Job Description:
We are seeking a skilled and experienced Lead Cybersecurity Engineer – Red Team to drive advanced offensive security assessments, simulate real-world attacks, and help enhance the organization’s detection and response capabilities. This role involves designing, executing, and leading red team operations to identify gaps in security controls, improve incident detection, and strengthen defense mechanisms.
Experience Level: 5+ years.
Key Responsibilities:
-
Lead and execute red team engagements simulating APT-style threats across networks, applications, cloud, and endpoints.
-
Design threat emulation plans using frameworks such as MITRE ATT&CK, CBEST, TIBER-EU, or NIST.
-
Develop and maintain custom attack tools, scripts, and exploits tailored to simulate realistic adversary techniques.
-
Perform vulnerability assessments and manual exploitation in IT and OT environments, reporting risks with actionable remediation plans.
-
Collaborate with Blue Team for Purple Team exercises to improve detection rules and SIEM coverage.
-
Analyze detection and response posture using EDR, SIEM, and SOAR tools; suggest detection engineering improvements.
-
Contribute to threat modeling, attack surface analysis, and red team readiness planning.
-
Document findings and deliver detailed technical reports and executive summaries.
Required Skills and Experience:
-
5+ years of experience in offensive security, penetration testing, or red teaming.
-
Strong knowledge of TTPs, adversary emulation, lateral movement, Active Directory attacks, and evasion techniques.
-
Proficient in scripting languages like Python, PowerShell, Bash.
-
Experience with tools like Cobalt Strike, Metasploit, BloodHound, Empire, Sliver, Nmap, Burp Suite, Responder, etc.
-
Experience in cloud attack simulation (AWS, Azure, GCP).
-
Solid understanding of Windows, Linux, networking protocols, and authentication systems.
-
Knowledge of secure coding, vulnerability management, and attack lifecycle (Kill Chain).
Nice to Have:
-
Prior experience in Purple Team collaboration.
- Certifications OSCP, OSCE3, GPEN
-
Experience with attack simulation platforms (e.g., MITRE Caldera, AttackIQ, SafeBreach).
-
Knowledge of Zero Trust, EDR bypass, cloud native security, and OT network security.
-
Experience in reporting to leadership/C-levels and aligning findings with business risk.
To apply for this job email your details to vijay@opencops.com