Security Engineer III, Red Team Operator
Job Description
Deloitte is seeking a Red Team Operator to plan and execute authorized adversary emulation and penetration testing activities. The role focuses on evaluating and improving detection, response, and resilience capabilities across enterprise and client environments. Work is performed onsite in Baltimore, Maryland, with a schedule of up to 5 days per week.
Compensation: USD 110,700 - 218,300 per year. The stated range reflects a reasonable estimate of the current wage range for this position.
What you’ll do
- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run simulations covering reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Perform phishing, social engineering, and credential attack exercises where authorization is in place.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, defense gaps, and recommendations for remediation.
- Produce clear after-action reports and debriefs for technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to strengthen defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- 2+ years of experience in areas including network architecture and protocols (for example, tunneling), and offensive security in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports that connect technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20% on average based on work, clients, and industries/sectors served.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies and platforms
- Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap
- PowerShell, Python
- MITRE ATT&CK, Active Directory, Windows, Linux
Additional skills
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines and provide clear guidance to others.
Preferred experience
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
Incentives
- Participate in a discretionary annual incentive program, subject to the rules governing the program.