Senior Consultant, Red Team Operator, Offensive Security

Kroll

Northern (KY)

Hybrid

USD 110,000 - 150,000

Full time

28 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Kroll is seeking a Senior Consultant, Red Team Operator to expand our offensive security capabilities. You will lead complex red team, purple team, and adversary emulation engagements across multiple sectors, working with clients to define objectives, attack paths, and engagement rules.

Responsibilities include executing tests across AD, cloud platforms, and hybrid environments, building red team infrastructure, and providing actionable remediation guidance.

Qualifications

  • 5+ years in offensive cybersecurity, including red/purple team engagements.
  • Experience with Windows enterprise environments and AD exploitation.
  • Experience with social engineering in red team operations.
  • Experience operating command-and-control frameworks such as Mythic or Cobalt Strike.
  • Knowledge of evasion techniques and detection-aware tradecraft.
  • Excellent written and verbal communication skills for technical and non-technical audiences.

Responsibilities

  • Deliver red team, purple team, assumed-breach, and adversary emulation engagements for clients across multiple sectors
  • Support engagement planning, including threat-informed scenarios, attack objectives, rules of engagement, and success criteria
  • Execute hands-on offensive activity across enterprise environments, including AD exploitation, credential access, privilege escalation, lateral movement, and objective-based testing
  • Assess and exploit attack paths across Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms
  • Build, adapt, and operate red team infrastructure, tooling, payloads, and scripts during engagements
  • Apply detection-aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring affect operations
  • Produce clear, evidence-based reporting that explains attack paths, business impact, and remediation actions
  • Present technical findings to security teams and communicate risk to senior stakeholders
  • Mentor junior consultants and support quality assurance
  • Collaborate with wider Cyber Risk teams, including incident response and threat intelligence

Skills

Red Team Operations
Adversary Emulation
Social Engineering
Cobalt Strike
Threat Modeling
Tooling Development

Tools

Mythic
Cobalt Strike

Job description

Senior Consultant, Red Team Operator, Offensive Security

Cybersecurity

Cybersecurity | United States | 21015130

Share This

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We help our clients discover, understand, and remediate security risks across their networks, systems, applications, cloud environments, and identity platforms. Our clients trust us to use advanced offensive security tools, creativity, imagination, and expert knowledge to identify realistic attack paths and improve cyber resilience.

We are looking to grow our Red Team capability with a Senior Consultant / L3 Red Team Operator. Our expertise in red team operations, purple team engagements, assumed-breach testing, adversary emulation, and threat intelligence-led penetration testing is in high demand. Our collaborative ties to our forensic and incident response team, detection engineering team, threat intelligence team, and wider Cyber Risk practice enable us to deliver high-impact offensive security engagements for clients across a range of sectors.

What you’ll do

As a Senior Consultant, Red Team Operator, you will support the delivery of complex red team, purple team, assumed-breach, and adversary emulation engagements. You will work with clients to understand their environments, help define realistic attack objectives, develop attack paths, and execute authorised offensive security activity within agreed rules of engagement.

You will be expected to operate across a range of attack surfaces, including enterprise networks, Active Directory, Microsoft Entra ID, Microsoft 365, cloud platforms, endpoints, externally exposed services, and, where authorised, social engineering scenarios. You will also help clients understand the business impact of identified attack paths and provide clear, actionable recommendations to improve prevention, detection, and response.

In summary, you will:

  • Deliver red team, purple team, assumed-breach, and adversary emulation engagements for clients across multiple sectors
  • Support engagement planning, including threat-informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria
  • Execute hands-on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective-based testing
  • Assess and exploit attack paths across Microsoft Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms, where in scope
  • Build, adapt, and operate red team infrastructure, command-and-control tooling, payloads, and scripts during authorised client engagements
  • Apply detection-aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations
  • Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability
  • Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios
  • Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting
  • Produce clear, evidence-based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions
  • Present technical findings to security teams and communicate business risk to senior stakeholders
  • Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance
  • Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering
What you’ll need to succeed
  • 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed-breach engagements
  • Strong experience with Windows enterprise environments, Active Directory exploitation, privilege escalation, and lateral movement
  • Experienced and comfortable with performing social engineering techniques in support of red team operations, including email and voice phishing
  • Experience operating command-and-control frameworks such as, Mythic, Cobalt Strike, or similar tooling in authorised client engagements
  • Experience developing, modifying, or extending offensive security tooling, scripts, or payloads
  • Practical understanding of evasion techniques, endpoint security controls, operational security, and detection-aware tradecraft
  • Strong understanding of networking and web protocols, including TCP/IP, DNS, HTTP, HTTPS, and authentication flows
  • Experience conducting reconnaissance, attack path development, and objective-based testing
  • Excellent written and verbal communication skills, with the ability to explain complex technical issues clearly to technical and non-technical audiences
  • The ability to manage risk during live client engagements and operate within agreed rules of engagement
Nice to have
  • OSEP, OSCE3, CRTO, CRTL, GPEN, GXPN, or equivalent experience
  • Experience delivering threat intelligence driven red team engagements
  • Strong working knowledge of Microsoft Entra ID, Microsoft 365, and hybrid identity attack paths
  • Working knowledge of cloud platforms such as AWS, Azure, or GCP, including identity, privilege escalation, misconfiguration abuse, and cloud-native attack paths
  • Experience with exploit development, reverse engineering, malware analysis, or assembly-level debugging
  • Experience with macOS or Linux endpoint tradecraft
  • Experience with Kubernetes, Docker, CI/CD platforms, DevOps environments, or containerised workloads
  • Experience with physical security
  • Experience with employing modern AI tooling to support offensive engagements
  • Experience writing blogs, presenting at industry events, publishing research, or contributing to offensive security tooling

Experience leading small teams or technical workstreams during complex offensive security engagements

Kroll is committed to creating an inclusive work environment. We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age, or disability.

Salary range for this role is $110,000 - $150,000 USD

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Red Team Operator — Offensive Security
Senior Red Team Operator — Offensive Security

Kroll • Northern (KY)

Hybrid
USD 110,000 - 150,000
Senior Red Team Operator — Offensive Security Expert
Senior Red Team Operator — Offensive Security Expert

RiseMe • United States

Remote
USD 110,000 - 150,000
Senior Manager, Threat Intelligence
Senior Manager, Threat Intelligence

Kroll • Northern (KY)

Hybrid
USD 90,000 - 170,000
Healthcare coverage
Generous PTO and parental leave
Life insurance and disability coverage
+2
Red Team Operator
Red Team Operator

SoTalent • United States

On-site
USD 100,000 - 130,000
Competitive compensation and performance incentives
Comprehensive health and wellness benefits
401(k) with employer match
+3
Senior Director, Cyber Threat Intellignece
Senior Director, Cyber Threat Intellignece

Kroll • United States

On-site
USD 200,000 - 300,000
Healthcare coverage
401(k) matching
Paid time off
Senior Security Consultant, Red Team
Senior Security Consultant, Red Team

IOActive, Inc. • United States

On-site
USD 75,000 - 150,000
Competitive compensation
Access to world-class technical teams
Flexibility to work remotely or from the office
+1
Senior Offensive Security Engineer
Senior Offensive Security Engineer

United States Digital Space LLC • Bellevue (NY)

On-site
USD 187,000 - 220,000
Health insurance
Equity
Wellness allowance
+4
Offensive Cyber Operations Lead
Offensive Cyber Operations Lead

WorkNovas LLC • Tampa (FL)

Hybrid
USD 140,000 - 190,000
Red Team Operator
Red Team Operator

Dark Wolf • Colorado Springs (CO)

Hybrid
USD 155,000 - 180,000
Red Team Manager (Remote)
Red Team Manager (Remote)

CrowdStrike • United States

On-site
USD 140,000 - 195,000
Competitive compensation
Wellness programs
Parental leave
+3