateĀ security controls and improve resilience through continuous testing.Ā
Support the Offensive Security Lifecycle via management ofĀ internal and externalĀ Cyber Threat and Offensive Security assessments.Ā
Partner closelyĀ withĀ Incident Response teams to enhanceĀ detection ofĀ logic, playbooks, and threat-hunting capabilities.Ā
Ā
QualificationsĀ
AĀ minimum ofĀ 6Ā yearsā experience delivering information security solutions, ideally withĀ AĀ mixed focus onĀ offensive and defensive security roles.Ā Ā
bachelorāsĀ or masterās degree in a relevant field of workĀ
Hands on experience inĀ Cyber Threat and Offensive SecurityĀ operationsĀ to test andĀ validateĀ the effective operation of securityĀ controls,Ā measuring the ability to stop threats and attacks at the earliest point in the kill chainĀ
ProvenĀ track recordĀ working as both an individual contributor andĀ leadĀ in the areas ofĀ CyberĀ Threat,Ā VulnerabilityĀ Management, orĀ IncidentĀ ResponseĀ
Strong understanding of the fundamental operations of servers, operating systems, networks,Ā cloudĀ applicationsĀ and infrastructureĀ along withĀ anĀ advancedĀ understanding of the key controls required for secure operation of these systemsĀ Ā
experience scriptingĀ in at least one of the following languages:Ā PowerShell, Python, JavaScriptĀ
experienceĀ in aligning threat and vulnerability management efforts to frameworksĀ and controlĀ objectivesĀ -Ā MITRE ATT&CK, NIST CSF, ISO27001, Center for Internet Security, OWASP,Ā Ā
Experience integrating theĀ following toolsĀ and capabilitiesĀ intoĀ a successfulĀ threat and vulnerabilityĀ program ā Security OrchestrationĀ Automation and Response, Security Information andĀ Event Management, Vulnerability Scanning,Ā SecurityĀ Threat Feeds,Ā Red TeamĀ ToolingĀ
Location
This role is hybrid, based in our Nashville office.
Ā
Compensation
The annual base salary for this position is in the range of $111,000 - $133,000 in Nashville. This position is also eligible for benefits and a discretionary bonus. Ultimately, the salary may vary based upon, but not limited to, relevant experience, time in the role, business sector, and geographic location, among other criteria. Please talk with a CAA Recruiter to learn more.
#LI-MS1
Learn more about this Employer on their Career Site
