Brown Brothers Harriman & Co logo
Brown Brothers Harriman & CoPosted 2 weeks ago

Cyber Red Team Operator

$120,000–$160,000 year

On-siteBoston, Massachusetts, United States or Philadelphia, Pennsylvania, United States

Full TimeSenior LevelLarge

Job Summary

Conduct enterprise-scale red team engagements, adversary emulation exercises, and offensive security assessments across network, application, cloud, identity, and infrastructure environments. Simulate sophisticated threat actor tactics, techniques, and procedures to validate vulnerabilities through controlled exploitation and realistic attack scenarios. Manage testing engagements from planning through final reporting, deliver technical reports and executive-level risk summaries, and lead purple team exercises to validate security controls and improve organizational resilience. Research emerging threats, mentor team members, and collaborate with security stakeholders to drive remediation and improve the firm's security posture.

Required Qualifications

  • 8-10 years of experience in Information Security, with significant experience in offensive security, red team operations, adversary emulation, or penetration testing
  • Demonstrated experience planning and executing enterprise-scale red team engagements and multi-stage attack scenarios
  • Deep understanding of attacker methodologies, MITRE ATT&CK, privilege escalation, lateral movement, command and control, persistence mechanisms, and identity-based attacks
  • Hands-on experience testing Windows, Linux, Active Directory, cloud platforms, network infrastructure, and enterprise applications
  • Experience with scripting and automation using technologies such as Python, PowerShell, Bash, or similar languages
  • Experience identifying, exploiting, and documenting complex vulnerabilities and attack paths
  • Ability to communicate complex technical concepts clearly to technical and non-technical audiences
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience
  • Expertise with security assessment methodology, vulnerability management, OWASP model, CVE ratings
  • Participate in Cyber Tabletop Exercises as a subject matter expert for adversary behavior, intent, and TTPs

Desired Qualifications

  • Financial services or other highly regulated industry experience
  • Relevant offensive security certifications such as PNPT, OSCP, OSEP, OSWE, CRTO, CRTE, GRTP, or equivalent advanced offensive security credentials
  • Experience with commercial offensive security and penetration testing management platforms, including Core Impact and AttackForge
  • Experience conducting cloud security assessments in Microsoft Azure environments
  • Experience participating in purple team exercises that validate security controls, test defensive coverage, improve organizational resilience, and facilitate collaboration between offensive and defensive security teams to strengthen overall security effectiveness
  • Contributions to open-source security projects, public research, conference speaking, or community involvement

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce