Information Security Specialist - Red Team Operator
$96,900–$136,800 year
On-siteToronto, Ontario, Canada or Ottawa, Ontario, Canada
Job Summary
Plan and execute full-scope red team engagements including reconnaissance, initial access, lateral movement, and privilege escalation. Emulate real-world threat actors using established TTPs while developing custom tooling and conducting phishing campaigns within defined legal constraints. Collaborate with Blue Team, Threat Intelligence, and Incident Response partners to produce clear engagement reports and support detection engineering by identifying control gaps. Mentor junior operators and contribute to continuous improvement of red team methodologies and governance processes.
Required Qualifications
- University degree
- 7+ years of experience in offensive security, red teaming, penetration testing, or equivalent hands-on security roles
- Strong knowledge of Windows Active Directory environments, identity abuse, and enterprise authentication flows
- Proven experience with common red team tooling (e.g., C2 frameworks, phishing platforms, custom payloads)
- Solid understanding of network protocols, operating systems, and endpoint security controls
- Ability to safely execute adversarial activities in regulated environments with strict scope and approval processes
- Strong written and verbal communication skills, including report writing and technical walkthroughs
- Demonstrated ability to work independently while collaborating effectively with cross-functional teams
- Familiarity with EDR, SIEM, and cloud security controls from an attacker's perspective
- Experience developing custom tooling in languages such as C#, Python, and PowerShell
- Knowledge of red team infrastructure, domain management, and OPSEC best practices
- Relevant certifications (e.g., CRTO, OSCP, GXPN, Red Team Ops–focused certs)
- Experience in financial services, large enterprises, or highly regulated environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.