
Offensive Security Technical Lead
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States.
• Act as the principal technical authority for penetration testing and red-team operations within the RFS portfolio.
• Establish and enhance assessment standards, rules of engagement, technical review checkpoints, evidence requirements, severity methodologies, reporting expectations, and reusable playbooks.
• Evaluate and authorize engagement plans, adversary scenarios, infrastructure designs, tooling exceptions, exploitation strategies, data-handling controls, and high-risk technical actions.
• Direct the technical team, allocate specialized roles, mentor personnel, conduct technical readiness evaluations, and address intricate cross-domain issues.
• Provide direct support for challenges related to network, application, Active Directory/identity, cloud, exploit development, adversary infrastructure, and defense evasion.
• Ensure the final technical quality and acceptance of assessment reports, attack-path narratives, severity determinations, remediation suggestions, customer debriefs, and purple-team scenarios.
• Lead technical discussions with customers and convey mission and business risks effectively.
• Collaborate with project management on timelines, staffing, dependencies, and issue escalation without taking on administrative PM responsibilities.
• Document lessons learned, assess technical quality and repeatability, and advance the capability as customer processes and tools evolve.
• Contribute to the CDM Program’s mission to protect and secure U.S. Federal IT networks through continuous monitoring, diagnosis, and mitigation services.
• U.S. citizenship is mandatory.
• Must be eligible for access to sensitive information and capable of obtaining a Public Trust fitness determination (High Risk).
• Competence to operate in customer-provided remote settings and adhere to rules of engagement, data-handling protocols, evidence controls, deconfliction procedures, and stop-work criteria.
• A minimum of eight years of progressively responsible offensive-security experience, including substantial hands-on penetration testing and red-team/adversary-emulation delivery.
• At least five years of experience leading complex technical engagements, multiple concurrent assessments, or senior offensive-security teams.
• Expert ability to scope and manage safe testing across enterprise networks, applications/APIs, Windows/Active Directory and identity, Linux, AWS/Azure, external attack surfaces, and production environments.
• Proven technical authority in rules of engagement, operational risk, deconfliction, exploit validation, evidence quality, severity decisions, report acceptance, and customer debriefing.
• Strong capabilities in scripting, automation, or tool development.
• One or more advanced hands-on certifications such as OSEP/OSCE, OSWE, GXPN, GPEN, OSED/OSEE, CRTO/CRTL, or equivalent expert-level experience.
• Desired twelve or more years in offensive security, security research, adversary emulation, or technical-assessment leadership.
• Experience in leading CISA, DHS, federal high-value-asset, critical-infrastructure, ICS/OT, or similarly sensitive assessment programs is preferred.
• Experience in enhancing an offensive-security program, establishing quality metrics, developing training, or creating repeatable technical delivery standards is desirable.
• Advanced expertise in cloud, identity, exploit development, malware/payload, detection engineering, or purple team operations is preferred.
• Ability to brief senior government leadership and interpret technical attack paths into operational and mission risk is a plus.
• Unique flexible time off benefit.
• Comprehensive learning resources.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Flexible work-life balance.
Webflow
RecruityTalent
Viceri SEIDOR
Ponta
Get handpicked remote jobs straight to your inbox weekly.