Red Team Operator - AVP

Barclays•Washington, WA
•Remote

About The Position

Embark on a transformative journey as a Red Team Operator - AVP. At Barclays, our vision is clear –to redefine the future of banking and help craft innovative solutions. In this role, you’ll leverage industry-leading tools, explore emerging techniques, and execute operations across a wide range of domains, including cyber, physical, human, process, and technology. As a member of the Red Team, you’ll participate in full-scope adversary emulation exercises spanning cyber operations, physical security assessments, social engineering engagements, and everything in between, testing the resilience of our defenses under realistic conditions. You’ll identify vulnerabilities and control gaps, then work closely with stakeholders to help strengthen our security posture. This is a highly hands-on role, ideal for someone who thrives on tackling complex challenges, developing offensive security capabilities, and operating against sophisticated targets. You’ll have dedicated time to research emerging tradecraft, evaluate new tools and techniques, and collaborate with a team of skilled, highly motivated operators. Success in this role requires good technical expertise, practical security testing experience, creativity in problem-solving, and the ability to work effectively across teams to achieve meaningful security outcomes.

Requirements

  • Good technical expertise
  • Practical security testing experience
  • Creativity in problem-solving
  • Ability to work effectively across teams to achieve meaningful security outcomes
  • Experience executing full-scope Red Team engagements aligned to clearly defined adversarial objectives across cyber, physical, social engineering, and process attack surfaces
  • Experience designing and delivering end-to-end phishing and social engineering campaigns, including building and managing supporting infrastructure (domains, redirectors, email services, and landing pages), developing realistic pretexts, and creating payloads that accurately emulate real-world threat actor techniques
  • Experience deploying, operating, and optimizing Command and Control (C2) frameworks, such as Cobalt Strike, Nighthawk, or similar platforms, to support adversary emulation activities spanning initial access, post-exploitation, persistence, and lateral movement
  • Experience assessing the effectiveness of security controls by simulating advanced attacker behaviors and identifying opportunities to strengthen organizational defenses
  • Experience collaborating with security teams and stakeholders to translate findings into actionable recommendations and measurable security improvements
  • Programming and scripting skills to build, customize, and automate tools that improve operational efficiency and support complex Red Team engagements
  • Considerable analytical thinking, creativity, and problem-solving skills to navigate technical challenges, adapt to dynamic environments, and deliver impactful security testing outcomes

Nice To Haves

  • Any of these industry-recognized certifications such as OSCP, OSEP, CRTO, CRTP, CREST, CCSAS, CCRTS, are a plus

Responsibilities

  • Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
  • Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
  • Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
  • Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
  • Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.
  • Executing full-scope Red Team engagements aligned to clearly defined adversarial objectives across cyber, physical, social engineering, and process attack surfaces
  • Designing and delivering end-to-end phishing and social engineering campaigns, including building and managing supporting infrastructure (domains, redirectors, email services, and landing pages), developing realistic pretexts, and creating payloads that accurately emulate real-world threat actor techniques
  • Deploying, operating, and optimizing Command and Control (C2) frameworks, such as Cobalt Strike, Nighthawk, or similar platforms, to support adversary emulation activities spanning initial access, post-exploitation, persistence, and lateral movement
  • Assessing the effectiveness of security controls by simulating advanced attacker behaviors and identifying opportunities to strengthen organizational defenses
  • Collaborating with security teams and stakeholders to translate findings into actionable recommendations and measurable security improvements
  • Developing and enhancing custom tooling, offensive tradecraft, and defense-evasion techniques to emulate sophisticated threat actors and evaluate the effectiveness of security controls, detection, and response capabilities
  • Research, prototype, and execute innovative attack methodologies that advance adversary emulation capabilities and align with the evolving threat landscape
  • Demonstrate expertise in Red Team operations through hands-on security testing, offensive security research
  • Leverage programming and scripting skills to build, customize, and automate tools that improve operational efficiency and support complex Red Team engagements
  • Apply considerable analytical thinking, creativity, and problem-solving skills to navigate technical challenges, adapt to dynamic environments, and deliver impactful security testing outcomes

Benefits

  • Medical coverage
  • Dental coverage
  • Vision coverage
  • 401(k)
  • Life insurance
  • Other paid leave for qualifying circumstances
  • Incentive award
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service