Security Engineer III, Red Team Operator
Job Description
Security Engineer III, Red Team Operator will support authorized adversary emulation to improve detection, response, and resilience through controlled offensive testing activities.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actors using realistic attack paths, tools, and techniques
- Simulate reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate security control effectiveness, including monitoring and incident response processes
- Conduct phishing, social engineering, and credential attack exercises where authorized
- Develop custom payloads, scripts, and attack workflows to support engagements
- Document findings, attack chains, defense gaps, and remediation recommendations
- Provide after-action reports and technical debriefs to stakeholders, including leadership
- Collaborate with blue teams, detection engineers, and security leadership to strengthen defensive capabilities
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week
- Knowledge of network architecture, protocols, and techniques (including tunneling)
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
- Experience with MITRE ATT&CK mapping and threat emulation
- Ability to write high-quality reports connecting technical findings to business risk
- CRTO (Certified Red Team Operator) or OSCP (Offensive Security Certified Professional)
- Ability to travel 20% on average
- Legally authorized to work in the United States without employer sponsorship, now or at any time in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Active Directory
- Linux
- Windows
- Cobalt Strike (C2 Framework)
- Havoc
- Sliver
- AWS
- Azure
- GCP
The Team
- Cyber Defense & Resilience supports clients defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence
- Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response to enable readiness, response, and recovery from business disruptions
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Location
- Baltimore, MD (onsite)
Compensation
- Salary range: USD 110,700 - 218,300 per year
In making compensation decisions, Deloitte considers a wide range of factors; a reasonable estimate of the current range is $110,700-$218,300, and it is not typical to hire at the top of the range. Compensation depends on the facts and circumstances of each case.
Minimum Experience
- 2 years