Red Team Lead @Sherwin-Williams
All Others
Salary usd 108,531.02 ..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today

[Hiring] Red Team Lead @Sherwin-Williams

Today - Sherwin-Williams is hiring a remote Red Team Lead. 💸 Salary: usd 108,531.02 - 140,086.17 per year 📍Location: USA

Role Description

The Threat Management Red Team Lead is a cybersecurity leader responsible for defining, building, and leading the enterprise adversary emulation program. This role establishes strategy aligned to business risk and threat intelligence while overseeing execution of complex, end-to-end attack simulations across the enterprise.

The Red Team Lead ensures the organization’s security controls are effectively validated against realistic threat scenarios and drives measurable improvements in detection and response capabilities. This role requires a blend of deep technical expertise, program leadership, and strong cross-functional coordination across SOC, Threat Intelligence, Detection Engineering, and Application Security. This role reports directly to the Senior Manager – Threat Management.

Responsibilities

  • Define and lead the enterprise adversary simulation strategy aligned to business risk, threat intelligence, and emerging threats.
  • Build, mature, and continuously improve the Red Team program, including methodologies, tooling, and engagement frameworks.
  • Oversee planning and execution of complex attack scenarios across enterprise environments, ensuring realistic end-to-end adversary simulation.
  • Validate effectiveness of preventive, detective, and response controls through full attack chain execution.
  • Drive cross-team collaboration with SOC, Threat Intelligence, Detection Engineering, Application Security, and Security Champions to remediate gaps.
  • Lead purple team exercises to strengthen detection and response capabilities.
  • Ensure findings are tracked, prioritized by risk, remediated, and retested for validation.
  • Translate threat intelligence and business risk into prioritized adversary scenarios.
  • Deliver clear, risk-based reporting and metrics to leadership, highlighting control gaps and improvement areas.
  • Define and track key performance indicators (KPIs) to measure program effectiveness and security posture improvements.
  • Oversee selection, implementation, and operation of red team tooling and infrastructure.
  • Provide technical leadership and mentorship to Red Team operators.
  • Establish standards for tradecraft, documentation, and operational rigor.
  • Continuously evaluate and integrate new tools, techniques, and adversary tradecraft.

Qualifications

  • Education and Experience
  • Required:
    • Bachelor’s Degree (or foreign equivalent) or in lieu of a degree, at least 12 years in experience in the field of Information Technology or Business.
    • Relevant certifications such as OSCP, OSEP, CRTO, GXPN, GPEN, CISSP or similar are preferred.
    • 8+ years IT/Cybersecurity experience.
    • Proven experience leading or building a Red Team or adversary simulation program.
    • Strong expertise in adversary tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
    • Extensive experience planning and executing advanced red team operations in enterprise environments.
    • Experience coordinating across multiple security disciplines including SOC, Detection Engineering, and Incident Response.
    • Strong understanding of enterprise security architecture including identity, endpoints, networks, and cloud platforms.
    • Experience with full attack lifecycle including social engineering, lateral movement, persistence, and ransomware scenarios.
    • Strong communication skills with the ability to translate technical findings into business risk.
    • Must be legally authorized to work in the United States without company sponsorship.
    • Must be at least eighteen (18) years of age.
  • Preferred:
    • Experience with command-and-control frameworks (e.g., Sliver, Cobalt Strike, Mythic, or similar).
    • Familiarity with identity and Active Directory attack tooling (e.g., BloodHound, Impacket, Mimikatz).
    • Experience with cloud attack techniques and platforms.
    • Experience building and managing red team infrastructure and tooling ecosystems.
    • Exposure to adversary emulation validation platforms (e.g., SafeBreach).
    • Experience leading purple team or detection validation exercises.

Requirements

  • This is a remote position.
  • This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa.
  • Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.
  • Job duties include contact with other employees and access to confidential and proprietary information and/or other items of value.
  • A review of criminal history is necessary to protect the business and its operations and reputation.

Benefits

  • Life … with rewards, benefits and the flexibility to enhance your health and well-being.
  • Career … with opportunities to learn, develop new skills and grow your contribution.
  • Connection … with an inclusive team and commitment to our own and broader communities.

A general description of benefits offered can be found at http://www.myswbenefits.com/ . Click on “Candidates” to view benefit offerings that you may be eligible for if you are hired as a Sherwin-Williams employee.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Red Team Lead @Sherwin-Williams
All Others
Salary usd 108,531.02 ..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 129,314+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later