The Security Engineer III role on Deloitte’s Cyber Defense & Resilience team centers on red teaming in enterprise environments. You will simulate adversary tactics to evaluate and strengthen detection, response, and overall resilience across systems, applications, and cloud platforms.
Location and Work Setting
Baltimore, MD (onsite). Onsite work is required up to 5 days per week, and travel averages 20% based on client engagements and supported industries or sectors.
Compensation
USD 119,000 - 218,300 per year.
Role Responsibilities
- Plan and execute red team operations targeting enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Perform simulations across the engagement lifecycle, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Conduct authorized phishing, social engineering, and credential attack exercises.
- Develop supporting artifacts such as custom payloads, scripts, and attack workflows.
- Document findings, attack chains, defense gaps, and remediation recommendations.
- Provide clear after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Follow strict rules of engagement, legal requirements, and operational safety procedures.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- 2+ years of experience in offensive security activities including red teaming, purple teaming, or adversary simulation.
- Knowledge of network architecture, protocols, and techniques such as tunneling.
- Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Tool proficiency including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience mapping activity to MITRE ATT&CK and performing threat emulation.
- Ability to write high-quality reports that connect technical results to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20% on average.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Havoc
- Sliver
- AWS
- Azure
- GCP
Team Overview
Deloitte’s Cyber team addresses the cybersecurity challenges and opportunities businesses face. The Cyber Defense & Resilience offering supports clients by enhancing security operations, monitoring technology, data analytics, and threat intelligence, while helping manage and protect dynamic attack surfaces. It also supports rapid crisis and cyber incident response to help clients be ready for, respond to, and recover from business disruptions.
Candidate Attributes
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to provide clear guidance to others.
Preferred Qualifications
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.