Security Engineer (Offensive) - Red Team Operational Vulnerability Assessor

Resource Management Concepts, Inc.

Quantico (VA)

Hybrid

USD 150,000 - 165,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Relocation assistance
Paid vacation
401K with match
Healthcare plans

Job summary

Resource Management Concepts, Inc. (RMC) seeks a highly skilled Red Team OVA/Operator based near Quantico, VA.

The role focuses on planning and executing operational vulnerability assessments of OT systems, IT/OT integration, and adversary emulation to improve detection and response capabilities for DoW environments. You will conduct no-notice assessments, develop PoCs, and deliver detailed remediation guidance while collaborating with blue teams and engineers.

Qualifications

  • TS/SCI eligibility required.
  • 5 years of cybersecurity experience (Red Team, pentest, IR, etc.).
  • DoD 8570 IAT Level III and CSSP Auditor certifications or equivalent.
  • Demonstrated knowledge of OT/ICS/IoT environments.
  • Ability to pass RTOC RTCP level course on first attempt.

Responsibilities

  • Plan and conduct Operational Vulnerability Assessments of OT security during missions.
  • Exploit network, host, and application vulnerabilities and create PoCs.
  • Produce detailed findings and remediation recommendations.
  • Collaborate with defensive/engineering teams to improve detections.
  • Contribute to training, playbooks, and policy updates.
  • Support CSSP accreditation efforts and maintain documentation.

Skills

Red Team operations
Vulnerability assessment
OT/ICS security
IoT security experience
PCO adversary emulation
C/C++ development
Malware analysis
Cloud platforms (AWS/Azure/GCP)
OSCP/OSEP/OSCE_CRTO
CISM/CISSP/CISA knowledge

Education

DoD 8570 IAT Level III certifications
DoD 8570 CSSP Auditor certifications
DoD 8140 DCWF 541 VA analyst certs

Tools

C
C++
Windows
Linux

Job description

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.

We are seeking a highly skilled Red Team Operational Vulnerability Assessor (OVA)/Operator to join one of only eleven Department of War (DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United States Cyber Command (USCYBERCOM). This team is based out of Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security. You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.

The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.

Requirements
Responsibilities
  • Primary role will be to plan and conduct Operational Vulnerability Assessments (OVA) of the security and defense of Operational Technology (OT) during discrete missions, often with additional objectives, including physical/wireless security, or specific vulnerabilities.
  • For this specific position, we are seeking experience in Industrial Control Systems (ICS), Internet of Things (IoT), and Facility-Related Control System (FRCS) environments.
  • This position may likely include supporting and conducting other roles within the Red Team, to include
  • Both Operational Technology (OT) and Information Technology (IT) vulnerability assessments
  • Persistent Cyberspace Operations (PCO) adversary emulation
  • Acquisition Penetration Testing (APT) via Adversarial Assessments of DoW systems
  • Support exercise objectives and training goals as an Opposing Force Aggressor (OFA)
  • Assist in the instruction of the customer's Red Team Operations Course (RTOC)
  • Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.
  • Identify and exploit network, host, and application-level vulnerabilities.
  • Develop and refine proof-of-concept exploits and techniques to test defensive measures.
  • Produce detailed technical findings and recommendations for remediation.
  • Collaborate with defensive and engineering teams to improve detection and response.
  • Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.
  • Participate in after-action reviews and contribute to policy and playbook updates.
  • Prepare, update, document, and present course materials that cover TTPs.
  • Provide support required to maintain the customer's Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.
  • Considerable travel. Normal schedule is Monday-Friday unless on travel supporting a discrete mission. Approximately 25% of support and schedule is either onsite at Quantico, VA, or on travel. The remainder of the schedule is remote. This can change based on the needs of the customer's mission. During normal schedule and during remote support periods, candidates should be feasibly able to report onsite to Quantico, VA, within two hours.
Minimum Qualifications
  • TS/SCI eligibility
  • 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).
  • Possess and maintain a DoD 8570 IAT Level III certification: SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP.
  • Possess and maintain a DoD 8570 CSSP Auditor certification: CySA+, CEH, CISA, GSNA, CFR, PenTest.
  • Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements: CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA.
  • Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active Directory).
  • Once placed in this role, candidates must pass the customer's Red Team Operations Course (RTOC) at the Red Team Certified Professional (RTCP) level upon the first attempt of the RTOC. Depending on timing and schedule of this course, course availability may or may not be immediate after starting the position.
Preferred Qualifications
  • Experience with any of the following
  • AV/EDR evasion and detection-bypass techniques.
  • Custom tooling, payload or, command-and-control (C2) development.
  • Software development in C, C++, or a similar language.
  • Malware analysis and reverse engineering.
  • Cloud platforms and services (AWS, Azure, GCP).
  • Physical security assessments or red-team intrusion exercises.
  • Industrial control systems (ICS) and Internet of Things (IoT) environments.
  • Offensive-security certifications such as OSCP, OSEP, OSCE, CRTO. CRTL, GXPN.
Benefits
  • At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.
  • RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.
  • Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $150,000 to $165,000 (annually).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead
Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead

Resource Management Concepts, Inc. • Quantico (VA)

On-site
USD 150,000 - 175,000
Relocation assistance
Paid vacation (11 federal holidays)
Healthcare plans
+2
Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead
Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead

RMC - Resource Management Concepts Inc. • Quantico (VA)

On-site
USD 150,000 - 175,000
Relocation assistance
Paid vacation and federal holidays
401K package
+2
Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead
Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead

Socket.dev • Quantico (VA)

On-site
USD 150,000 - 175,000
Relocation assistance
11 paid holidays
Healthcare
+2
Elite Red Team Operator: OT/ICS Vulnerability Assessor
Elite Red Team Operator: OT/ICS Vulnerability Assessor

Resource Management Concepts, Inc. • Quantico (VA)

Hybrid
USD 150,000 - 165,000
Relocation assistance
Paid vacation
401K with match
+1
Red Team Operator (Hybrid)
Red Team Operator (Hybrid)

Sentar • United States

On-site
USD 140,000 - 210,000
Voluntary Medical, Dental, Vision with
Health Savings or Flexible Spending
Generous 401(k) match
+2
Senior OT Cybersecurity Analyst
Senior OT Cybersecurity Analyst

Rmcinc • Norfolk (VA)

Hybrid
USD 100,000 - 130,000
Comprehensive health, vision, and dental insurance
Participation in Annual Bonus Program
Life insurance policy
+3
Senior OT Cybersecurity Analyst
Senior OT Cybersecurity Analyst

Rmcinc • San Diego (CA)

Hybrid
USD 100,000 - 150,000
Comprehensive health, vision, and dental insurance
Participation in Annual Bonus Program
Life insurance
+3
Senior OT Cybersecurity Analyst
Senior OT Cybersecurity Analyst

RMC Global • San Diego (CA)

Hybrid
USD 90,000 - 130,000
Comprehensive health, vision, and dental insurance
Participation in Annual Bonus Program
Life insurance policy
+4
Red Team Operator (Hybrid)
Red Team Operator (Hybrid)

Sentar Inc. • Quantico (VA)

On-site
USD 120,000 - 180,000
Voluntary Medical, Dental, Vision
Health Savings or Flexible Spending
Group Term Life & Disability
+4
Red Team Operator (Senior)
Red Team Operator (Senior)

Cyber Defense Technologies • Chantilly (VA)

On-site
USD 160,000 - 210,000
Health insurance
Dental coverage
Vision coverage
+1