CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte’s Cyber Defense & Resilience team is hiring a Security Engineer III Red Team Operator to plan and run authorized adversary emulation, penetration testing, and social engineering activities.

Responsibilities

  • Plan and execute red team operations targeting enterprise environments, web applications, cloud platforms, and endpoints
  • Emulate advanced threat actors using realistic attack paths, tools, and techniques
  • Run simulations across the attack lifecycle, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
  • Evaluate security controls by assessing monitoring and incident response effectiveness
  • Perform authorized phishing and social engineering or credential attack exercises
  • Develop custom payloads, scripts, and attack workflows to support engagements
  • Document findings, including attack chains, defense gaps, and remediation recommendations
  • Deliver after-action reports and debriefs to technical and leadership stakeholders
  • Collaborate with blue teams, detection engineers, and security leadership to strengthen defensive capabilities
  • Follow strict rules of engagement, legal requirements, and operational safety procedures

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance
  • Ability to work onsite up to 5 days a week (Baltimore, MD)
  • 1+ years experience in offensive security focused on red teaming, purple teaming, or adversary simulation
  • Knowledge of network architecture, protocols, and techniques such as tunneling
  • Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
  • Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques
  • Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
  • Experience with MITRE ATT&CK mapping and threat emulation
  • Ability to write high-quality reports connecting technical findings to business risk
  • Ability to travel 20% on average, based on client needs and sectors
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Cobalt Strike
  • Mythic
  • Metasploit
  • BloodHound
  • Burp Suite
  • Nmap
  • PowerShell
  • Python
  • MITRE ATT&CK
  • Active Directory

Preferred

  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
  • Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
  • Experience with cloud red teaming in AWS, Azure, or GCP
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises
  • Experience developing custom tooling or modifying public offensive tools
  • Knowledge of malware analysis, reverse engineering, or exploit development

Benefits

  • May be eligible to participate in a discretionary annual incentive program, subject to program rules and factors including individual and organizational performance

Compensation

  • Salary range: USD 88,800 - 162,800 per year
  • Range reflects a wide set of factors used in compensation decisions

Similar Jobs