Cyber Red Team Operator

Brown Brothers HarrimanPhiladelphia, PA

About The Position

At Brown Brothers Harriman, cybersecurity is a critical enabler of trust, resilience, and innovation. We are seeking a highly skilled Senior Cyber Red Team Operator to join our growing Red Team and help strengthen the firm's ability to detect, respond to, and withstand sophisticated cyber threats. In this role, you will simulate real-world adversaries through advanced red team operations, adversarial emulation, penetration testing, and purple team exercises. You will work across enterprise infrastructure, cloud environments, applications, identity platforms, and emerging technologies to identify vulnerabilities, validate attack paths, and improve BBH's overall security posture. As a senior member of the team, you will help shape offensive security strategy, mentor developing operators, and collaborate closely with security and technology stakeholders across the organization. This is an exceptional opportunity for an experienced offensive security professional who is passionate about staying ahead of evolving threats and driving measurable improvements in cyber resilience.

Requirements

  • 8-10 years of experience in Information Security, with significant experience in offensive security, red team operations, adversary emulation, or penetration testing.
  • Demonstrated experience planning and executing enterprise-scale red team engagements and multi-stage attack scenarios.
  • Deep understanding of attacker methodologies, MITRE ATT&CK, privilege escalation, lateral movement, command and control, persistence mechanisms, and identity-based attacks.
  • Hands-on experience testing Windows, Linux, Active Directory, cloud platforms, network infrastructure, and enterprise applications.
  • Experience with scripting and automation using technologies such as Python, PowerShell, Bash, or similar languages.
  • Experience identifying, exploiting, and documenting complex vulnerabilities and attack paths.
  • Ability to communicate complex technical concepts clearly to technical and non-technical audiences.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Expertise with security assessment methodology, vulnerability management, OWASP model, CVE ratings
  • Participate in Cyber Tabletop Exercises as a subject matter expert for adversary behavior, intent, and TTPs

Nice To Haves

  • Financial services or other highly regulated industry experience.
  • Relevant offensive security certifications such as PNPT, OSCP, OSEP, OSWE, CRTO, CRTE, GRTP, or equivalent advanced offensive security credentials.
  • Experience with commercial offensive security and penetration testing management platforms, including Core Impact and AttackForge, preferred.
  • Experience conducting cloud security assessments in Microsoft Azure environments.
  • Experience participating in purple team exercises that validate security controls, test defensive coverage, improve organizational resilience, and facilitate collaboration between offensive and defensive security teams to strengthen overall security effectiveness.
  • Contributions to open-source security projects, public research, conference speaking, or community involvement.

Responsibilities

  • Understand and implement BBH Red Team Operating Standard and conditional Rules of Engagement in accordance with regulatory guidelines and best practices
  • Conduct risk assessments of vulnerabilities identified and write reports to facilitate the mitigations and remediations needed to improve BBH security posture
  • Lead and execute red team engagements, adversary emulation exercises, and offensive security assessments including network, application, cloud, identity, endpoint, and infrastructure security testing
  • Simulate sophisticated threat actor tactics, techniques, and procedures (TTPs) to validate vulnerabilities through controlled exploitation and realistic attack scenarios.
  • Manage testing engagements from planning through final reporting and validation.
  • Lead purple team exercises to validate security controls, improve visibility into attacker activity, and strengthen organizational resilience.
  • Research emerging threats and evolving offensive security techniques.
  • Deliver technical reports and executive-level risk summaries.
  • Mentor team members and contribute to Red Team methodologies and best practices.
  • Collaborate with security and technology stakeholders to drive remediation and improve security effectiveness.

Benefits

  • Competitive compensation and comprehensive benefits.
  • A culture that promotes inclusion, collaboration, and long-term career growth.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service