Security Engineer III, Red Team Operator
Job Description
Deloitte’s Cyber Defense & Resilience team helps clients strengthen security operations and improve readiness against advanced threats. In this Security Engineer III role, you will operate as a Red Team Operator, planning and carrying out authorized adversary emulation to evaluate and enhance detection, response, and resilience capabilities.
This onsite position is based in Baltimore, MD, supporting assessments across enterprise systems and modern attack surfaces.
What you will do
- Plan and execute red team operations targeting enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run simulations for reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Conduct phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagement objectives.
- Document findings, attack chains, gaps in defenses, and remediation recommendations.
- Provide clear after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Follow strict rules of engagement, legal requirements, and operational safety.
Required qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling).
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports connecting technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20%, on average, based on client needs and industries/sectors served.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies
- Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap
- PowerShell, Python, MITRE ATT&CK
- Active Directory, Windows, Linux
- AWS, Azure, GCP
- Havoc, Sliver, SIEM, EDR
Preferred experience
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
How you will work
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to provide clear guidance to others.
Additional details
- Minimum experience: 2 years
- Location: Baltimore, MD (onsite)
- Salary range: USD 110,700 - 218,300 per year
- Incentive program: You may be eligible to participate in a discretionary annual incentive program, subject to program rules. An award, if any, depends on factors including individual and organizational performance.