Run objective-based adversary emulation against mature, defended environments and measure how well clients can detect and respond. You will operate as the threat, end to end, and turn every action into a defensible map of detection and response gaps.
What you will do
Plan and lead covert, objective-based red-team operations against hardened, monitored estates
Build initial access, escalation, lateral movement, and persistence that stay under detection thresholds
Design, deploy, and operate resilient C2 and redirector infrastructure with strong operational security
Map every technique to MITRE ATT&CK and document detection gaps, dwell time, and response timing
Run purple-team replays so blue teams can build and validate durable detections
Develop and maintain custom tradecraft, loaders, and tooling that evade modern EDR and AV
What we are looking for
4+ years in red teaming or advanced offensive security, with full-scope engagements you led end to end
OSCP plus at least one of OSEP or CRTO; deeper certs (OSED, CRTL) are a strong plus
Expert Active Directory attack knowledge: Kerberos abuse, delegation, ADCS, trust and forest compromise
Hands-on mastery of at least one mature C2 (Cobalt Strike, Mythic, Sliver) and proven EDR-evasion tradecraft
Working code in C, C#, or Go for tooling and payload development, plus solid Windows internals
Fluency with MITRE ATT&CK and the judgment to operate quietly in live production environments
Nice to have
Malware development or EDR-evasion research, public or private
Social engineering or physical intrusion experience
Published tooling, CVEs, or conference talks
Get ahead of zero
Ready to see yourself the way an adversary would?
Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.