This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Red Team Operator / SME based in the United States.
This senior cybersecurity role leads sophisticated adversary-emulation engagements designed to identify and address weaknesses across federal cyber environments.
You will own engagements from initial scenario design and rules of engagement through execution, evidence collection, reporting, and customer briefings.
The role combines advanced offensive security expertise with strong operational discipline, technical leadership, and defensive improvement objectives.
You will emulate modern threat actors across identity, endpoint, network, web, cloud, and infrastructure environments within strictly authorized scopes.
You will also mentor other operators, collaborate with detection and response teams, and translate findings into measurable security improvements.
The position supports continuous assessment of externally and internally visible federal assets as part of a mission focused on strengthening national cyber resilience.
This is an opportunity to operate at the forefront of offensive security while helping organizations build stronger defenses against evolving threats.
Accountabilities:
- Lead assigned red-team engagements end to end, including scenario development, rules-of-engagement planning, infrastructure preparation, execution, deconfliction, reporting, and customer out-briefs.
- Develop sophisticated, multi-vector adversary-emulation campaigns aligned with MITRE ATT&CK and contemporary advanced persistent threat profiles.
- Design and oversee adversary infrastructure, redirectors, command-and-control channels, payload delivery mechanisms, operator access, logging, and secure teardown procedures.
- Build secure cloud-based attack infrastructure and associated workflows that support authorized adversary-emulation activities.
- Lead hands-on execution of advanced identity, endpoint, network, web, cloud, phishing, persistence, defense-evasion, and simulated exfiltration techniques within approved engagement boundaries.
- Plan and execute campaigns covering reconnaissance, initial access, credential access, privilege escalation, lateral movement, persistence, command and control, defense evasion, and simulated exfiltration.
- Review offensive tooling and payloads for authorized evasion capabilities, including endpoint detection and response considerations and living-off-the-land techniques.
- Mentor junior red-team operators, review tradecraft and scripts, and enforce operational security, safety, evidence-handling, and deconfliction requirements.
- Make real-time technical decisions during engagements while maintaining strict adherence to legal, ethical, operational, and customer-defined boundaries.
- Coordinate with stakeholders to validate detection and response capabilities and develop targeted purple-team scenarios.
- Translate technical observations into measurable defensive improvements and actionable remediation recommendations.
- Maintain technical quality and integrity across operator logs, attack narratives, evidence, mitigation recommendations, assessment reports, and customer briefings.
- Escalate material risks, scope changes, operational impacts, and cross-engagement concerns to technical leadership.
- Support continuous technical assessments of federal internet-facing assets, including domains, subdomains, and externally visible systems.
- Contribute to special projects and evolving offensive-security capabilities in support of broader cybersecurity objectives.
- U.S. citizenship is required.
- Ability to meet eligibility requirements for access to sensitive information and obtain a Public Trust fitness determination at the High Risk level.
- Five or more years of hands-on experience in red teaming, defensive adversary emulation, or advanced penetration testing.
- At least two years of experience leading defensive detection-engineering activities, security engagements, or small offensive-security teams.
- Demonstrated experience planning and executing campaigns across the full attack lifecycle, including reconnaissance, initial access, credential access, privilege escalation, lateral movement, persistence, command and control, defense evasion, and simulated exfiltration.
- Advanced experience with command-and-control frameworks, adversary infrastructure, Active Directory/Entra ID, Windows and Linux tradecraft, cloud attack paths, and security-focused scripting or tool development.
- Strong understanding of operational security, engagement deconfliction, legal and ethical boundaries, evidence handling, data protection, and safe execution within production environments.
- Advanced proficiency with offensive-security tooling such as Sliver, Mythic, and Havoc, as well as secure cloud-based attack architecture.
- Ability to write, review, and communicate technically rigorous assessment reports and deliver clear findings to both technical and executive audiences.
- One or more advanced hands-on certifications such as OSEP/OSCE, OSCP, GXPN, GPEN, CRTO/CRTL, CRTP, OSED, or an equivalent qualification.
- Ability to work effectively within customer-provided remote environments and comply with approved tools, rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria.
- Strong technical leadership, communication, analytical thinking, and problem-solving skills.
- Ability to remain disciplined and effective during complex, high-pressure security operations.
- Eight or more years of offensive-security experience, particularly across multi-tenant enterprise or federal environments.
- Experience developing payloads or security tools using C#, C/C++, Go, Rust, Python, or PowerShell.
- Familiarity with modern endpoint detection and response bypass concepts and living-off-the-land techniques within authorized security testing.
- Advanced AWS or Azure identity and cloud-security experience.
- Experience with container and Kubernetes security or hybrid enterprise environments.
- Experience facilitating purple-team exercises, detection engineering, or SOC and incident-response validation.
- Experience working with critical infrastructure, ICS/OT environments, federal high-value assets, or restricted and air-gapped environments.
- Base salary range of $90,300-$189,600 USD per year, with final compensation influenced by geographic location, contract requirements, relevant experience, education, certifications, skills, and competencies.
- Fully remote position available across U.S. states.
- Full-time employment with up to 25% travel, primarily within the continental United States.
- Flexible time-off benefits designed to support work-life balance.
- Comprehensive healthcare and wellness benefits.
- Financial and retirement benefits.
- Family support programs and related resources.
- Continuing education and professional learning opportunities.
- Career development opportunities within a high-performing cybersecurity environment.
- Opportunity to work on nationally significant cybersecurity missions and advanced federal cyber defense initiatives.
- Collaborative environment emphasizing integrity, innovation, trust, continuous growth, and technical excellence.
- Opportunity to work alongside experienced offensive-security professionals and contribute to evolving adversary-emulation capabilities.
Requirements:
Preferred qualifications:

