Security Engineer III, Red Team Operator; TS Clearance
Listed on 2026-06-18
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Overview
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever‑changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Role PurposeWe are seeking a skilled Red Team Operator to simulate real‑world adversary tactics, techniques, and procedures to assess and improve the organization’s detection, response, and resilience capabilities. The role is responsible for planning and executing adversary emulation, penetration testing, social engineering, and post‑exploitation activities in a controlled and authorized manner.
Work You’ll Do- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Conduct reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration simulations.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Perform phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Deliver clear after‑action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or work streams
- Ability to manage and prioritize multiple tasks in a fast‑paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top‑Secret Clearance
- Ability to work onsite up to 5 days a week
- 2+ years of experience with knowledge of network architecture, protocols, and techniques (e.g., tunneling); hands‑on offensive security experience in red teaming, purple teaming, or adversary simulation; strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments; experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques; proficiency with tools such as Cobalt Strike, Mythic, Metasploit, Blood Hound, Burp Suite, Nmap, Power Shell or Python;
experience with MITRE ATT&CK mapping and threat emulation; ability to write high‑quality reports that connect technical findings to business risk. - Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP)
- Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
The wage range for this role is $102,500 – $188,900. You may also be eligible to participate in a discretionary annual incentive program.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).