Security Engineer III, Red Team Operator
Job Description
Deloitte seeks a Security Engineer III to operate as a Red Team Operator, executing controlled adversary emulation to evaluate and strengthen detection, response, and resilience across enterprise technology environments.
Role Overview
The Security Engineer III, Red Team Operator will simulate real-world adversary tactics using authorized testing activities. Work may include penetration testing, social engineering, post-exploitation simulations, and structured assessments designed to expose gaps in security controls and improve overall defensive posture.
Key Responsibilities
- Plan and execute red team operations targeting enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Conduct simulations across the attack lifecycle, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring capabilities, and incident response processes.
- Run authorized phishing, social engineering, and credential attack exercises.
- Develop custom payloads, scripts, and attack workflows to support engagement goals.
- Document findings, attack chains, defense gaps, and remediation recommendations.
- Produce clear after-action reports and debriefs for technical teams and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Follow strict rules of engagement, legal requirements, and operational safety practices.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- Knowledge of network architecture, protocols, and techniques (for example, tunneling).
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience using command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports connecting technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20% on average based on client needs and industries served.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies and Tools
- Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap
- PowerShell, Python
- MITRE ATT&CK
- Active Directory, Linux, Windows
- Cobalt Strike (C2 Framework), Havoc, Sliver
- AWS, Azure, GCP
Team Context
Deloitte’s Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. The team supports managing and protecting dynamic attack surfaces and provides rapid crisis and cyber incident response so clients can be ready for, respond to, and recover from business disruptions.
Preferred Qualifications
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, or Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
Location and Compensation
Baltimore, MD (onsite)
- Salary range: USD 110,700 - 218,300 per year.
- A reasonable estimate of the current range is $110,700-$218,300.
- At Deloitte, hiring at or near the top of the range is not typical, and compensation decisions depend on the facts and circumstances of each case.