Red Team Operator - Assistant Director
EY · Jacksonville, FL · 1 mo ago
On-siteBusiness Development$128k–$240k/yrFull-time
About the role
Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets. As a Red Team Operator within the Attack Surface Management team, you will emulate advanced threat actors through offensive security testing and adversary emulation.
Responsibilities
- Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact.
- Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures.
- Perform social engineering (e.g., phishing) as part of integrated engagements.
- Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks.
- Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
- Produce high-quality deliverables: detailed technical reports, executive summaries, risk assessments, and remediation recommendations.
- Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts).
- Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development.
Requirements
- Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, BloodHound, Nmap, Burp Suite, and others).
- Demonstrated ability to think critically.
- Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols.
- Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling.
- Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders.
- Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence.
- Excellent analytical, problem-solving, and technical writing skills.
- Strong teamwork, independence, and communication skills.
Skills and Attributes
- 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security.
- Demonstrated experience executing red team or advanced penetration testing engagements.
- Relevant certifications including OSCP, CPTS (or equivalents such as GPEN, CRTO, OSEP, OSCE).
- Ability to work effectively in a fully remote environment.
- Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU).
- Prior consulting or client-facing experience (where applicable).
- Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering.
- Creation of, or contributions to open-source tools or projects, CTF participation, or public research/blogging.