Security Engineer III, Red Team Operator
Job Description
Deloitte Cyber is seeking a Security Engineer III and Red Team Operator to help test real-world security posture through authorized adversary simulations. In this role, you plan and run engagements that mirror how threats operate, translating findings into improvements for detection, response, and overall resilience.
This onsite position is based in Arlington, VA and supports work across enterprise environments, web applications, cloud platforms, and endpoints. The annual salary range for this role is USD 110,700 to 218,300.
What you’ll do
- Plan and execute red team operations targeting enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run simulations across the full attack lifecycle, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Perform authorized phishing, social engineering, and credential attack exercises.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document results, attack chains, gaps in defenses, and remediation recommendations.
- Produce clear after-action reports and debriefs for technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Follow strict rules of engagement, legal requirements, and operational safety standards.
Required qualifications
- 2+ years of experience in adversary simulation and offensive security, including red teaming, purple teaming, or adversary emulation.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days per week.
- Knowledge of network architecture, protocols, and techniques (for example, tunneling).
- Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports connecting technical findings to business risk.
- CRTO (Certified Red Team Operator) or OSCP (Offensive Security Certified Professional).
- Ability to travel 20% on average based on client and industry needs.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK (including mapping)
- Active Directory
Preferred qualifications
- Experience with C2 frameworks such as Havoc, Sliver (in addition to Cobalt Strike, Mythic).
- Cloud red teaming experience in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.