Red-Team / Adversarial Security Lead

Steampunk

McLean (VA)

On-site

USD 85,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Steampunk is seeking a Red-Team / Adversarial Security Lead to plan and execute threat-based assessments across enterprise environments. You will develop threat models, conduct adversarial testing, and evaluate security controls to support pass/fail safety gating.

You will collaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams, document findings with evidence, and drive remediation verification across Windows, Linux, and cloud platforms.

Qualifications

  • Ability to obtain and maintain a government security clearance.
  • 5+ years in cybersecurity with hands-on testing and red-team operations.
  • Experience with threat modeling methodologies at scale (STRIDE or equivalent).
  • Experience planning and executing technical security assessments and red-team engagements.
  • Deep technical experience across Windows and Linux environments.
  • Knowledge of attack techniques, vulnerabilities, and defensive controls.
  • Cloud architecture and security concepts across AWS, Azure, and GCP.
  • Ability to document findings, evidence, and remediation actions.
  • Strong analytical, problem-solving, and communication skills.

Responsibilities

  • Develop threat models to identify threats, attack vectors, and risks.
  • Plan and execute red-team/adversarial security assessments aligned to objectives.
  • Perform penetration testing to validate vulnerabilities and exploit paths.
  • Evaluate security controls and effectiveness against criteria.
  • Document findings with evidence and remediation recommendations.
  • Collaborate with security, infra, cloud, engineering, and architecture teams.
  • Validate remediation through follow-up testing.
  • Maintain awareness of evolving threats and techniques.
  • Support development of red-team methodologies and criteria.
  • Communicate risks and remediation steps to stakeholders.

Skills

Adversarial security testing
Threat modeling
Penetration testing
Cloud security
Security testing frameworks

Education

Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related field

Tools

AWS
Azure
GCP

Job description

Overview

We are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls.

The Red-Team / Adversarial Security Lead will analyze and document assessment results, communicate identified risks and vulnerabilities, recommend appropriate remediation actions, and support pass/fail safety-gate determinations based on established security criteria. This role requires strong technical cybersecurity experience across operating systems, infrastructure, and cloud environments.

Contributions
  • Develop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environments
  • Develop and execute red-team and adversarial security assessment plans based on defined objectives and security criteria
  • Perform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack paths
  • Evaluate the effectiveness of existing security controls through technical testing and adversarial techniques
  • Analyze vulnerabilities and assessment findings to determine exploitability, potential impact, and associated security risk
  • Conduct security assessments across diverse operating systems and enterprise technology environments
  • Assess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)
  • Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actions
  • Evaluate assessment results against established security and safety-gate criteria and support pass/fail determinations
  • Communicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholders
  • Collaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risks
  • Validate remediation of identified vulnerabilities and security weaknesses through follow-up testing
  • Maintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practices
  • Support the development and refinement of red-team methodologies, assessment procedures, and security testing criteria
Qualifications

Required:

  • Ability to obtain and maintain a government security clearance
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience
  • 5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplines
  • Experience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risks
  • Experience planning and executing technical security assessments, penetration tests, or adversarial security assessments
  • Deep technical experience across operating systems and associated security concepts, including environments such as Windows and Linux
  • Experience identifying, validating, and assessing vulnerabilities and potential attack paths
  • Knowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controls
  • Experience with cloud architecture and security concepts across AWS, Azure, and/or GCP
  • Ability to analyze technical security findings and evaluate their potential impact and risk
  • Experience documenting technical findings, supporting evidence, and remediation recommendations
  • Strong analytical, problem-solving, communication, and collaboration skills

Preferred:

  • Experience conducting red-team assessments across complex enterprise environments
  • Experience with multiple cloud platforms, including AWS, Azure, and GCP
  • Experience with adversary emulation and penetration testing tools and methodologies
  • Knowledge of MITRE ATT&CK and related adversarial tactics, techniques, and procedures
  • Experience evaluating security assessment results against defined acceptance, release, or safety-gate criteria
  • Experience working within federal government or other highly regulated environments
  • Offensive Security Certified Professional (OSCP) or comparable hands‑on offensive security/penetration testing certification strongly preferred; comparable certifications may include GIAC Penetration Tester (GPEN), Practical Network Penetration Tester (PNPT), Hack The Box Certified Penetration Testing Specialist (HTB CPTS), or equivalent
About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $85,000 to $170,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red-Team / Adversarial Security Lead
Red-Team / Adversarial Security Lead

Steampunk • Bloomington (IL)

On-site
USD 85,000 - 170,000
Red-Team / Adversarial Security Lead
Red-Team / Adversarial Security Lead

Steampunk, Inc. • McLean (VA)

On-site
USD 85,000 - 170,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk • McLean (VA)

On-site
USD 85,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

Steampunk • Bloomington (IL)

On-site
USD 125,000 - 175,000
Vulnerability Management Lead
Vulnerability Management Lead

Steampunk, Inc. • McLean (VA)

On-site
USD 125,000 - 175,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk, Inc. • McLean (VA)

On-site
USD 85,000 - 170,000
Senior Test Engineer
Senior Test Engineer

Steampunk • McLean (VA)

On-site
USD 110,000 - 160,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Steampunk, Inc. • McLean (VA)

On-site
USD 150,000 - 185,000
RMF Security SME
RMF Security SME

Steampunk • Bloomington (IL)

On-site
USD 130,000 - 180,000
Senior DevSecOps (Pipeline) Engineer
Senior DevSecOps (Pipeline) Engineer

Steampunk • Bloomington (IL)

On-site
USD 150,000 - 185,000