Senior Consultant, Human Threats
Listed on 2026-09-20
-
Security
Cybersecurity
About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Position Summary:
The Human Threats Senior Consultant will serve as a senior technical consultant on the Division Hex Human Threats team, assessing the security posture and human-centered detection and response capabilities of client organizations. The role will place a strong emphasis on authorized physical security assessments, including facility access controls, perimeter and entry-point security, visitor and badge-management processes, secure-area protections, employee behaviors, and other physical safeguards.
The Senior Consultant will also perform and support social engineering activities, including phishing, vishing, pretext development, human risk assessment, and awareness and behavior measurement, to evaluate how physical and digital attack paths can exploit people, processes, and technology.
The ideal candidate will bring expert-level knowledge of physical security assessment methodologies and adversary tradecraft, along with deep experience in one or more social engineering disciplines. They will work with the Managing Principal of Human Threats, Project Managers, Directors, and client Points of Contact to plan and execute engagements, meet project requirements, and provide subject matter expertise across social engineering domains.
As a trusted client advisor, the Senior Consultant will use objective testing, onsite assessment activities, social engineering exercises, and clear reporting to help clients identify weaknesses, prioritize remediation, and improve resilience against physical and other human-centric threats.
- Conduct human threat engagements, including social engineering, phishing, vishing, physical security assessments, and human risk evaluations.
- Plan, scope, and execute physical security assessments across facilities, offices, campuses, and other client locations in accordance with approved rules of engagement.
- Evaluate physical security controls, including perimeter protections, entry points, locks, badges, visitor management, reception procedures, secure areas, employee access practices, and related processes.
- Develop assessment scenarios, pretexts, and test plans that safely evaluate how physical and social engineering techniques may be combined to gain access to people, facilities, information, or technology.
- Coordinate onsite logistics, client communications, safety considerations, evidence collection, and testing activities while maintaining strict adherence to scope and client authorization.
- Document observations and evidence through accurate notes, timestamps, photographs, interviews, and other appropriate assessment records, while protecting sensitive client information.
- Deliver timely client briefings and debriefs that clearly communicate physical security gaps, social engineering results, business impact, and prioritized remediation actions.
- Manage priorities and tasks to achieve delivery utilization targets and ensure client deliverables and services are delivered on time.
- Maintain current industry certifications and knowledge of emerging physical security, social engineering, and human threat tactics, technologies,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).