
Senior Consultant, Human Threats
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Engage in human threat operations, which include social engineering, phishing, vishing, authorized physical security evaluations, and assessments of human risk.
• Strategize, define, and carry out physical security evaluations across various facilities, offices, campuses, and client sites under established rules of engagement.
• Assess perimeter security measures, access points, locks, badges, visitor management processes, reception protocols, secure areas, and employee access practices.
• Conduct onsite evaluations and walkthroughs to uncover opportunities for unauthorized access, control bypasses, tailgating, weak access governance, and other vulnerabilities.
• Create assessment scenarios, pretexts, and testing plans that integrate both physical and social engineering methods.
• Manage onsite logistics, client communication, safety considerations, evidence gathering, and testing tasks within the authorized framework.
• Record observations and evidence through notes, timestamps, photographs, interviews, and other evaluation documents.
• Analyze findings, categorize risk-based results, and suggest enhancements to facility security, access management, detection, response, and resilience.
• Draft, review, and approve Human Threat reports.
• Present client briefings and debriefs that outline security vulnerabilities, social engineering findings, business implications, and recommended remediation actions.
• Prioritize tasks and manage responsibilities to achieve delivery utilization targets and ensure timely outputs.
• Provide guidance to clients and foster collaborative relationships with clients and stakeholders.
• Keep up-to-date with industry certifications and trends related to physical security, social engineering, and human threat developments.
• Identify opportunities for up-selling and cross-selling and communicate these to the sales team.
• Collaborate with project managers, quality assurance, sales, and delivery team members.
• Mentor junior consultants in physical assessment methods, social engineering, client communication, reporting, and engagement execution.
• Develop and enhance Human Threat methodologies, tools, playbooks, and service offerings.
• Contribute to thought leadership through research, blogs, whitepapers, webinars, and presentations at conferences.
• Support the development of the Human Threat practice through research, service innovation, and engagement with external industry content.
• Represent Coalfire at industry events, client briefings, and conferences.
• Participate in other offensive security operations as necessary.
• Undertake additional responsibilities that support client delivery, practice growth, and team success.
• 5–8 years of consulting experience in client-facing roles.
• 3–5 years of expertise in social engineering, red team operations, insider risk, or physical security.
• Proficiency in social engineering techniques and principles.
• Experience in phishing, vishing, smishing, and other communication-based attack strategies.
• Ability to develop pretexts and emulate adversaries targeting human subjects.
• Conduct human risk assessments and evaluations focusing on behavior-based security.
• Skilled in report writing and delivering presentations to clients.
• Understanding of current tactics, techniques, and procedures utilized by threat actors involving human targets.
• Familiarity with physical security concepts and vulnerabilities related to badge/access control.
• Knowledge of email security protocols, identity-based assaults, and user-targeted attack pathways.
• Awareness of security culture, behavior change principles, and safety measures.
• Willingness to travel up to 75% of the time.
• Strong writing abilities, personal accountability, and capacity to meet established standards independently.
• Experience in planning and executing authorized physical security evaluations, facility walkthroughs, access control assessments, and onsite testing.
• Comprehensive understanding of physical security principles and controls, including perimeter security, access points, locks, badges, visitor management, reception procedures, secure areas, and employee access practices.
• Capability to formulate assessment plans, scenarios, pretexts, rules of engagement, and safety protocols.
• Strong situational awareness, sound judgment, discretion, and professionalism.
• Ability to identify, document, assess, and convey physical and human-centered security weaknesses along with practical remediation suggestions.
• Proficient in communicating intricate security concepts through written material, client presentations, executive briefings, and public speaking engagements.
• Excellent communication, teamwork, and presentation skills.
• Strong time management skills and ability to handle multiple priorities, engagements, deadlines, and onsite demands.
• Ability to safeguard sensitive client information and maintain accurate assessment documentation and engagement records.
• Willingness and capability to travel to client locations and engage in onsite assessments as required.
• ASIS Certified Protection Professional certification or an equivalent physical security credential is advantageous.
• Familiarity with physical red team tactics and techniques is a plus.
• Experience in executive protection or targeted social engineering against executives is beneficial.
• Background in behavioral science, psychology, or influence training is a bonus.
• Insight into threat intelligence related to social engineering campaigns and the tactics of threat actors is advantageous.
• Experience in developing insider risk programs is beneficial.
• Capability in creating training materials and facilitating workshops is a plus.
• Social engineering experience related to hardware, badges, or access control is an advantage.
• Published works, blogs, whitepapers, or presentations on topics like social engineering, human threats, or offensive security is a bonus.
• Flexible work arrangements that allow for remote work or office presence.
• Employee resource groups to foster inclusion.
• Opportunities for both in-person and virtual events.
• Paid parental leave for employees.
• Flexible time-off policies.
• Reimbursement for certifications and training.
• Membership for digital mental health and wellness support.
• Comprehensive insurance options available.
• Eligibility for annual incentives, commissions, and/or recognition programs.
dentsu Austria
GHY International
GHY International
GHY International
Get handpicked remote jobs straight to your inbox weekly.