
Senior Consultant, Adversary Services – Red Team
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Oversee red team, adversary emulation, and purple team initiatives for clients spanning various industries and environments, advising on suitable remediation strategies, with reporting aligned to MITRE ATT&CK and other pertinent frameworks.
• Evasion of detection and response, development of innovative tactics and exploits, simulation of threat actor TTPs, and the advancement of sophisticated command and control (C2) infrastructures.
• Serve as a trusted advisor to our clients regarding security issues, offering insights and recommendations to guide strategic decision-making.
• Design and implement advanced offensive cybersecurity practices to achieve initial access, maintain persistence, elevate privileges, conduct lateral movement, and avoid detection and response measures.
• Remain updated on emerging security threats and trends, proactively pinpointing improvement opportunities to bolster our security posture.
• Create and sustain custom exploit code, scripts, and tools to automate and enhance adversary services activities.
• Contribute to internal tradecraft, reusable tools, testing methodologies, and team knowledge transfer.
• Promote thought leadership through research, internal training, blog posts, conference presentations, or customer workshops.
• At least 5 years of experience in penetration testing, adversary services/red teaming, and purple teaming, including a minimum of 2 years leading covert Red Team operations.
• Extensive experience in creating and delivering specialized testing for clients focused on the latest threat actor TTPs and capabilities, including advanced persistent threats (APTs), ransomware, and insider threats.
• Demonstrated experience in presenting thought leadership, including speaking engagements at security conferences, blogging, or participating in other forums.
• Profound technical knowledge in adversary services-related tradecraft, encompassing the development and management of command and control infrastructure, custom development of leading C2 toolsets (e.g., Cobalt Strike, Sliver, Mythic), and mastery of evasion techniques to optimize effectiveness.
• Significant experience executing adversary services engagements across various platforms and environments, including on-premise, cloud, and hybrid settings.
• Exceptional communication and collaboration skills, with the ability to effectively articulate complex technical concepts to both technical and non-technical audiences.
• Comprehensive understanding of all components of the attack chain, including OSINT, social engineering (e.g., phishing, vishing), custom payload creation, C2 infrastructure, lateral movement, privilege escalation, and impact objectives.
• Technical proficiency in programming and scripting languages (e.g., Python, Ruby, Go) to design and adjust custom evasion tools and infrastructure.
• Capacity to excel in a fast-paced, dynamic environment, adapting swiftly to changing priorities and requirements.
• Ability to cultivate a positive work atmosphere and mindset, demonstrating a “team first” attitude.
• Paid parental leave
• Flexible time off
• Certification and training reimbursement
• Digital mental health and wellbeing support membership
• Comprehensive insurance options
ToxStrategies, a BlueRidge Life Sciences Company
Outreach
Get handpicked remote jobs straight to your inbox weekly.