Назад
Company hidden
3 месяца назад

Threat Emulation & Readiness Lead / Red Team Lead (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Emulation & Readiness Lead (Cybersecurity): Overseeing adversary emulation, red team operations, and cyber readiness exercises for a federal enterprise program with an accent on nation-state tradecraft and MITRE ATT&CK methodologies. Focus on designing threat emulation campaigns, assessing detection effectiveness, and briefing executive leadership on organizational risk.

Location: Washington, DC

Company

hirify.global provides specialized cybersecurity services supporting federal enterprise programs.

What you will do

  • Lead red team operations and adversary emulation exercises.
  • Design and execute threat emulation campaigns, purple team exercises, tabletop exercises, and crisis simulations.
  • Develop attack chains aligned with MITRE ATT&CK and real-world threat actor behaviors.
  • Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams.
  • Assess detection and response effectiveness across defensive technologies and operational workflows.
  • Develop after-action reports and brief executives on adversary risk and organizational readiness.

Requirements

  • 10+ years of offensive security or advanced cybersecurity operations experience.
  • 5+ years leading red team or adversary emulation operations.
  • Experience conducting operations against enterprise Active Directory, cloud infrastructure, and hybrid identity systems.
  • Deep understanding of adversary tradecraft, post-exploitation, detection evasion, and lateral movement.
  • Proven experience conducting purple team engagements and readiness exercises.
  • Strong executive communication and briefing capabilities.

Nice to have

  • Industry certifications such as OSCP, OSEP, CRTO, GXPN, GPEN, or CISSP.
  • MITRE ATT&CK certifications.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →