Security Engineer III, Red Team Operator
Active Directory
Bloodhound
Burp Suite
Cobalt Strike
Cybersecurity Tools
Data Security
Desktop Support
Embedded System
End User Support
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Metasploit
Nmap
Offensive Security
Operating System
Operating Systems
Penetration Testing
Powershell
Project Management
Red Team
Risk Management
Security
Security Engineering
Security Operations
Security Testing
Software Development
Systems
Technical Support
Unix Operating System
Windows
Job Description
Deloitte is seeking a Red Team Operator for the Cyber Defense & Resilience team. This onsite role in Rosslyn, VA focuses on improving real-world security outcomes through controlled adversary emulation, engagement execution, and actionable reporting that supports stronger detection, response, and resilience.
What you’ll do
- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors with realistic attack paths, tools, and techniques.
- Run simulations across reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Perform authorized phishing, social engineering, and credential attack exercises.
- Develop custom payloads, scripts, and attack workflows to support engagement objectives.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Provide clear after-action reports and debriefs to technical and leadership stakeholders.
- Partner with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
Required qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- Knowledge of network architecture, protocols, and techniques (for example, tunneling).
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports connecting technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20% on average, based on work, clients, and industries/sectors.
- Legally authorized to work in the United States without employer sponsorship, now or in the future.
- Ability to work independently and collaborate in a team, with effective written and verbal communication.
- Meticulous attention to detail and quality of work product, including meeting deadlines.
- Ability to build and sustain professional relationships, manage priorities, and provide clear guidance to others.
Preferred qualifications
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, or Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
Tools and technologies
- Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, PowerShell, Python, MITRE ATT&CK
- Active Directory, Windows, Linux, C2 frameworks
- Havoc, Sliver, AWS, Azure, GCP, SIEM, EDR
Location, clearance, and compensation
Location: Rosslyn, VA (onsite). Salary range: USD 110,700 - 218,300 per year. Compensation reflects a wide range of factors used to make compensation decisions.
Minimum experience: 2 years.