Red-Team / Adversarial Security Lead

SteampunkMcLean, VA
$85,000 - $170,000

About The Position

We are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls. The Red-Team / Adversarial Security Lead will analyze and document assessment results, communicate identified risks and vulnerabilities, recommend appropriate remediation actions, and support pass/fail safety-gate determinations based on established security criteria. This role requires strong technical cybersecurity experience across operating systems, infrastructure, and cloud environments.

Requirements

  • Ability to obtain and maintain a government security clearance
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience
  • 5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplines
  • Experience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risks
  • Experience planning and executing technical security assessments, penetration tests, or adversarial security assessments
  • Deep technical experience across operating systems and associated security concepts, including environments such as Windows and Linux
  • Experience identifying, validating, and assessing vulnerabilities and potential attack paths
  • Knowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controls
  • Experience with cloud architecture and security concepts across AWS, Azure, and/or GCP
  • Ability to analyze technical security findings and evaluate their potential impact and risk
  • Experience documenting technical findings, supporting evidence, and remediation recommendations
  • Strong analytical, problem-solving, communication, and collaboration skills

Nice To Haves

  • Experience conducting red-team assessments across complex enterprise environments
  • Experience with multiple cloud platforms, including AWS, Azure, and GCP
  • Experience with adversary emulation and penetration testing tools and methodologies
  • Knowledge of MITRE ATT&CK and related adversarial tactics, techniques, and procedures
  • Experience evaluating security assessment results against defined acceptance, release, or safety-gate criteria
  • Experience working within federal government or other highly regulated environments
  • Offensive Security Certified Professional (OSCP) or comparable hands-on offensive security/penetration testing certification strongly preferred; comparable certifications may include GIAC Penetration Tester (GPEN), Practical Network Penetration Tester (PNPT), Hack The Box Certified Penetration Testing Specialist (HTB CPTS), or equivalent

Responsibilities

  • Develop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environments
  • Develop and execute red-team and adversarial security assessment plans based on defined objectives and security criteria
  • Perform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack paths
  • Evaluate the effectiveness of existing security controls through technical testing and adversarial techniques
  • Analyze vulnerabilities and assessment findings to determine exploitability, potential impact, and associated security risk
  • Conduct security assessments across diverse operating systems and enterprise technology environments
  • Assess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)
  • Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actions
  • Evaluate assessment results against established security and safety-gate criteria and support pass/fail determinations
  • Communicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholders
  • Collaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risks
  • Validate remediation of identified vulnerabilities and security weaknesses through follow-up testing
  • Maintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practices
  • Support the development and refinement of red-team methodologies, assessment procedures, and security testing criteria

Benefits

  • The estimate displayed represents a typical annual salary range for this position.
  • Annual salary is just one aspect of Steampunk’s total compensation package for employees.
  • Learn more about additional Steampunk benefits here.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service