Offensive Security Consultant – Red Team & Adversary Simulation

Protiviti•Washington, DC
•$138,000 - $219,000•Hybrid

About The Position

Protiviti's Attack & Penetration team is growing, and we're looking for an offensive security professional who wants to do real adversary work—not checkbox testing. You'll join a team that runs red team, purple team, and threat-led engagements for organizations across nearly every industry, and you'll have the tools, lab, and backing to push the craft forward. You'll be both a trusted advisor and a hands-on operator. You'll lead engagements from scoping through executive readout, build lasting relationships with client security teams, and help them understand not just what's broken, but how a real attacker would exploit it and what to fix first. You'll also coach and develop teammates—sharing what you know and learning from them in return.

Requirements

  • You love offensive security and get energized by finding the path an attacker would take.
  • You stay current on the threat landscape—new TTPs, tooling, vulnerabilities, and how AI is changing both attack and defense.
  • You thrive on the puzzle of targeting an organization, chaining weaknesses together, and evading defensive controls.
  • You enjoy sharing what you know—coaching teammates on engagements, building training, or debating the latest technique.
  • You care about the client outcome and can translate technical risk into business impact that resonates with security teams and executives alike.
  • You're comfortable owning work end to end—scoping, execution, reporting, and readout.
  • You're curious about your clients' businesses and how security risk shows up in their industries.
  • Red & Purple Teaming: Experience running red team engagements that emulate real-world threat actors, with a strong command of TTPs and MITRE ATT&CK.
  • Ability to partner with SOC and detection engineering teams to improve detection and response.
  • Experience designing threat intel–driven scenarios, including ransomware simulations.
  • Hands-on experience attacking Active Directory, cloud and identity platforms (AWS, Azure, GCP, Entra ID, Okta), and CI/CD pipelines.
  • Proficiency with C2 frameworks (e.g., Mythic, Sliver, Cobalt Strike) and building custom tooling in languages like C#, Go, Rust, Python, or PowerShell.
  • Strong OpSec and experience evading EDR and other monitoring tools.
  • Experience performing internal and external network penetration tests, including vulnerability discovery, exploitation, and privilege escalation.
  • Experience testing web applications, APIs, and mobile apps, with a solid grasp of the OWASP Top 10 and tools like Burp Suite.
  • Ability to look past scanner output, validate findings manually, and chain issues into real attack paths.
  • Understanding of attacks against LLM-enabled apps and agents (e.g., prompt injection, data leakage, tool abuse) and interest in using AI to speed up offensive work.
  • Ability to turn technical findings into clear, actionable reports and conversations for both technical teams and executives.
  • Creative problem solving—finding a way forward when the obvious path is blocked.
  • Bachelor's degree in a relevant discipline (e.g., CS, CE, IS, MIS, EE) or equivalent hands-on experience.
  • 5+ years of hands-on offensive security experience—red teaming, penetration testing, or adversary simulation—in consulting or in-house.
  • Strong written and verbal communication skills, including producing clear, client-ready reports and presentations.

Nice To Haves

  • Familiarity with DORA TLPT, TIBER-EU, or CBEST is a plus.
  • Exploit development or reverse engineering skills are a plus.
  • A track record of research, tool releases, blogs, or conference involvement (e.g., Black Hat, DEF CON, BSides) is a plus.
  • Certifications such as OSCP, OSEP, OSWE, OSED, CRTO/CRTL, GXPN, GPEN, BSCP, or comparable SANS 600/700-level coursework are a plus.
  • Cloud security certifications (e.g., AWS Certified Security – Specialty, Microsoft AZ-500, Google Professional Cloud Security Engineer, CCSK) are a plus.

Responsibilities

  • Plan and execute red team, purple team, and threat-led penetration testing (TLPT) engagements that emulate real-world threat actors across on-prem, cloud, identity, and SaaS environments.
  • Test the newest attack surface, including AI/LLM-powered applications, agentic workflows, and the identity platforms that connect them.
  • Use and build AI-assisted tooling and automation to move faster and go deeper during operations.
  • Develop new tooling, design novel attacks, and contribute to a robust lab of testing tools and equipment built to tackle hundreds of adversary simulation scenarios.
  • Partner with defenders to turn findings into better detections, faster response, and measurable improvement.
  • Help shape the future of the practice—if you have an idea for a new service and there's demand for it, we'll help you build it.

Benefits

  • medical, dental, and vision coverages
  • FSA and HSA healthcare accounts
  • life and accident insurance
  • adoption and fertility assistance
  • paid parental leave up to 10 weeks
  • short/long term disability
  • company 401(k) savings and investment plan with an employer match of 50% on the first 6% of your contributions
  • Choice Time Off (CTO) for vacation, personal needs, and sick time
  • up to 11 paid holidays each calendar year
  • annual bonus plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service