Senior Red Team Operator – SME

atCACI International IncRemoteUS flagUnited StatesFull-timeUncategorizedSenior$90.3k – $189.6k/year

Posted Sep 8

This is a fully remote position, open to applicants in United States.

📋 Description

• Lead designated red-team operations, overseeing everything from scenario design and rules-of-engagement planning to infrastructure setup, execution, conflict resolution, reporting, and customer debriefing.

• Create multi-vector campaigns in alignment with MITRE ATT&CK and contemporary APT profiles.

• Implement identity-layer exploitation, cloud lateral movement, and infrastructure pivoting techniques.

• Design and manage adversary infrastructure, including redirectors, command-and-control channels, payload-delivery methods, operator access, logging, and teardown procedures.

• Build secure cloud-based attack infrastructure alongside teardown workflows.

• Execute advanced techniques in identity, endpoint, network, web, cloud, phishing, defense evasion, persistence, and exfiltration simulation, when authorized.

• Mentor junior operators, evaluate tradecraft and scripts, enforce operational security and safety measures, and make real-time technical decisions during operations.

• Assess payload/tooling for evasion capabilities within authorized parameters.

• Collaborate with stakeholders to verify detection and response and craft tailored purple-team scenarios.

• Convert observations into quantifiable defensive enhancements.

• Ensure technical quality for operator logs, attack narratives, evidence, mitigation recommendations, assessment reports, and customer debriefs.

• Report significant risks, scope alterations, operational impacts, and cross-engagement issues to the Technical Lead.

• Provide ongoing technical assessment support for proactive testing of federal cyber assets visible both externally and internally.

• Perform continuous evaluations of .gov domains, subdomains, and internet-facing assets to identify unknown vulnerabilities and validate weaknesses.

• Offer actionable remediation guidance to agencies in support of the CDM Program.


⛳️ Requirements

• U.S. citizenship is mandatory.

• Must fulfill eligibility criteria for access to sensitive information and be capable of obtaining a Public Trust fitness determination (High Risk).

• Ability to operate in customer-provided remote environments, utilize customer-approved tools, and adhere to rules of engagement, data-handling protocols, evidence controls, conflict resolution procedures, and stop-work criteria.

• A minimum of five years of practical experience in red-team operations, defensive adversary emulation, or advanced penetration testing.

• At least two years of experience leading defensive detection engineering activities and engagements or small operator teams.

• Proven experience in campaign planning across reconnaissance, initial access, credential access, privilege escalation, lateral movement, persistence, command and control, defense evasion, and simulated exfiltration.

• Advanced knowledge of C2 frameworks, adversary infrastructure, Active Directory/Entra ID, Windows and Linux tradecraft, cloud attack methods, and operator scripting/tool development.

• Strong comprehension of operational security, conflict resolution, legal/ethical boundaries, evidence management, and safe execution in production environments.

• Adept at writing and technically reviewing assessment reports and providing clear customer debriefs to both technical and executive audiences.

• Proficient with Sliver, Mythic, Havoc, and secure cloud attack architecture.

• One or more advanced hands-on certifications, such as OSEP/OSCE, OSCP, GXPN, GPEN, CRTO/CRTL, CRTP, OSED, or equivalent.

• Desired: Eight or more years of offensive-security experience, including multi-tenant enterprise or federal engagements.

• Desired: Experience in payload or tool development in C#, C/C++, Go, Rust, Python, or PowerShell; familiarity with modern EDR/AV bypass and living-off-the-land techniques.

• Desired: Advanced skills in AWS/Azure identity and cloud tradecraft, container/Kubernetes security, or hybrid-enterprise campaign experience.

• Desired: Experience in facilitating purple-team exercises, detection engineering, or SOC/incident-response validation.

• Desired: Background in critical infrastructure, ICS/OT, federal high-value assets, or restricted/air-gapped environments.


🏝️ Benefits

• Flexible time off benefit.

• Comprehensive learning resources.

• Healthcare benefits.

• Wellness benefits.

• Financial benefits.

• Retirement benefits.

• Family support benefits.

• Continuing education benefits.

• Time off benefits.

• Competitive compensation.

People also viewed

Mercor9 hours ago

PDF Annotation, Transcription Expert – Japanese

JP flagJapan, +3 more countriesFreelanceUncategorized$33/hour
ApplyView job
Parexel9 hours ago

Site Activation Leader

US flagUnited States OnlyFull-timeUncategorized
ApplyView job
HighLevel9 hours ago

Lead Product Analyst – AI Products

GB flagUnited Kingdom OnlyFull-timeUncategorized
ApplyView job
Ms Ms9 hours ago

Associate, Commodities Document Negotiator

US flagAlabama, +46 more statesFull-timeUncategorized$100k – $150k/year
ApplyView job
URBN (Urban Outfitters, Anthropologie Group, Free People & Nuuly)9 hours ago

Temporary Loss Prevention Coordinator

US flagPennsylvania OnlyFull-timeUncategorized$20 – $25/hour
ApplyView job
Dent Wizard International9 hours ago

Entry Level Automotive Wheel Repair Technician

US flagWisconsin OnlyFull-timeUncategorized$21/hour
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers