A complete application in a minute — tailored resume and cover letter, ready to send.
Citizens is seeking a Principal Operator, Red Team to lead offensive security engagements across cloud, AI-enabled systems, and hybrid environments. You will emulate real-world attackers, map attack paths, and collaborate with Blue Team to harden defenses.
You will work with a cross-functional Red/Blue team to translate findings into concrete detection improvements while maintaining strict safety and engagement rules of work. This role reports to the Red Team Manager.
Description
The Operator, Red Team is a hands on offensive security practitioner responsible for executing advanced adversary emulation and continuous red teaming operations across a modern, cloud and AI enabled enterprise. This role plays a critical part in building and scaling the organization’s offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.
Operating within high impact engagements, this individual will simulate real world attackers, identify and validate attack paths, and partner closely with defensive teams to ensure findings translate into measurable improvements in detection, response, and overall risk posture. Success in this role requires deep technical tradecraft, strong operational discipline, and a mindset focused not just on breaking systems, but on strengthening them through full lifecycle accountability.
This role reports to the Red Team Manager and works closely with Blue Team, Detection Engineering, Threat Intelligence, and Incident Response through Purple Teaming to continuously improve defensive effectiveness.
Johnston, RI
Boston, MA
Iselin, NJ
Pittsburgh, PA
Plano or Irving TX
Phoenix, AZ
Charlotte, NC
Manchester, NH
Cleveland, OH
Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths
Design and execute campaign based attack operations that simulate real world adversary behavior across enterprise environments
Perform hands on exploitation and abuse across on prem, cloud, SaaS, and hybrid infrastructures
Simulate advanced attacker tradecraft, including living off the land techniques, identity abuse, privilege escalation, lateral movement, persistence, command and control, and controlled data exfiltration
Conduct testing against AI enabled systems and workflows, including abuse and misuse of AI assistants, copilots, and automation platforms
Execute prompt manipulation, indirect prompt injection, and AI model misuse scenarios to evaluate emerging attack surfaces
Collaborate closely with Detection Engineering and Blue Team during Purple Team engagements to validate detections, identify coverage gaps, and refine response effectiveness
Translate offensive findings into actionable remediation insights and partner with stakeholders to ensure vulnerabilities are addressed and control effectiveness is improved
Contribute to full lifecycle execution of engagements, ensuring findings are tracked through resolution and result in measurable risk reduction
Leverage and extend red team tooling and frameworks and develop targeted scripts or payloads to emulate specific adversary behaviors
Document findings clearly, including attack paths, control weaknesses, and detection gaps, contributing to engagement reports and technical debriefs
Operate within defined rules of engagement, safety protocols, and ethical guidelines to ensure realistic and controlled testing
Stay current on evolving adversary tactics, offensive tooling, and AI security research, incorporating new techniques into ongoing testing efforts
4 to 8 years of hands on cybersecurity experience with a strong focus on Red Team operations, adversary emulation, or advanced offensive security
Demonstrated experience executing Red Team or Purple Team engagements in assumed breach or adversary based scenarios
Proven ability to design and execute attack paths rather than relying solely on automated tools or point in time testing
Strong technical capability across multiple attack surfaces, including identity and access attacks, endpoint and network exploitation, cloud and SaaS environments, and command and control frameworks
Understanding of campaign based red teaming and continuous testing approaches, including iterative and regression style validation
Working knowledge of AI security concepts, including how AI enabled systems, inputs, and workflows can be manipulated or abused
Ability to collaborate with Blue Team and Detection Engineering to translate offensive activity into improved detection and response capabilities
Strong operational discipline, including clear documentation, safe execution, and adherence to engagement constraints
Effective communication skills, with the ability to explain technical findings to security practitioners and cross functional partners
Demonstrated curiosity, adaptability, and ability to operate in rapidly evolving threat and technology environments
Bachelor’s Degree in Security, Computer Science, Information Technology, or related field, or equivalent experience
Relevant industry certifications such as OSCP, OSEP, CRTO, CRTP, or similar advanced offensive security credentials
Exposure to AI security testing or AI red teaming through hands on work, training, or research is preferred
The salary range for this position is from $120,000 to $210,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to, the budget, work location, relevant skills, and experience.
We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.
#LI-Citizens1
Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.
Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.
At Citizens, you'll find a customer-centric culture built around helping our customers and giving back to our local communities. When you join our team, you are part of a supportive and collaborative workforce, with access to training and tools to accelerate your potential and maximize your career growth
Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.
10/30/2026