Security Engineer III, Red Team Operator
Active Directory
Burp Suite
Cloud Platforms
Cobalt Strike
Command And Control
Endpoint Security
Ethical Hacking
Identity and Access Management
Incident Response
Information Security
InfoSec
Metasploit
Mitre Att&ck
Nmap
Offensive Security
Penetration Testing
Powershell
Red Team
Red Team Operator
Security
Security Engineer
Security Testing
Job Description
Deloitte is seeking a Red Team Operator to support authorized adversary emulation and penetration testing activities with the goal of strengthening enterprise detection, response, and resilience. This onsite role in Rosslyn, VA focuses on realistic threat simulations across modern IT environments, followed by clear reporting and collaboration with security teams.
The position is aligned to a senior security engineering track and requires an active Top-Secret Clearance, along with experience planning and executing red team operations in a controlled, legally compliant setting.
Location and compensation
- Location: Rosslyn, VA (onsite)
- Salary: USD 88,800 - 162,800 per year
- Work model: onsite up to 5 days a week
- Travel: 20% on average
What you will do
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run simulations for reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Conduct phishing and other social engineering and credential attack exercises when authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Provide after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
Required qualifications
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Clearance: Active Top-Secret Clearance.
- Experience: 1+ years within offensive security and adversary simulation activities.
- Knowledge of network architecture, protocols, and techniques such as tunneling.
- Hands-on experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience mapping activity to MITRE ATT&CK and performing threat emulation.
- Ability to write high-quality reports connecting technical findings to business risk.
- Ability to travel 20% on average.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technology focus
- Cobalt Strike, Mythic, Metasploit
- BloodHound, Burp Suite, Nmap
- PowerShell, Python
- MITRE ATT&CK
- Windows, Active Directory, Linux
- Cloud and identity environments
- Command and control frameworks
Incentive program
- You may be eligible to participate in a discretionary annual incentive program, subject to program rules and dependent on factors including individual and organizational performance.
Preferred qualifications
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.