- Plan and lead covert, objective-based red team operations from scoping and rules of engagement through execution and debriefing.
- Emulate real-world adversaries across enterprise and cloud environments, including Windows, Linux, Active Directory, Azure, AWS and GCP, by combining misconfigurations into complete attack paths.
- Build custom tools, payloads and C2 infrastructure to test the effectiveness of EDR, SIEM and other modern defenses.
- Conduct social-engineering and physical-intrusion activities where permitted by scope and move effectively between attack vectors.
- Write clear reports and brief both engineers and executives, translating technical risk into concrete actions.
- Mentor penetration testers, improve our methodology and incorporate field experience into Radar, Breach and Guard.
What you bring
- At least five years of offensive-security experience, including two or more years leading objective-based red team operations.
- Deep knowledge of Active Directory attack paths, cloud abuse and post-exploitation techniques, with the ability to develop custom tools in C#, Python, PowerShell or Go.
- Hands-on experience with frameworks such as Cobalt Strike, Mythic and BloodHound, as well as modern offensive-security tooling.