Red Team Operator - Assistant Director
Job in
Frankfort, Franklin County, Kentucky, 40621, USA
Listed on 2026-07-25
Listing for:
EY
Full Time
position Listed on 2026-07-25
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets!
Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
** The opportunity*
* As a Red Team Operator within the Attack Surface Management team, you will emulate advanced threat actors through offensive security testing and adversary emulation. You will identify vulnerabilities, demonstrate business and operational risks, and provide actionable recommendations to improve defenses.
** Your key responsibilities*
* + Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact.
+ Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures.
+ Perform social engineering (e.g., phishing) as part of integrated engagements.
+ Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks.
+ Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
+ Produce high-quality deliverables: detailed technical reports, executive summaries, risk assessments, and remediation recommendations.
+ Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts).
+ Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development.
** Skills and attributes for success*
* + Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, Blood Hound, Nmap, Burp Suite, and others).Demonstrated ability to thinking critically
+ Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols.
+ Proficiency in scripting/programming (Python, Power Shell, Bash, etc.) for automation and custom tooling.
+ Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders.
+ Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence.
+ Independently research and stay knowledgeable of Threat Actor TTP's and how they may be leveraged.
+ Excellent analytical, problem-solving, and technical writing skills.
+ Strong teamwork, independence, and communication skills.
** To qualify for the role you must have*
* + 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security.
+ Demonstrated experience executing red team or advanced penetration testing engagements.
+ Relevant certifications including OSCP, CPTS (or equivalents such as GPEN, CRTO, OSEP, OSCE).
+ Ability to work effectively in a fully remote environment.
** Ideally, you'll also have*
* +
Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU).
+ Prior consulting or client-facing experience (where applicable).
+ Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering.
+ Creation of, or contributions to open-source tools or projects, CTF participation, or public research/blogging.
** What we look for*
* We are looking for a senior operator that can operate autonomously and bring new, strategic approaches to discovering and evaluating the firm's attack surface to improve the overall security posture. We are seeking a seasoned operator to improve the organization's ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
** What we…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×