Security Engineer III, Red Team Operator (TS Clearance)
Senior
Cloud Platforms
Cobalt Strike
Cybersecurity Tools
Data Security
Endpoint Security
Ethical Hacking
Facilities Management
Incident Response
Information Security
InfoSec
Management
Metasploit
Mitre Att&ck
Offensive Security
Penetration Testing
Pentesting Tools
Project Management
Red Team
Red Team Operator
Risk Management
Security
Security Automation
Security Clearance
Security Operations
Security Standards
Security Testing
Security Testing Tools
Job Description
Lead authorized adversary emulation efforts to test enterprise resilience and strengthen detection and incident response capabilities.
Responsibilities
- Plan and carry out red team engagements targeting enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actor behavior using realistic attack paths, tools, and techniques
- Simulate full attack lifecycle activities including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate security controls, monitoring effectiveness, and incident response processes
- Run phishing, social engineering, and credential-focused exercises where authorized
- Create custom payloads, scripts, and attack workflows to support engagement objectives
- Document attack chains, defensive gaps, and remediation recommendations
- Produce after-action reports and conduct debriefs for technical and leadership stakeholders
- Partner with blue teams, detection engineers, and security leadership to improve defensive posture
- Follow rules of engagement, legal requirements, and operational safety procedures
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related technical field
- Active Top-Secret clearance
- Ability to work onsite up to 5 days per week
- Knowledge of network architecture, protocols, and related techniques (including tunneling)
- Hands-on offensive security background supporting red teaming, purple teaming, or adversary simulation
- Strong understanding of enterprise attack methods across Windows, Active Directory, Linux, cloud, and identity environments
- Experience using command and control frameworks, privilege escalation, lateral movement, and evasion methods
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
- Experience mapping activity using MITRE ATT&CK and performing threat emulation
- Ability to write high-quality reports connecting technical findings to business risk
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
- Ability to travel 20% on average based on client engagements and industries served
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
What You’ll Do
- On the Cyber Defense & Resilience team, serve as a Red Team Operator focused on adversary emulation and resilience assessment
Team
- Deloitte Cyber supports the unique cybersecurity challenges and opportunities businesses face, delivering solutions and managed services to reduce complexity and enable resilience
- The Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence
- Supports managing and protecting dynamic attack surfaces and providing rapid crisis and cyber incident response so clients can be ready to respond to and recover from disruptions
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, or Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Location & Work Details
- Rosslyn, VA (onsite)
- Work up to 5 days per week onsite
- Travel: 20% on average
Salary
- Estimated wage range: $110,700 - $218,300 per year (USD)
- May be eligible for a discretionary annual incentive program, based on program rules and performance factors