Red-Team / Adversarial Security Lead
About the role
We are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls.
Responsibilities
- Develop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environments
- Develop and execute red-team and adversarial security assessment plans based on defined objectives and security criteria
- Perform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack paths
- Evaluate the effectiveness of existing security controls through technical testing and adversarial techniques
- Analyze vulnerabilities and assessment results to determine exploitability, potential impact, and associated security risk
- Assess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)
- Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actions
- Evaluate assessment results against established security and safety-gate criteria and support pass/fail determinations
- Communicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholders
- Collaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risks
- Validate remediation of identified vulnerabilities and security weaknesses through follow-up testing
- Maintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practices
- Support the development and refinement of red-team methodologies, assessment procedures, and security testing criteria
Requirements
- Ability to obtain and maintain a government security clearance
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience
- 5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplines
- Experience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risks
- Experience planning and executing technical security assessments, penetration tests, or adversarial security assessments
- Deep technical experience across operating systems and associated security concepts, including environments such as Windows and Linux
- Experience identifying, validating, and assessing vulnerabilities and potential attack paths
- Knowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controls
- Experience with cloud architecture and security concepts across AWS, Azure, and/or GCP
- Experience evaluating security assessment results against defined acceptance, release, or safety-gate criteria
Qualifications
- Ability to obtain and maintain a government security clearance
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience
- 5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplines
- Experience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risks
- Experience planning and executing technical security assessments, penetration tests, or adversarial security assessments
- Deep technical experience across operating systems and associated security concepts, including environments such as Windows and Linux
- Experience identifying, validating, and assessing vulnerabilities and potential attack paths
- Knowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controls
- Experience with cloud architecture and security concepts across AWS, Azure, and/or GCP
- Experience evaluating security assessment results against defined acceptance, release, or safety-gate criteria
Skills
- Threat modeling
- Penetration testing
- Adversarial security testing
- Vulnerability assessment
- Cloud security
- MITRE ATT&CK
- Offensive security/penetration testing
Benefits
Identity Statement As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.