Red Team Operator - Assistant Director
About the role
Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
Responsibilities
- Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact.
- Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures.
- Perform social engineering (e.g., phishing) as part of integrated engagements.
- Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks.
- Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
- Produce high-quality deliverables: detailed technical reports, executive summaries, risk assessments, and remediation recommendations.
- Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts).
- Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development.
Requirements
- Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, BloodHound, Nmap, Burp Suite, and others).
- Demonstrated ability to think critically.
- Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols.
- Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling.
- Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders.
- Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence.
- Excellent analytical, problem-solving, and technical writing skills.
- Strong teamwork, independence, and communication skills.
Skills and Attributes for Success
- Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU).
- Prior consulting or client-facing experience (where applicable).
- Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering.
- Creation of, or contributions to open-source tools or projects, CTF participation, or public research/blogging.
Qualifications
- 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security.
- Demonstrated experience executing red team or advanced penetration testing engagements.
- Relevant certifications including OSCP, CPTS (or equivalents such as GPEN, CRTO, OSEP, OSCE).
- Ability to work effectively in a fully remote environment.
Benefits
Our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Pay
The base salary range for this job in all geographic locations in the US is $128,100 to $239,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $153,800 to $272,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.
Schedule
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business.