EngineerJobs.io
← Back to all jobs

Job Description

Deloitte is seeking a Red Team Operator for the Cyber Defense & Resilience team. This onsite role in Rosslyn, VA focuses on improving real-world security outcomes through controlled adversary emulation, engagement execution, and actionable reporting that supports stronger detection, response, and resilience.

What you’ll do

  • Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
  • Emulate advanced threat actors with realistic attack paths, tools, and techniques.
  • Run simulations across reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
  • Evaluate the effectiveness of security controls, monitoring, and incident response processes.
  • Perform authorized phishing, social engineering, and credential attack exercises.
  • Develop custom payloads, scripts, and attack workflows to support engagement objectives.
  • Document findings, attack chains, gaps in defenses, and recommendations for remediation.
  • Provide clear after-action reports and debriefs to technical and leadership stakeholders.
  • Partner with blue teams, detection engineers, and security leadership to improve defensive capabilities.
  • Maintain strict adherence to rules of engagement, legal requirements, and operational safety.

Required qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • Ability to work onsite up to 5 days a week.
  • Knowledge of network architecture, protocols, and techniques (for example, tunneling).
  • Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
  • Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
  • Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
  • Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
  • Experience with MITRE ATT&CK mapping and threat emulation.
  • Ability to write high-quality reports connecting technical findings to business risk.
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
  • Ability to travel 20% on average, based on work, clients, and industries/sectors.
  • Legally authorized to work in the United States without employer sponsorship, now or in the future.
  • Ability to work independently and collaborate in a team, with effective written and verbal communication.
  • Meticulous attention to detail and quality of work product, including meeting deadlines.
  • Ability to build and sustain professional relationships, manage priorities, and provide clear guidance to others.

Preferred qualifications

  • Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, or Sliver.
  • Experience with cloud red teaming in AWS, Azure, or GCP.
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
  • Experience developing custom tooling or modifying public offensive tools.
  • Knowledge of malware analysis, reverse engineering, or exploit development.

Tools and technologies

  • Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, PowerShell, Python, MITRE ATT&CK
  • Active Directory, Windows, Linux, C2 frameworks
  • Havoc, Sliver, AWS, Azure, GCP, SIEM, EDR

Location, clearance, and compensation

Location: Rosslyn, VA (onsite). Salary range: USD 110,700 - 218,300 per year. Compensation reflects a wide range of factors used to make compensation decisions.

Minimum experience: 2 years.

Similar Jobs