Security Engineer III, Red Team Operator
Job Description
Join Deloitte’s Cyber Defense & Resilience team to operate as a Security Engineer III focused on authorized red team engagements.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actors using realistic attack paths, tools, and techniques
- Run simulations across reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate security control effectiveness, monitoring coverage, and incident response processes
- Conduct authorized phishing, social engineering, and credential attack exercises
- Develop custom payloads, scripts, and attack workflows to support engagements
- Document findings, attack chains, defense gaps, and remediation recommendations
- Provide after-action reports and debriefs to technical and leadership stakeholders
- Collaborate with blue teams, detection engineers, and security leadership to strengthen defensive capabilities
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week
- 1+ years of experience with:
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques
- Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
- Experience with MITRE ATT&CK mapping and threat emulation
- Ability to write high-quality reports connecting technical findings to business risk
- Ability to travel 20% on average based on work, clients, and industries/sectors served
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Active Directory
Preferred
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Location & Compensation
- Location: Baltimore, MD (onsite)
- Salary range: USD 88,800 - 162,800 per year
- Estimated range basis: A reasonable estimate of the current range is $88,800-$162,800
Benefits
- May be eligible to participate in a discretionary annual incentive program, subject to program rules; awards, if any, depend on factors including individual and organizational performance