{"id":533375,"url":"https://alion.io/job/northwave-experienced-red-team-operator","title":"Experienced Red Team Operator","company":{"id":54533,"name":"Northwave","domain":"northwave-cybersecurity.com","url":"https://alion.io/company/northwave","size_band":"201-500","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Recruitee","truth_index":{"grade":"B","score":70,"open_postings":12,"ghost_share":0.5,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Field & Service","role_family":"Field & Service","seniority":null,"employment_type":null,"work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Utrecht, Netherlands"],"countries":["NL"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":5500,"max":8560,"currency":"EUR","period":"month","gross":null,"usd_annual":117252},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Red Teaming","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-08-04T09:11:24Z","employer_posted_date":"2026-08-04","last_verified_at":"2026-09-23T19:47:34Z","board_verified":true,"closed_at":null,"days_open":50,"trust":{"level":"ok","repost_count":0,"flags":["company_stale"],"days_open":49},"description":"At Northwave, 275 cybersecurity specialists transform how organisations approach digital safety. From our HQ in Utrecht, along with offices in Germany, Sweden, and Belgium.\nNorthwave combines ethical hacking expertise with behavioral psychology insights and cutting-edge security management at the highest level. We respond to threats and anticipate them, providing 24/7 managed security services and tailored solutions for each client's journey.\nBy joining Northwave, you’ll become part of an organisation where innovation drives results, whether your talents lie in technical penetration testing or strategic client partnerships. Here, your expertise will grow and help shape the future of digital security across industries, leaving a lasting impact.\nThe team you will join\nOur Red Team brings together 15 ethical hackers with expertise spanning adversary simulation, social engineering, Active Directory and Entra ID, malware and tooling development, cloud, application security, reverse engineering and exploitation. We challenge one another, share techniques openly and combine the right skills for each operation.\nYou will also work closely with our Threat Intelligence, Blue Team, Reverse Engineering and CERT specialists. Insights from real incidents and current threats help us build credible scenarios. Purple teaming turns each exercise into practical improvements for our clients.\n\nWhat you will do\nDesign and execute realistic attack scenarios against critical business processes and systems.\n\nOperate across the full attack chain: reconnaissance and initial access, command and control, privilege escalation, lateral movement and actions on objectives.\n\nDeliver threat-intelligence-led ART and TIBER exercises, alongside other advanced red team and purple team engagements.\n\nBuild or adapt tooling, infrastructure and payloads when an operation requires it.\n\nMake sound OPSEC and risk decisions while working in live client environments.\n\nTranslate technical activity into clear lessons for defenders, technical leaders and executives.\n\nImprove our tradecraft by researching new techniques, developing TTPs and sharing what you learn with the team.\n\nHow an engagement works\nWe start by understanding the organisation, its critical functions and the threat actors it faces. Together with the client and control team, we turn that context into objectives, attack scenarios and clear Rules of Engagement.\nDuring execution, you will have room to adapt. The aim is not to follow a checklist, but to emulate a credible adversary without losing sight of safety or learning value. We close with transparent reporting, executive and technical presentations, and often a purple teaming session in which attacks are replayed with the defenders.\n\nWhat you can expect from us\nSerious red team work requires trust, time to learn and colleagues who can challenge your thinking. We offer:\nComplex, multi-week adversary simulation assignments with meaningful objectives.\n\nA team of specialists who share knowledge and bring different perspectives to an operation.\n\nDirect collaboration with offensive, defensive, threat intelligence, reverse engineering and incident-response experts.\n\nTime and budget for training, certifications, conferences and longer development programmes.\n\nProfessional equipment and the tooling needed to do your work well.\n\nHybrid working with access to our offices in Belgium, Germany, the Netherlands and Sweden.\n\nA competitive local compensation and benefits package. Salary, leave, pension, mobility and allowances differ by country. Our recruiter will explain the package that applies to your location.\n\nRoom to influence our methods, tooling and the future of our red team services as demand grows.\n\nRequirements\nEssential\nSeveral years of hands-on penetration testing or red team experience, including responsibility for planning and executing operations.\n\nStrong attack-path knowledge in Windows and Active Directory environments.\n\nExperience with Entra ID or other cloud environments.\n\nPractical command-and-control, OPSEC and infrastructure skills.\n\nThe judgement to balance operational objectives, client safety and learning value.\n\nClear written and spoken English, with the ability to explain decisions and findings to both technical and non-technical audiences.\n\nA collaborative approach: you ask for a second pair of eyes, share what worked and help others improve.\n\nEligibility to work from Belgium, Germany, the Netherlands or Sweden, and willingness to travel for client work when an engagement requires it.\n\nUseful, but not required\nExperience delivering ART, TIBER or another structured threat-led red team framework.\n\nDepth in one or more areas such as social engineering, malware development, cloud, application security, exploit development or reverse engineering.\n\nRelevant certifications such as OSCP, OSEP or CRTO. We value demonstrated capability and sound judgement more than a checklist of certificates.\n\nAnother European language in addition to English.\n\nNot sure you match every point?\nIf you have solid offensive-security experience and are ready to take ownership of realistic red team operations, we would still like to hear from you. Tell us what you are strongest at, what you want to deepen and how you approach an operation when the obvious route does not work. \nReady to operate with us?\nApply through the vacancy page or contact Youri Roelofs at . Please include the country from which you would like to work so we can discuss the relevant local package and practical arrangements.","description_format":"text","description_chars":5585,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Hybrid work"],"hiring_locations":[{"name":"Germany","iso":"DE","kind":"country"},{"name":"Belgium","iso":"BE","kind":"country"},{"name":"Netherlands","iso":"NL","kind":"country"},{"name":"Sweden","iso":"SE","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Cybersecurity"],"lifecycle":[{"event":"open","at":"2026-09-08T07:15:57Z"}],"liveness":{"score":15,"band":"cold","label":"Long shot","p_open":1,"p_active":0.326,"p_room":0.45,"age_days":49,"expected_fill_days":32,"reasons":["conf:2","stale_co","win:tail"],"computed_at":"2026-09-23T05:45:00Z"},"pay":{"stated_usd_annual":117252,"is_top_pay":true},"html_url":"https://alion.io/job/northwave-experienced-red-team-operator","json_url":"https://alion.io/job/northwave-experienced-red-team-operator.json","meta":{"generated_at":"2026-09-23T21:31:18Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}