
Senior Red Team Operator – SME
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States.
• Lead designated red-team operations, overseeing everything from scenario design and rules-of-engagement planning to infrastructure setup, execution, conflict resolution, reporting, and customer debriefing.
• Create multi-vector campaigns in alignment with MITRE ATT&CK and contemporary APT profiles.
• Implement identity-layer exploitation, cloud lateral movement, and infrastructure pivoting techniques.
• Design and manage adversary infrastructure, including redirectors, command-and-control channels, payload-delivery methods, operator access, logging, and teardown procedures.
• Build secure cloud-based attack infrastructure alongside teardown workflows.
• Execute advanced techniques in identity, endpoint, network, web, cloud, phishing, defense evasion, persistence, and exfiltration simulation, when authorized.
• Mentor junior operators, evaluate tradecraft and scripts, enforce operational security and safety measures, and make real-time technical decisions during operations.
• Assess payload/tooling for evasion capabilities within authorized parameters.
• Collaborate with stakeholders to verify detection and response and craft tailored purple-team scenarios.
• Convert observations into quantifiable defensive enhancements.
• Ensure technical quality for operator logs, attack narratives, evidence, mitigation recommendations, assessment reports, and customer debriefs.
• Report significant risks, scope alterations, operational impacts, and cross-engagement issues to the Technical Lead.
• Provide ongoing technical assessment support for proactive testing of federal cyber assets visible both externally and internally.
• Perform continuous evaluations of .gov domains, subdomains, and internet-facing assets to identify unknown vulnerabilities and validate weaknesses.
• Offer actionable remediation guidance to agencies in support of the CDM Program.
• U.S. citizenship is mandatory.
• Must fulfill eligibility criteria for access to sensitive information and be capable of obtaining a Public Trust fitness determination (High Risk).
• Ability to operate in customer-provided remote environments, utilize customer-approved tools, and adhere to rules of engagement, data-handling protocols, evidence controls, conflict resolution procedures, and stop-work criteria.
• A minimum of five years of practical experience in red-team operations, defensive adversary emulation, or advanced penetration testing.
• At least two years of experience leading defensive detection engineering activities and engagements or small operator teams.
• Proven experience in campaign planning across reconnaissance, initial access, credential access, privilege escalation, lateral movement, persistence, command and control, defense evasion, and simulated exfiltration.
• Advanced knowledge of C2 frameworks, adversary infrastructure, Active Directory/Entra ID, Windows and Linux tradecraft, cloud attack methods, and operator scripting/tool development.
• Strong comprehension of operational security, conflict resolution, legal/ethical boundaries, evidence management, and safe execution in production environments.
• Adept at writing and technically reviewing assessment reports and providing clear customer debriefs to both technical and executive audiences.
• Proficient with Sliver, Mythic, Havoc, and secure cloud attack architecture.
• One or more advanced hands-on certifications, such as OSEP/OSCE, OSCP, GXPN, GPEN, CRTO/CRTL, CRTP, OSED, or equivalent.
• Desired: Eight or more years of offensive-security experience, including multi-tenant enterprise or federal engagements.
• Desired: Experience in payload or tool development in C#, C/C++, Go, Rust, Python, or PowerShell; familiarity with modern EDR/AV bypass and living-off-the-land techniques.
• Desired: Advanced skills in AWS/Azure identity and cloud tradecraft, container/Kubernetes security, or hybrid-enterprise campaign experience.
• Desired: Experience in facilitating purple-team exercises, detection engineering, or SOC/incident-response validation.
• Desired: Background in critical infrastructure, ICS/OT, federal high-value assets, or restricted/air-gapped environments.
• Flexible time off benefit.
• Comprehensive learning resources.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Competitive compensation.
Mercor
HighLevel
Ms Ms
Get handpicked remote jobs straight to your inbox weekly.