Security Engineer III, Red Team Operator
Job Description
Deloitte is seeking a Red Team Operator to plan and execute authorized adversary emulation and penetration testing activities that help evaluate and strengthen detection, response, and resilience across enterprise environments.
Role Location and Work Model
Location: Baltimore, MD (onsite)
Onsite expectation: Ability to work onsite up to 5 days a week.
Travel: Ability to travel 20%, on average, based on work activities and client and industry needs.
Compensation
Salary range: USD 110,700 to 218,300 per year.
The wage range for this role takes into account a reasonable estimate of the current range of $110,700–$218,300.
Responsibilities
- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Run simulations across the lifecycle of an intrusion, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
- Evaluate the effectiveness of security controls, monitoring, and incident response processes.
- Conduct phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document engagement outcomes, attack chains, defense gaps, and remediation recommendations.
- Provide clear after-action reports and technical debriefs for both technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- 2+ years of experience within network architecture and offensive security practice, including red teaming, purple teaming, or adversary simulation.
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling).
- Hands-on offensive security experience across enterprise attack techniques spanning Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports that connect technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20%, on average, and to work onsite up to 5 days a week.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Active Directory
- Windows
- Linux
Benefits
- Participation in a discretionary annual incentive program, subject to the rules governing the program.
Additional Skills (Success Factors)
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to provide clear guidance to others.
Preferred Qualifications
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver.
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
Education
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.