Security Engineer III, Red Team Operator (TS Clearance)
Senior
Cloud Platforms
Cobalt Strike
Cybersecurity Tools
Data Security
Endpoint Security
Engineer
Ethical Hacking
Facilities Management
Incident Response
Information Security
InfoSec
Management
Metasploit
Mitre Att&ck
Offensive Security
Penetration Testing
Pentesting Tools
Project Management
Red Team
Red Team Operator
Risk Management
Security
Security Automation
Security Clearance
Security Operations
Security Standards
Security Testing
Security Testing Tools
Job Description
Operate as an adversary simulation specialist to test and strengthen enterprise detection, response, and resilience.
Responsibilities
- Plan and carry out red team engagements across enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actors using realistic attack paths, tools, and techniques
- Simulate reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate the effectiveness of security controls, monitoring, and incident response processes
- Conduct authorized phishing, social engineering, and credential attack exercises
- Create custom payloads, scripts, and attack workflows to support engagement objectives
- Document findings, attack chains, defense gaps, and remediation recommendations
- Produce after-action reports and technical debriefs for stakeholders, including leadership
- Partner with blue teams, detection engineers, and security leadership to improve defensive capabilities
- Follow rules of engagement, legal requirements, and operational safety standards
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret clearance
- Ability to work onsite in Rosslyn, VA up to 5 days a week
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation
- Strong command of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques
- Proficiency with Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, plus PowerShell or Python
- Experience mapping activities to MITRE ATT&CK and performing threat emulation
- Ability to write high-quality reports linking technical findings to business risk
- CRTO (Certified Red Team Operator) or OSCP (Offensive Security Certified Professional)
- Ability to travel 20% on average based on client needs and served industries/sectors
- Legally authorized to work in the United States without employer sponsorship now or in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
Team and Work
- Red Team Operator role on the Cyber Defense & Resilience team focused on adversary emulation and improving defensive readiness
- Deloitte Cyber Defense & Resilience supports clients by transforming security operations, monitoring technology, data analytics, and threat intelligence
- Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response to support readiness, response, and recovery from business disruptions
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Cloud red teaming experience in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Compensation
- Estimated wage range: $110,700 - $218,300 USD per year
- May be eligible for a discretionary annual incentive program based on applicable rules, individual performance, and organizational performance