Security Engineer; Offensive; Red Team Adversary Emulation Tech Lead
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, Information Security & Data Protection
Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.
We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations (PCO) to join one of only eleven Department of War (DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United States Cyber Command (USCYBERCOM). This team is based out of Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security.
You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.
The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.
Responsibilities- Primary role will be to plan and conduct Red Team Persistent Cyberspace Operations (PCO) Adversary Emulation as a Tech Lead in this specific Red Team capability area. This includes conducting long-term persistence emulating an intel-driven Advanced Persistent Threat (APT).
- This position may likely include supporting and conducting other roles within the Red Team, to include:
- Both Operational Technology (OT) and Information Technology (IT) vulnerability assessments
- Acquisition Penetration Testing (APT) via Adversarial Assessments of DoW systems
- Support exercise objectives and training goals as an Opposing Force Aggressor (OFA)
- Assist in the instruction of the customer's Red Team Operations Course (RTOC)
- Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.
- Identify and exploit network, host, and application-level vulnerabilities.
- Develop and refine proof-of-concept exploits and techniques to test defensive measures.
- Produce detailed technical findings and recommendations for remediation.
- Collaborate with defensive and engineering teams to improve detection and response.
- Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.
- Participate in after-action reviews and contribute to policy and playbook updates.
- Prepare, update, document, and present course materials that cover TTPs.
- Provide support required to maintain the customer’s Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.
- Schedule:
Mon-Fri onsite at Quantico, VA. May likely include some travel.
- TS/SCI eligibility
- 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).
- Possess and maintain a DoD 8570 IAT Level III certification:
SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP. - Possess and maintain a DoD 8570 CSSP Auditor certification:
CySA+, CEH, CISA, GSNA, CFR, Pen Test. - Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements:
CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA. - Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).