About The Position

At Armadin, we're a group of engineers, researchers, and hackers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on. We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite red teamers into purpose-built security models and agents that discover risk and remediate it before organizations are breached. Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, and MIT to reinvent security for an adversary that never sleeps. As an Operational Technology (OT) Red Team Operator, you will conduct adversary-focused offensive operations in highly sensitive Operational Technology (OT) and Critical Infrastructure networks where the margin for error is zero. These engagements are designed to simulate real-world attacks against cyber physical and industrial control environments. This role requires far more than executing tools — you will analyze environments holistically, discover attack paths, and operate with discipline, creativity, and intent. You will emulate motivated attackers by chaining misconfigurations, vulnerabilities, security gaps, and trust relationships to achieve objectives while minimizing detection. Engagements may range from assumed-breach scenarios to full red team operations against mature defensive programs. Beyond direct engagement work, you will partner closely with internal engineers and researchers to help define, build, and test adversarial evaluations that model real attacker behavior. You will translate engagement outcomes—such as attack paths, privilege escalation techniques, and operational tradecraft—into structured inputs that support the training and validation of AI systems intended to learn how to plan, execute, and reason about offensive operations at scale. This role plays a direct part in shaping how offensive expertise is captured, operationalized, and automated.

Requirements

  • Ability to clearly communicate with OT stakeholders in a manner that builds relationships and trust.
  • Demonstrated experience in offensive security with a focus on OT/ICS/SCADA/Embedded Systems. You should know your way around automation and control systems as well as a Linux terminal.
  • You understand that while AI provides scale, human expertise is required to navigate the nuance of a sensitive power grid or production line.
  • Deep technical knowledge of industrial protocols (Modbus, DNP3, Ethernet/IP, Profinet) and the ability to perform manual packet manipulation.
  • Deep understanding of networking and operating system fundamentals
  • Strong knowledge of common enterprise protocols and services (e.g., SMB, LDAP, Kerberos, DNS, HTTP)
  • Scripting or programming experience in at least one language (e.g., Python, Go, PowerShell, Bash, C/C++)
  • Ability to quantify "exploitable risk" vs. "theoretical vulnerability" in a way that resonates with both plant managers and CISOs.
  • Ability to analyze attack paths and chain multiple weaknesses into meaningful outcomes
  • Strong technical writing and communication skills
  • Eligibility to work in the United States without sponsorship.

Nice To Haves

  • Experience modifying or developing offensive tooling
  • Familiarity with detection evasion concepts and operational tradecraft
  • Experience working with mature defensive teams and security operations centers
  • Experience or interest in how LLMs and agentic workflows can be applied to offensive security.
  • Relevant certifications (e.g., GICSP, GRID, GCIP, or OSCP/OSEP) or equivalent demonstrated capability
  • Experience at world class consulting firms, fortune 100 Red Teams, or within specialized government offensive units

Responsibilities

  • Execute semi-automated and manual red team and penetration testing on sensitive OT environments (e.g., ICS, SCADA, DCS, BMS, IIoT, Embedded Systems) where autonomous testing requires expert human oversight to maintain safety and uptime.
  • Identify and exploit weaknesses across diverse attack surfaces:
  • Understanding of OT services and protocols
  • Understanding and able to execute common Active Directory attacks that would allow lateral movement and privilege escalation
  • Ability to target controls systems and embedded devices for attack activities and abuse opportunities
  • Moderate understanding of container technologies and attack techniques to abuse these technologies
  • Certificate services and PKI infrastructure abuse
  • Knowledge of trust relationship attacks forest trusts
  • Conduct privilege escalation, lateral movement, and post-exploitation activities
  • Ability to customize public offensive tooling or develop custom internal tooling
  • Maintain operational security throughout engagements:
  • Deploy and operate command-and-control infrastructure (Cobalt Strike, Sliver, Mythic, custom frameworks)
  • Implement evasion techniques against EDR, SIEM, and network monitoring
  • Practice proper OPSEC including infrastructure isolation and attribution management
  • Demonstrate operational discipline, including scope control, cleanup, and evidence handling
  • Develop proof-of-concept exploits and tooling as needed to achieve objectives
  • Produce clear, actionable reports that communicate risk and business impact
  • Present findings to technical teams and executive stakeholders
  • Contribute to internal research, tooling, playbooks, and knowledge sharing
  • Define the reasoning paths, safety guardrails, and protocol-specific logic our AI uses to navigate industrial networks.
  • Act as the ultimate safety valve, defining the "No-Go" parameters for autonomous agents in volatile manufacturing or utility environments.
  • Work with client engineers and our internal AI teams to translate validated OT kill chains into autonomous defensive postures.

Benefits

  • Full Health, Dental, & Vision Coverage
  • Meaningful Equity Ownership
  • In-Office Meals
  • Haircuts at the Office
  • Company Sponsored Conferences & Events
  • 401(k), HSA, and FSA Plans
  • Flexible PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service