More jobs:
Senior Red Team Operator
Job in
New York, New York County, New York, 10261, USA
Listed on 2026-09-02
Listing for:
Covington & Burling LLP
Full Time
position Listed on 2026-09-02
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
- Minimum of 6–10 years’ experience in offensive security, penetration testing, red teaming, exposure management, and/or advanced vulnerability management roles.
- Demonstrated hands-on experience conducting penetration tests, red team exercises, attack simulations, or adversary emulation, either internally or via consulting, MSSP, or internal security teams.
- Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile applications (android/iOS), including the use of industry-standard tools (e.g., Burp Suite, Nmap, Metasploit, etc.).
- Be capable of leveraging AI-powered toolsets for day-to-day functions such as modernized exploitation and reporting tasks.
- Strong understanding of modern attack chains, including initial access, privilege escalation, lateral movement, persistence, command and control, and data exfiltration.
- Deep knowledge of common vulnerability types and exposure classes, including CVEs, misconfigurations, identity weaknesses, end-of-life software, insecure architectures, supply chain dependencies, and cloud control gaps.
- Proven ability to validate vulnerabilities in real-world conditions, distinguish theoretical findings from exploitable risk, and communicate impact clearly to technical and non-technical stakeholders.
- Strong written and verbal communication skills, with the ability to translate technical findings into risk-informed narratives that support prioritization and remediation.
- Demonstrates intellectual curiosity and maintains awareness of current threat actor behaviors, CTI reporting, exploit trends, and emerging attack techniques.
- Experience working collaboratively with vulnerability management, SOC, engineering, IT operations, and risk teams.
- Experience working with offensive artificial intelligence solutions/tools preferred.
- Bachelor’s degree in computer science, cybersecurity, or related field preferred but not required.
- Offensive and/or technical certifications preferred (e.g., OSCP, OSCE, CRTO, GXPN, GPEN, GWAPT, or equivalent experience).
- Conduct penetration testing, red team activities, and adversary emulation across enterprise environments, including endpoints, servers, identity platforms, applications, and cloud services.
- Leverage AI-powered resources to conduct red team, pentesting, and vulnerability management activities.
- Validate vulnerabilities identified through automated scanning, CTI, or third-party reporting to determine exploitability, attack paths, and real-world impact.
- Identify chained vulnerabilities, misconfigurations, or systemic weaknesses that increase exposure beyond individual CVE severity scores.
- Contribute to purple team engagements by collaborating with detection and incident response teams to evaluate monitoring coverage and response effectiveness.
- Act as a senior contributor within the vulnerability management lifecycle, enhancing triage accuracy by providing exploit validation and technical depth.
- Support risk-based prioritization by mapping vulnerabilities to likely attack paths, asset criticality, and existing compensating controls.
- Collaborate with VM analysts to improve assessment quality, reduce false positives, and identify high-risk exposures that warrant immediate action or leadership escalation.
- Stay current on cyber threat intelligence trends, exploit development, and active threat actor campaigns relevant to enterprise and legal services environments.
- Apply CTI insights to vulnerability assessment, helping identify which vulnerabilities are actively weaponized versus low-risk background noise.
- Partner with IT and security teams to clearly explain findings, recommend solutions, and validate remediation effectiveness.
- Document findings clearly in internal ticketing and reporting systems, articulating technical detail, business impact, recommended remediation, and residual risk.
- Contribute to the evolution of exposure management practices, including documentation, validation workflows, metrics, and continuous improvement of the VM program.
- Apply sound judgment, prioritize work effectively, and communicate emerging risks with appropriate urgency and professionalism.
- Pe…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×