CybersecurityJobs.io
← Back to all jobs

Job Description

As a Security Engineer III Red Team Operator within Deloitte Cyber, you will help validate and strengthen security by simulating real-world adversary behavior. The role emphasizes controlled, authorized testing to evaluate detection, response, and overall resilience across modern enterprise environments.

Onsite Location

Arlington, VA (onsite). Ability to work onsite up to 5 days a week.

Salary

USD 110,700 - 218,300 per year.

Role Summary

You will plan and execute adversary emulation activities, including penetration testing, social engineering, and post-exploitation activities conducted in controlled and authorized settings. Work includes designing realistic attack paths to test how well security controls and incident response capabilities perform under simulated threat conditions.

Key Responsibilities

  • Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints.
  • Emulate advanced threat actor behavior using realistic attack paths, tools, and techniques.
  • Run simulations covering reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
  • Evaluate the effectiveness of security controls, monitoring, and incident response processes.
  • Perform phishing, social engineering, and credential attack exercises where authorized.
  • Develop custom payloads, scripts, and attack workflows to support engagement objectives.
  • Document findings, identify gaps in defenses, and provide recommendations for remediation.
  • Deliver after-action reporting and debriefs to both technical teams and leadership stakeholders.
  • Collaborate with blue teams, detection engineers, and security leadership to strengthen defensive capabilities.
  • Maintain strict compliance with rules of engagement, legal requirements, and operational safety.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • 2+ years of experience, including offensive security work such as red teaming, purple teaming, or adversary simulation.
  • Knowledge of network architecture, protocols, and related techniques (including tunneling).
  • Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
  • Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
  • Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
  • Experience with MITRE ATT&CK mapping and threat emulation.
  • Ability to write high-quality reports connecting technical findings to business risk.
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
  • Ability to travel 20%, on average, based on client needs and served industries or sectors.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Technologies

  • Cobalt Strike
  • Mythic
  • Metasploit
  • BloodHound
  • Burp Suite
  • Nmap
  • PowerShell
  • Python
  • MITRE ATT&CK
  • Active Directory

Preferred Qualifications

  • Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
  • Experience with cloud red teaming in AWS, Azure, or GCP.
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
  • Experience developing custom tooling or modifying public offensive tools.
  • Knowledge of malware analysis, reverse engineering, or exploit development.

Similar Jobs