Security Engineer III, Red Team Operator
Active Directory
Bloodhound
Burp Suite
Cobalt Strike
Cybersecurity Tools
Data Security
Desktop Support
Embedded System
End User Support
Engineer
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Metasploit
Nmap
Offensive Security
Operating System
Operating Systems
Penetration Testing
Powershell
Project Management
Red Team
Risk Management
Security
Security Engineering
Security Operations
Security Testing
Software Development
Systems
Technical Support
Unix Operating System
Windows
Job Description
Deloitte’s Cyber Defense & Resilience team is seeking a Security Engineer III to support authorized adversary emulation and assessment activities. In this role, you will plan and execute red team operations designed to test detection, response, and resilience across enterprise environments.
This onsite position is based in Rosslyn, VA, with a focus on realistic attack simulation, post-exploitation activities, and clear reporting back to technical and leadership stakeholders.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run reconnaissance and simulation sequences for initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Conduct phishing, social engineering, and credential-focused exercises when explicitly authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Provide after-action reports and debriefs to technical and leadership stakeholders.
- Partner with blue teams, detection engineers, and security leadership to strengthen defensive capabilities.
- Follow strict rules of engagement, legal requirements, and operational safety procedures.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- Knowledge of network architecture, protocols, and techniques such as tunneling.
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Tool proficiency including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience mapping to MITRE ATT&CK and performing threat emulation.
- Ability to write high-quality reports that connect technical findings to business risk.
- CRTO (Certified Red Team Operator) or OSCP (Offensive Security Certified Professional).
- Ability to travel about 20% on average based on client needs and industries served.
- Legal authorization to work in the United States without employer sponsorship, now or in the future.
- Ability to work independently and collaborate with a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and strong work product quality.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Capability to manage and prioritize multiple tasks in a fast-paced environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to provide clear guidance to others.
Technologies
- Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap
- PowerShell, Python
- MITRE ATT&CK, Active Directory
- Windows, Linux
- C2 frameworks, Havoc, Sliver
- AWS, Azure, GCP
- SIEM, EDR
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
Compensation
The estimated wage range for this role is $110,700 - $218,300 per year, based on multiple factors used to determine compensation.