EngineerJobs.io
← Back to all jobs

Job Description

Lead authorized adversary emulation efforts to test enterprise resilience and strengthen detection and incident response capabilities.

Responsibilities

  • Plan and carry out red team engagements targeting enterprise environments, web applications, cloud platforms, and endpoints
  • Emulate advanced threat actor behavior using realistic attack paths, tools, and techniques
  • Simulate full attack lifecycle activities including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
  • Evaluate security controls, monitoring effectiveness, and incident response processes
  • Run phishing, social engineering, and credential-focused exercises where authorized
  • Create custom payloads, scripts, and attack workflows to support engagement objectives
  • Document attack chains, defensive gaps, and remediation recommendations
  • Produce after-action reports and conduct debriefs for technical and leadership stakeholders
  • Partner with blue teams, detection engineers, and security leadership to improve defensive posture
  • Follow rules of engagement, legal requirements, and operational safety procedures

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related technical field
  • Active Top-Secret clearance
  • Ability to work onsite up to 5 days per week
  • Knowledge of network architecture, protocols, and related techniques (including tunneling)
  • Hands-on offensive security background supporting red teaming, purple teaming, or adversary simulation
  • Strong understanding of enterprise attack methods across Windows, Active Directory, Linux, cloud, and identity environments
  • Experience using command and control frameworks, privilege escalation, lateral movement, and evasion methods
  • Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
  • Experience mapping activity using MITRE ATT&CK and performing threat emulation
  • Ability to write high-quality reports connecting technical findings to business risk
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
  • Ability to travel 20% on average based on client engagements and industries served
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Cobalt Strike
  • Mythic
  • Metasploit
  • BloodHound
  • Burp Suite
  • Nmap
  • PowerShell
  • Python
  • MITRE ATT&CK

What You’ll Do

  • On the Cyber Defense & Resilience team, serve as a Red Team Operator focused on adversary emulation and resilience assessment

Team

  • Deloitte Cyber supports the unique cybersecurity challenges and opportunities businesses face, delivering solutions and managed services to reduce complexity and enable resilience
  • The Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence
  • Supports managing and protecting dynamic attack surfaces and providing rapid crisis and cyber incident response so clients can be ready to respond to and recover from disruptions

Preferred

  • Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, or Sliver
  • Experience with cloud red teaming in AWS, Azure, or GCP
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises
  • Experience developing custom tooling or modifying public offensive tools
  • Knowledge of malware analysis, reverse engineering, or exploit development

Location & Work Details

  • Rosslyn, VA (onsite)
  • Work up to 5 days per week onsite
  • Travel: 20% on average

Salary

  • Estimated wage range: $110,700 - $218,300 per year (USD)
  • May be eligible for a discretionary annual incentive program, based on program rules and performance factors

Similar Jobs