At Armadin, we're a group of engineers, researchers, and security researchers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on. We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite security practioners into purpose-built security models and agents that discover risk and remediate it before organizations are breached. Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, Georgia Tech, Waterloo, Berkeley, and MIT to reinvent security for an adversary that never sleeps. As an Operational Technology (OT) Red Team Operator, you will conduct adversary-focused offensive operations in highly sensitive Operational Technology (OT), Critical Infrastructure, and converged enterprise environments where the margin for error is zero. Modern OT environments do not exist in isolation; they are deeply interconnected with corporate networks, Active Directory, cloud systems, and specialized web/thick-client software management layers. These engagements are designed to simulate complex, multi-stage real-world attacks spanning the entire attack surface—from enterprise network perimeters down to cyber-physical and industrial control systems. This role requires far more than executing automated scanners—you will analyze environments holistically, discover complex attack paths across network boundaries and applications, and operate with discipline, creativity, and intent. You will emulate motivated threat actors by chaining application vulnerabilities, Active Directory misconfigurations, network trust relationships, and protocol weaknesses to achieve operational objectives while minimizing detection and ensuring process safety. Beyond direct engagement work, you will partner closely with internal engineers and researchers to help define, build, and test adversarial evaluations that model real attacker behavior across OT, network, and application domains. You will translate engagement outcomes—such as complex kill chains, privilege escalation techniques, and custom operational tradecraft—into structured inputs that support the training and validation of AI systems intended to learn how to plan, execute, and reason about offensive operations at scale. This role plays a direct part in shaping how cross-domain offensive expertise is captured, operationalized, and automated.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed