Experienced Red Team Operator

Northwave Cyber Security

Utrecht

Hybrid

EUR 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working and international reloc
Training budget and certifications
Professional equipment provided
Office access across NL/BE/DE/SE

Job summary

Northwave Cyber Security in Utrecht is seeking an experienced Red Team / Penetration Testing Specialist to strengthen our offensive security capabilities across multiple clients and industries.

You will lead and execute advanced attack simulations, build and adapt tooling, and collaborate with Threat Intelligence, Blue Team and CERT specialists to translate findings into actionable improvements.

Qualifications

  • Several years of hands-on penetration testing or red team experience.
  • Strong attack-path knowledge in Windows and Active Directory environments.
  • Experience with Entra ID or other cloud environments.
  • Practical command-and-control, OPSEC and infrastructure skills.
  • The judgement to balance operational objectives, client safety and learning value.
  • Clear written and spoken English, with the ability to explain decisions and findings to both technical and non-technical audiences.
  • A collaborative approach: you ask for a second pair of eyes, share what worked and help others improve.
  • Eligibility to work from Belgium, Germany, the Netherlands or Sweden, and willingness to travel for client work when an engagement requires it.

Responsibilities

  • Design and execute realistic attack scenarios against critical business processes and systems.
  • Operate across the full attack chain: reconnaissance and initial access, command and control, privilege escalation, lateral movement and actions on objectives.
  • Deliver threat-led red team exercises, alongside other advanced engagements.
  • Build or adapt tooling, infrastructure and payloads when an operation requires it.
  • Make sound OPSEC and risk decisions while working in live client environments.
  • Translate technical activity into clear lessons for defenders, technical leaders and executives.
  • Improve our tradecraft by researching new techniques, developing TTPs and sharing what you learn with the team.

Skills

Penetration testing
Red team
Windows / Active Directory
OPSEC
English proficiency
Team collaboration
Travel flexible

Tools

Entra ID

Job description

At Northwave, 275 cybersecurity specialists transform how organisations approach digital safety. From our HQ in Utrecht, along with offices in Germany, Sweden, and Belgium.

Northwave combines ethical hacking expertise with behavioral psychology insights and cutting-edge security management at the highest level. We respond to threats and anticipate them, providing 24/7 managed security services and tailored solutions for each client's journey.

By joining Northwave, you'll become part of an organisation where innovation drives results, whether your talents lie in technical penetration testing or strategic client partnerships. Here, your expertise will grow and help shape the future of digital security across industries, leaving a lasting impact.

The team you will join

Our Red Team brings together 15 ethical hackers with expertise spanning adversary simulation, social engineering, Active Directory and Entra ID, malware and tooling development, cloud, application security, reverse engineering and exploitation. We challenge one another, share techniques openly and combine the right skills for each operation.

You will also work closely with our Threat Intelligence, Blue Team, Reverse Engineering and CERT specialists. Insights from real incidents and current threats help us build credible scenarios. Purple teaming turns each exercise into practical improvements for our clients.

What you will do
  • Design and execute realistic attack scenarios against critical business processes and systems.
  • Operate across the full attack chain: reconnaissance and initial access, command and control, privilege escalation, lateral movement and actions on objectives.
  • Deliver threat-intelligence-led ART and TIBER exercises, alongside other advanced red team and purple team engagements.
  • Build or adapt tooling, infrastructure and payloads when an operation requires it.
  • Make sound OPSEC and risk decisions while working in live client environments.
  • Translate technical activity into clear lessons for defenders, technical leaders and executives.
  • Improve our tradecraft by researching new techniques, developing TTPs and sharing what you learn with the team.
How an engagement works

We start by understanding the organisation, its critical functions and the threat actors it faces. Together with the client and control team, we turn that context into objectives, attack scenarios and clear Rules of Engagement.

During execution, you will have room to adapt. The aim is not to follow a checklist, but to emulate a credible adversary without losing sight of safety or learning value. We close with transparent reporting, executive and technical presentations, and often a purple teaming session in which attacks are replayed with the defenders.

What you can expect from us

Serious red team work requires trust, time to learn and colleagues who can challenge your thinking. We offer:

  • Complex, multi-week adversary simulation assignments with meaningful objectives.
  • A team of specialists who share knowledge and bring different perspectives to an operation.
  • Direct collaboration with offensive, defensive, threat intelligence, reverse engineering and incident-response experts.
  • Time and budget for training, certifications, conferences and longer development programmes.
  • Professional equipment and the tooling needed to do your work well.
  • Hybrid working with access to our offices in Belgium, Germany, the Netherlands and Sweden.
  • A competitive local compensation and benefits package. Salary, leave, pension, mobility and allowances differ by country. Our recruiter will explain the package that applies to your location.
  • Room to influence our methods, tooling and the future of our red team services as demand grows.
Job Requirements
Essential
  • Several years of hands-on penetration testing or red team experience, including responsibility for planning and executing operations.
  • Strong attack-path knowledge in Windows and Active Directory environments.
  • Experience with Entra ID or other cloud environments.
  • Practical command-and-control, OPSEC and infrastructure skills.
  • The judgement to balance operational objectives, client safety and learning value.
  • Clear written and spoken English, with the ability to explain decisions and findings to both technical and non-technical audiences.
  • A collaborative approach: you ask for a second pair of eyes, share what worked and help others improve.
  • Eligibility to work from Belgium, Germany, the Netherlands or Sweden, and willingness to travel for client work when an engagement requires it.
Useful, but not required
  • Experience delivering ART, TIBER or another structured threat-led red team framework.
  • Depth in one or more areas such as social engineering, malware development, cloud, application security, exploit development or reverse engineering.
  • Relevant certifications such as OSCP, OSEP or CRTO. We value demonstrated capability and sound judgement more than a checklist of certificates.
  • Another European language in addition to English.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Experienced Red Team Operator
Experienced Red Team Operator

Northwave • Utrecht

On-site
EUR 70,000 - 120,000
Hybrid working
Global offices across Europe
Senior Red Team Operator - Adversary Simulation Expert
Senior Red Team Operator - Adversary Simulation Expert

Northwave • Utrecht

Hybrid
EUR 70,000 - 120,000
Hybrid working
Global offices across Europe
Senior Red Team Operator - Adversary Simulation Expert
Senior Red Team Operator - Adversary Simulation Expert

Northwave Cyber Security • Utrecht

Hybrid
EUR 80,000 - 110,000
Hybrid working and international reloc
Training budget and certifications
Professional equipment provided
+1
Security Automation Engineer
Security Automation Engineer

Northwave • Utrecht

Hybrid
EUR 50,000 - 70,000
Competitive salary with annual review
Pension contributions
25 vacation days plus national holidays
+3
Senior Stack Engineer
Senior Stack Engineer

Northwave • Utrecht

On-site
EUR 60,000 - 80,000
Detection Quality Engineer
Detection Quality Engineer

Northwave • Utrecht

On-site
EUR 70,000 - 110,000
Senior Stack Engineer
Senior Stack Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
Detection Quality Engineer
Detection Quality Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
SOC Analyst
SOC Analyst

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
25 vacation days plus all Dutch national holidays
€200 net annual allowance for flexible and remote working
Learning budget from €700 to €1,200 per year
(Senior) Penetration Tester - NL
(Senior) Penetration Tester - NL

Capgemini • Utrecht

On-site
EUR 55,000 - 75,000
Direct een vast contract
All You Can Train
26 vakantiedagen
+2