Principal Red Team Operator

Citizens Bank

Raleigh (NC)

Hybrid

USD 120,000 - 210,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Citizens Bank is seeking a Principal Operator, Red Team to perform advanced adversary emulation across on-prem, cloud, SaaS and hybrid environments. This hands-on role tests controls and translates findings into measurable improvements in detection, response, and risk posture.

You will work with Blue Team, Detection Engineering, Threat Intelligence, and Incident Response in a purple-team approach with a hybrid schedule (4 days onsite, 1 day remote) across designated hub locations.

Qualifications

  • Hands-on Red Team and adversary emulation experience across complex environments.
  • Ability to design and execute attack paths across on-prem, cloud, SaaS and hybrid
  • Strong collaboration with Blue Team and Detection Engineering to translate activity into improved defenses
  • Excellent documentation and testing discipline for engagements
  • Familiarity with AI security testing and misuse scenarios

Responsibilities

  • Execute Red Team and Purple Team engagements including adversary emulation and breach scenarios
  • Design and execute campaign-based attacks across enterprise environments
  • Perform exploitation across on-prem, cloud, SaaS and hybrid infrastructures
  • Simulate attacker tradecraft including living off the land, privilege escalation, lateral movement
  • Test AI-enabled systems and workflows for misuse by attackers
  • Conduct prompt manipulation and AI model misuse assessments
  • Collaborate with Detection Engineering to validate detections and close gaps
  • Translate offensive findings into remediation insights with stakeholders
  • Ensure engagement findings are tracked through resolution and risk reduction
  • Develop targeted scripts or payloads to emulate adversary behaviors
  • Document findings and contribute to engagement reports and debriefs
  • Operate within rules of engagement and safety protocols
  • Stay current on evolving adversary tactics and tooling

Skills

Red Team operations
Adversary emulation
Cloud and AI security
Threat simulation
Operational discipline

Education

Bachelor's Degree in Security / CS / IT or related field
OSCP, OSEP, CRTO, CRTP or similar
AI security testing exposure

Tools

Caldera
Metasploit
Atomic Red Team

Job description

Description
Principal Operator, Red Team
Role Summary

The Operator, Red Team is a hands on offensive security practitioner responsible for executing advanced adversary emulation and continuous red teaming operations across a modern, cloud and AI enabled enterprise. This role plays a critical part in building and scaling the organization’s offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

Operating within high impact engagements, this individual will simulate real world attackers, identify and validate attack paths, and partner closely with defensive teams to ensure findings translate into measurable improvements in detection, response, and overall risk posture. Success in this role requires deep technical tradecraft, strong operational discipline, and a mindset focused not just on breaking systems, but on strengthening them through full lifecycle accountability.

This role reports to the Red Team Manager and works closely with Blue Team, Detection Engineering, Threat Intelligence, and Incident Response through Purple Teaming to continuously improve defensive effectiveness.

Locations & Work Arrangement: Remote is not an option

candidates must be willing to commute to one of the following hub locations with a hybrid schedule of 4 days onsite and 1 day remote per week with flexibility in one of the following hubs:

  • Phoenix
  • Johnston, RI
  • Boston, MA
  • Iselin, NJ
  • Pittsburgh, PA
  • Plano or Irving TX
  • Charlotte, NC
  • Manchester, NH
Key Responsibilities
  • Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths
  • Design and execute campaign based attack operations that simulate real world adversary behavior across enterprise environments
  • Perform hands on exploitation and abuse across on prem, cloud, SaaS, and hybrid infrastructures
  • Simulate advanced attacker tradecraft, including living off the land techniques, identity abuse, privilege escalation, lateral movement, persistence, command and control, and controlled data exfiltration
  • Conduct testing against AI enabled systems and workflows, including abuse and misuse of AI assistants, copilots, and automation platforms
  • Execute prompt manipulation, indirect prompt injection, and AI model misuse scenarios to evaluate emerging attack surfaces
  • Collaborate closely with Detection Engineering and Blue Team during Purple Team engagements to validate detections, identify coverage gaps, and refine response effectiveness
  • Translate offensive findings into actionable remediation insights and partner with stakeholders to ensure vulnerabilities are addressed and control effectiveness is improved
  • Contribute to full lifecycle execution of engagements, ensuring findings are tracked through resolution and result in measurable risk reduction
  • Leverage and extend red team tooling and frameworks and develop targeted scripts or payloads to emulate specific adversary behaviors
  • Document findings clearly, including attack paths, control weaknesses, and detection gaps, contributing to engagement reports and technical debriefs
  • Operate within defined rules of engagement, safety protocols, and ethical guidelines to ensure realistic and controlled testing
  • Stay current on evolving adversary tactics, offensive tooling, and AI security research, incorporating new techniques into ongoing testing efforts
Experience and Skills
  • 4 to 8 years of hands on cybersecurity experience with a strong focus on Red Team operations, adversary emulation, or advanced offensive security
  • Demonstrated experience executing Red Team or Purple Team engagements in assumed breach or adversary based scenarios
  • Proven ability to design and execute attack paths rather than relying solely on automated tools or point in time testing
  • Strong technical capability across multiple attack surfaces, including identity and access attacks, endpoint and network exploitation, cloud and SaaS environments, and command and control frameworks
  • Understanding of campaign based red teaming and continuous testing approaches, including iterative and regression style validation
  • Working knowledge of AI security concepts, including how AI enabled systems, inputs, and workflows can be manipulated or abused
  • Ability to collaborate with Blue Team and Detection Engineering to translate offensive activity into improved detection and response capabilities
  • Strong operational discipline, including clear documentation, safe execution, and adherence to engagement constraints
  • Effective communication skills, with the ability to explain technical findings to security practitioners and cross functional partners
  • Demonstrated curiosity, adaptability, and ability to operate in rapidly evolving threat and technology environments
Education and Certifications
  • Bachelor’s Degree in Security, Computer Science, Information Technology, or related field, or equivalent experience
  • Relevant industry certifications such as OSCP, OSEP, CRTO, CRTP, or similar advanced offensive security credentials
  • Exposure to AI security testing or AI red teaming through hands on work, training, or research is preferred
Pay Transparency

The salary range for this position is from $120,000 to $210,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to, the budget, work location, relevant skills, and experience.

We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Red Team Operator
Principal Red Team Operator

Citizens Bank • Woodbridge Township (NJ)

Hybrid
USD 150,000 - 210,000
Comprehensive medical coverage
Retirement benefits
Maternity and paternity leave
Red Team Manager
Red Team Manager

Citizens Bank • Marlton (NJ)

On-site
USD 170,000 - 230,000
Medical, dental, vision coverage
Retirement benefits
Flexible work arrangements
+1
Red Team Manager
Red Team Manager

Citizens • Marlton (NJ)

On-site
USD 170,000 - 230,000
Medical, dental, and vision coverage
Retirement benefits
Flexible work arrangements
+3
Principal Security Engineer
Principal Security Engineer

Citizens Bank • Johnston (RI)

On-site
USD 140,000 - 180,000
Comprehensive medical coverage
Retirement benefits
Education reimbursement
+1
Principal Security Engineer -DLP AI Security Automation
Principal Security Engineer -DLP AI Security Automation

Citizens Bank • Pittsburgh

Hybrid
USD 145,000 - 180,000
Competitive compensation
Comprehensive medical, dental, and vision coverage
Flexible work arrangements
+1
Technology Risk Principal Analyst- Data, AI and Emerging Technology
Technology Risk Principal Analyst- Data, AI and Emerging Technology

Citizens • Johnston (RI)

Hybrid
USD 138,000 - 200,000
Maternity/paternity leave
Education reimbursement
Wellness programs
+5
Senior Vulnerability Specialist (Infra)
Senior Vulnerability Specialist (Infra)

Citizens Bank • Woodbridge Township (NJ)

On-site
USD 96,000 - 135,000
Comprehensive medical, dental, and vision coverage
Flexible work arrangements
Education reimbursement
+1
Business Analyst
Business Analyst

Citizens Bank • Southfield (MI)

Hybrid
USD 140,000 - 160,000
Comprehensive medical, dental and vision coverage
Retirement benefits
Flexible work arrangements
+2
Senior Red Team Operator
Senior Red Team Operator

U.S. Bank • Englewood (CO)

Hybrid
USD 133,000 - 157,000
Healthcare (medical, dental, vision)
401(k) and employer‑funded retirement
Paid vacation and holidays
+2
Manager Application Security
Manager Application Security

Citizens Bank • Johnston (RI)

Hybrid
USD 133,000 - 190,000
Comprehensive medical, dental, and vision coverage
Retirement benefits
Flexible work arrangements
+1