Security Validation Engineer (Red Team)

Athena

Palo Alto (CA)

On-site

USD 140,000 - 190,000

Full time

19 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Athena in Palo Alto is seeking a Security Validation Engineer to join our Red Team. You will plan, design, and execute red team engagements across infrastructure, applications, and cloud environments, and perform end-to-end attack simulations including phishing and lateral movement.

You will develop tools and provide remediation guidance, collaborate with incident response and threat intelligence teams, and stay current with emerging threats and offensive security techniques.

Qualifications

  • Knowledge of penetration testing methodologies (OWASP, MITRE ATT&CK, NIST).
  • Proficiency with exploitation frameworks, scripting, and tools (Cobalt Strike, Metasploit, Burp Suite, BloodHound, Python, PowerShell).
  • Hands-on experience with attack vectors across networks, operating systems, applications, and cloud platforms.
  • Familiarity with Active Directory attacks, privilege escalation, persistence techniques, and evasion methods.
  • Understanding of enterprise defense mechanisms such as EDR, SIEM, logging, and network monitoring.
  • Strong problem-solving and analytical skills with the ability to think like an attacker.
  • Excellent written and verbal communication skills for documenting findings and presenting results.

Responsibilities

  • Plan, design, and execute red team engagements across infrastructure, applications, and cloud environments.
  • Conduct manual and automated penetration testing to identify exploitable vulnerabilities and misconfigurations.
  • Develop and execute adversary emulation scenarios to validate detection and response capabilities.
  • Perform end-to-end attack simulations, including phishing, lateral movement, privilege escalation, and data exfiltration.
  • Build and maintain custom tools, scripts, or frameworks to support red team operations.
  • Validate the effectiveness of blue team defenses and provide actionable feedback for improving detection, prevention, and response measures.
  • Document findings with clear risk impact assessment and remediation guidance.
  • Collaborate closely with incident response, threat intelligence, and engineering teams to share attacker tradecraft and improve security controls.
  • Stay current with emerging threats, vulnerabilities, and offensive security techniques.

Skills

Penetration testing methodologies
Attack vector knowledge
Problem solving mindset
Communication skills

Tools

Cobalt Strike
Metasploit
Burp Suite
BloodHound
Python
PowerShell

Job description

We are seeking a Security Validation Engineer to join our Red Team. This role is focused on identifying, validating, and exploiting vulnerabilities across systems, applications, and infrastructure to simulate real-world adversary behavior. As part of the security organization, you will help evaluate and strengthen our security posture by rigorously testing defenses, collaboratively reporting findings, and recommending mitigations.

Key Responsibilities
  • Plan, design, and execute red team engagements across infrastructure, applications, and cloud environments.
  • Conduct manual and automated penetration testing to identify exploitable vulnerabilities and misconfigurations.
  • Develop and execute adversary emulation scenarios to validate detection and response capabilities.
  • Perform end-to-end attack simulations, including tactics such as phishing, lateral movement, privilege escalation, and data exfiltration.
  • Build and maintain custom tools, scripts, or frameworks to support red team operations.
  • Validate the effectiveness of blue team defenses and provide actionable feedback for improving detection, prevention, and response measures.
  • Document findings with clear risk impact assessment and remediation guidance.
  • Collaborate closely with incident response, threat intelligence, and engineering teams to share attacker tradecraft and improve security controls.
  • Stay current with emerging threats, vulnerabilities, and offensive security techniques.
Required Qualifications
  • Strong knowledge of penetration testing methodologies (OWASP, MITRE ATT&CK, NIST, etc.).
  • Proficiency in exploitation frameworks, scripting, and tools (e.g., Cobalt Strike, Metasploit, Burp Suite, BloodHound, Python, PowerShell).
  • Hands‑on experience with attack vectors across networks, operating systems, applications, and cloud platforms.
  • Familiarity with Active Directory attacks, privilege escalation, persistence techniques, and evasion methods.
  • Understanding of enterprise defense mechanisms such as EDR, SIEM, logging, and network monitoring.
  • Solid problem‑solving and analytical skills with the ability to think like an attacker.
  • Excellent written and verbal communication skills for documenting findings and presenting results to both technical and non‑technical audiences.
Preferred Skills
  • Prior experience in a Red Team, Purple Team, or advanced penetration testing role.
  • Knowledge of adversary emulation frameworks and threat modeling.
  • Scripting capability (Python, PowerShell, Bash, or Go).
  • OSCP, OSCE, OSEP, CRTP, or similar offensive security certifications.
  • Knowledge of cloud security (AWS, Azure, GCP) attack surfaces.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Red Team Engineer
AI Red Team Engineer

ByLabs • San Francisco (CA)

On-site
USD 150,000 - 190,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Red Team Operator
Red Team Operator

SoTalent • United States

On-site
USD 100,000 - 130,000
Competitive compensation and performance incentives
Comprehensive health and wellness benefits
401(k) with employer match
+3
Senior Red Team & Offensive Security Engineer
Senior Red Team & Offensive Security Engineer

Veracity Engineering • Atlantic City (NJ)

On-site
USD 90,000 - 125,000
Tuition reimbursement
Health benefits
Paid time off
+2
Security Software Engineer – Red Team Penetration Tester
Security Software Engineer – Red Team Penetration Tester

RPI Group, Inc. • Dahlgren (VA)

On-site
USD 110,000 - 150,000
Security Software Engineer – Red Team Penetration Tester
Security Software Engineer – Red Team Penetration Tester

RPI Group Inc • Dahlgren (VA)

On-site
USD 110,000 - 150,000
Security Engineer – Offensive Security
Security Engineer – Offensive Security

Jobtailor • California (MO)

On-site
USD 180,000 - 280,000
Security Software Engineer – Red Team Penetration Tester with Security Clearance
Security Software Engineer – Red Team Penetration Tester with Security Clearance

RPI Group, Inc. • Dahlgren (VA)

On-site
USD 110,000 - 150,000
Red Team Operator
Red Team Operator

Dark Wolf • Colorado Springs (CO)

Hybrid
USD 155,000 - 180,000
Senior Analyst, Cybersecurity Red Team – Offensive Security/Penetration Testing
Senior Analyst, Cybersecurity Red Team – Offensive Security/Penetration Testing

Jobtailor • Pennsylvania

On-site
USD 120,000 - 180,000