×
Register Here to Apply for Jobs or Post Jobs. X

Red Team Member

Job in Baltimore, Anne Arundel County, Maryland, 21276, USA
Listing for: Creative Global Consulting
Full Time position
Listed on 2026-06-13
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 60000 USD Yearly USD 60000.00 YEAR
Job Description & How to Apply Below

Client:
Maryland Health Benefit Exchange (MHBE)

POP: 12+ months

Location:

Hybrid;
Baltimore, MD

Required Skills
  • A Minimum eight (8) years of progressive experience in cybersecurity
  • A minimum of five (5) years performing penetration testing or red team engagements.
  • A minimum of five (5) years conducting network penetration testing, web application and API testing, internal and external vulnerability assessments and threat modeling and attack path analysis
  • A minimum of five (5) years developing and delivering formal penetration test reports, including executive summaries and technical remediation guidance.
  • A minimum of five (5) years supporting incident response investigations and validation testing.
  • A minimum of five (5) years with common penetration testing tools (e.g., Metasploit, Burp Suite, Nmap, Wireshark, Nessus, etc.).
  • Strong knowledge of Secure coding practices, Application security testing (SAST/DAST concepts), Network architecture and segmentation and Identity and access management concepts
  • A minimum of five (5) years of demonstrated scripting or development ability in at least one language (e.g., Python, C/C++, Power Shell, Bash).
  • A minimum of five (5) years of working with NIST Cybersecurity Framework, NIST 800-53 or similar federal control frameworks, MITRE ATT&CK and OWASP Top 10
  • A minimum of five (5) years of experience mapping findings to security control frameworks.
  • At least one recognized offensive security certification (e.g., OSCP, GPEN, GXPN, CEH, or major experience can substitute for certification).
  • Demonstrated ability to communicate technical findings to executive and non-technical audiences, and provide actionable remediation recommendations.
  • Demonstrated experience working in government or highly regulated environments.
Preferred Skills
  • A minimum of ten (10) years of progressive experience in cybersecurity
  • A minimum of eight (8) years of experience in Advanced Offensive Security:
  • Experience leading red team engagements.
  • Experience performing adversary emulation exercises.
  • Experience conducting phishing and social engineering simulations.
  • Experience performing purple team exercises.
  • A minimum of five (5) years of experience in Zero Trust & Architecture:
  • Experience designing or assessing Zero Trust implementations.
  • Experience evaluating micro-segmentation strategies and identity-centric controls.
  • A minimum of five (5) years of experience in Cloud & Modern Infrastructure:
  • Experience performing security assessments in AWS or Azure environments, Containerized environments (Docker/Kubernetes) and Infrastructure-as-Code deployments
  • Experience testing CI/CD pipelines.
  • A minimum of ten (10) years of experience in Software Development Depth:
  • Strong low-level development knowledge (kernel, assembly, embedded systems) that supports advanced exploit analysis.
  • Experience reviewing source code in JAVA or other compiled languages for vulnerabilities.
  • A minimum of ten (10) years of experience in Government in the following:
  • Experience supporting federal or state government security programs.
  • Familiarity with FedRAMP, FISMA, or IRS Pub 1075 environments.
Tasks
  • Conduct internal and external penetration testing of networks, web applications, APIs, and cloud environments to identify security vulnerabilities and exploit paths.
  • Perform red team engagements simulating real-world adversary tactics, techniques, and procedures (TTPs) aligned with MITRE ATT&CK.
  • Execute vulnerability assessments and validate remediation efforts through retesting and technical verification.
  • Develop comprehensive penetration testing reports, including executive summaries, risk ratings, proof-of-concept evidence, and actionable remediation guidance.
  • Perform threat modeling and attack surface analysis to identify high-risk exposure areas and privilege escalation pathways.
  • Conduct secure configuration reviews of operating systems, network infrastructure, cloud platforms, and identity systems.
  • Evaluate application security through dynamic and manual testing techniques, including authentication, session management, input validation, and access control testing.
  • Review source code for security weaknesses and secure coding gaps, particularly in C/C++, Python, Java, or similar languages.
  • Develop and maintain custom scripts or tooling to automate testing activities and enhance offensive security capabilities.
  • Support incident response activities by recreating attack chains, validating compromise scenarios, and identifying root causes.
  • Assess Zero Trust implementations, micro-segmentation strategies, and identity-based security controls for effectiveness.
  • Conduct phishing simulations and social engineering exercises to evaluate user awareness and organizational resilience.
  • Provide technical briefings to executive leadership and technical stakeholders regarding risk posture and remediation prioritization.
  • Collaborate with engineering, Dev Ops, and infrastructure teams to remediate identified vulnerabilities and strengthen security architecture.
  • Contribute to the development of security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary