Senior Consultant, Human Threats

atCoalfireRemoteUS flagUnited StatesFull-timeConsultantSenior$146k – $180k/year

Posted Sep 15

This is a fully remote position, open to applicants in United States.

📋 Description

• Engage in human threat operations, which include social engineering, phishing, vishing, authorized physical security evaluations, and assessments of human risk.

• Strategize, define, and carry out physical security evaluations across various facilities, offices, campuses, and client sites under established rules of engagement.

• Assess perimeter security measures, access points, locks, badges, visitor management processes, reception protocols, secure areas, and employee access practices.

• Conduct onsite evaluations and walkthroughs to uncover opportunities for unauthorized access, control bypasses, tailgating, weak access governance, and other vulnerabilities.

• Create assessment scenarios, pretexts, and testing plans that integrate both physical and social engineering methods.

• Manage onsite logistics, client communication, safety considerations, evidence gathering, and testing tasks within the authorized framework.

• Record observations and evidence through notes, timestamps, photographs, interviews, and other evaluation documents.

• Analyze findings, categorize risk-based results, and suggest enhancements to facility security, access management, detection, response, and resilience.

• Draft, review, and approve Human Threat reports.

• Present client briefings and debriefs that outline security vulnerabilities, social engineering findings, business implications, and recommended remediation actions.

• Prioritize tasks and manage responsibilities to achieve delivery utilization targets and ensure timely outputs.

• Provide guidance to clients and foster collaborative relationships with clients and stakeholders.

• Keep up-to-date with industry certifications and trends related to physical security, social engineering, and human threat developments.

• Identify opportunities for up-selling and cross-selling and communicate these to the sales team.

• Collaborate with project managers, quality assurance, sales, and delivery team members.

• Mentor junior consultants in physical assessment methods, social engineering, client communication, reporting, and engagement execution.

• Develop and enhance Human Threat methodologies, tools, playbooks, and service offerings.

• Contribute to thought leadership through research, blogs, whitepapers, webinars, and presentations at conferences.

• Support the development of the Human Threat practice through research, service innovation, and engagement with external industry content.

• Represent Coalfire at industry events, client briefings, and conferences.

• Participate in other offensive security operations as necessary.

• Undertake additional responsibilities that support client delivery, practice growth, and team success.


⛳️ Requirements

• 5–8 years of consulting experience in client-facing roles.

• 3–5 years of expertise in social engineering, red team operations, insider risk, or physical security.

• Proficiency in social engineering techniques and principles.

• Experience in phishing, vishing, smishing, and other communication-based attack strategies.

• Ability to develop pretexts and emulate adversaries targeting human subjects.

• Conduct human risk assessments and evaluations focusing on behavior-based security.

• Skilled in report writing and delivering presentations to clients.

• Understanding of current tactics, techniques, and procedures utilized by threat actors involving human targets.

• Familiarity with physical security concepts and vulnerabilities related to badge/access control.

• Knowledge of email security protocols, identity-based assaults, and user-targeted attack pathways.

• Awareness of security culture, behavior change principles, and safety measures.

• Willingness to travel up to 75% of the time.

• Strong writing abilities, personal accountability, and capacity to meet established standards independently.

• Experience in planning and executing authorized physical security evaluations, facility walkthroughs, access control assessments, and onsite testing.

• Comprehensive understanding of physical security principles and controls, including perimeter security, access points, locks, badges, visitor management, reception procedures, secure areas, and employee access practices.

• Capability to formulate assessment plans, scenarios, pretexts, rules of engagement, and safety protocols.

• Strong situational awareness, sound judgment, discretion, and professionalism.

• Ability to identify, document, assess, and convey physical and human-centered security weaknesses along with practical remediation suggestions.

• Proficient in communicating intricate security concepts through written material, client presentations, executive briefings, and public speaking engagements.

• Excellent communication, teamwork, and presentation skills.

• Strong time management skills and ability to handle multiple priorities, engagements, deadlines, and onsite demands.

• Ability to safeguard sensitive client information and maintain accurate assessment documentation and engagement records.

• Willingness and capability to travel to client locations and engage in onsite assessments as required.

• ASIS Certified Protection Professional certification or an equivalent physical security credential is advantageous.

• Familiarity with physical red team tactics and techniques is a plus.

• Experience in executive protection or targeted social engineering against executives is beneficial.

• Background in behavioral science, psychology, or influence training is a bonus.

• Insight into threat intelligence related to social engineering campaigns and the tactics of threat actors is advantageous.

• Experience in developing insider risk programs is beneficial.

• Capability in creating training materials and facilitating workshops is a plus.

• Social engineering experience related to hardware, badges, or access control is an advantage.

• Published works, blogs, whitepapers, or presentations on topics like social engineering, human threats, or offensive security is a bonus.


🏝️ Benefits

• Flexible work arrangements that allow for remote work or office presence.

• Employee resource groups to foster inclusion.

• Opportunities for both in-person and virtual events.

• Paid parental leave for employees.

• Flexible time-off policies.

• Reimbursement for certifications and training.

• Membership for digital mental health and wellness support.

• Comprehensive insurance options available.

• Eligibility for annual incentives, commissions, and/or recognition programs.

People also viewed

dentsu Austria1 day ago

Senior Consultant, Digital Media

CA flagCanada OnlyFull-timeConsultantC$80k – C$90k/year
ApplyView job
GHY International1 day ago

Customs Trade Consultant

US flagNorth Dakota, +1 more stateFull-timeConsultant$55k – $65k/year
ApplyView job
GHY International1 day ago

Customs Trade Consultant

US flagNew York, +1 more stateFull-timeConsultant$55k – $65k/year
ApplyView job
GHY International1 day ago

Customs Trade Consultant

US flagNorth Carolina, +1 more stateFull-timeConsultant$55k – $65k/year
ApplyView job
Health Care Service Corporation1 day ago

Analytics & Reporting Consultant

US flagIllinois OnlyFull-timeConsultant$84.4k – $152.3k/year
ApplyView job
Brown & Brown Insurance1 day ago

Managing Consultant

US flagUnited States OnlyFull-timeConsultant$250k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers