Security Engineer III, Red Team Operator
Job Description
Join Deloitte’s Cyber Defense & Resilience team to plan and run authorized adversary emulation engagements that strengthen detection, response, and resilience.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Simulate reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Run phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagement objectives.
- Document findings, attack chains, defense gaps, and remediation recommendations.
- Deliver after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Operate under strict rules of engagement, legal requirements, and safety procedures.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days per week in Rosslyn, VA.
- Knowledge of network architecture, protocols, and techniques (including tunneling).
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, PowerShell, and Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports that tie technical findings to business risk.
- Certified CRTO or OSCP.
- Ability to travel 20% on average, based on work, client engagements, and industries/sectors served.
- Legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- MITRE ATT&CK mapping
- Active Directory
- Windows
- Linux
- Cloud
- Command and control frameworks
Salary
- USD 110,700 - 218,300 per year
Benefits
- Eligible for a discretionary annual incentive program, subject to program rules.
Skills for a Successful Candidate
- Independently perform work while collaborating as part of a team.
- Effective written and verbal communication.
- Meticulous attention to detail and quality of work product.
- Build and sustain professional relationships.
- Lead projects or workstreams.
- Manage and prioritize multiple tasks in a fast-paced, dynamic environment.
- Strong interpersonal skills and professional demeanor.
- Meet deadlines.
- Provide clear guidance to others.
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.