Security Engineer III, Red Team Operator
Active Directory
Burp Suite
Cloud Platforms
Cobalt Strike
Command And Control
Endpoint Security
Engineer
Ethical Hacking
Identity and Access Management
Incident Response
Information Security
InfoSec
Metasploit
Mitre Att&ck
Nmap
Offensive Security
Penetration Testing
Powershell
Red Team
Red Team Operator
Security
Security Engineer
Security Testing
Job Description
Join Deloitte as a Red Team Operator supporting authorized adversary emulation, penetration testing, and social engineering to strengthen detection and response capabilities.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actors using realistic attack paths, tools, and techniques
- Run simulations for reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate the effectiveness of security controls, monitoring, and incident response processes
- Conduct authorized phishing, social engineering, and credential-focused attack exercises
- Develop custom payloads, scripts, and attack workflows to support engagement objectives
- Document findings, attack chains, defense gaps, and remediation recommendations
- Produce after-action reports and debriefs for technical and leadership stakeholders
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capability
- Follow strict rules of engagement, legal requirements, and operational safety practices
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days per week (Rosslyn, VA)
- 1+ years of experience in offensive security activities such as red teaming, purple teaming, or adversary simulation
- Knowledge of network architecture, protocols, and techniques (example: tunneling)
- Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques
- Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
- Experience with MITRE ATT&CK mapping and threat emulation
- Ability to write high-quality reports connecting technical findings to business risk
- Ability to travel 20% on average based on work, clients, and industry/sector
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Windows
- Active Directory
- Linux
- Cloud
- Identity environments
- Command and control frameworks
Preferred
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Benefits
- Discretionary annual incentive program eligibility, subject to program rules and factors including individual and organizational performance
Salary range: USD 88,800 - 162,800 per year.