Senior Consultant, Red Team Operator, Offensive Security @Kroll
All Others
Salary usd 110,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Senior Consultant, Red Team Operator, Offensive Security @Kroll

1wk ago - Kroll is hiring a remote Senior Consultant, Red Team Operator, Offensive Security. πŸ’Έ Salary: usd 110,000 - 150,000 per year πŸ“Location: USA

Role Description

As a Senior Consultant, Red Team Operator, you will support the delivery of complex red team, purple team, assumed-breach, and adversary emulation engagements. You will work with clients to understand their environments, help define realistic attack objectives, develop attack paths, and execute authorised offensive security activity within agreed rules of engagement.

You will be expected to operate across a range of attack surfaces, including:

  • Enterprise networks
  • Active Directory
  • Microsoft Entra ID
  • Microsoft 365
  • Cloud platforms
  • Endpoints
  • Externally exposed services
  • Social engineering scenarios (where authorised)

You will also help clients understand the business impact of identified attack paths and provide clear, actionable recommendations to improve prevention, detection, and response.

In summary, you will:

  • Deliver red team, purple team, assumed-breach, and adversary emulation engagements for clients across multiple sectors
  • Support engagement planning, including threat-informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria
  • Execute hands-on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective-based testing
  • Assess and exploit attack paths across Microsoft Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms, where in scope
  • Build, adapt, and operate red team infrastructure, command-and-control tooling, payloads, and scripts during authorised client engagements
  • Apply detection-aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations
  • Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability
  • Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios
  • Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting
  • Produce clear, evidence-based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions
  • Present technical findings to security teams and communicate business risk to senior stakeholders
  • Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance
  • Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering

Qualifications

  • 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed-breach engagements
  • Strong experience with Windows enterprise environments, Active Directory exploitation, privilege escalation, and lateral movement
  • Experienced and comfortable with performing social engineering techniques in support of red team operations, including email and voice phishing
  • Experience operating command-and-control frameworks such as Mythic, Cobalt Strike, or similar tooling in authorised client engagements
  • Experience developing, modifying, or extending offensive security tooling, scripts, or payloads
  • Working knowledge of at least one of C, C#, Python, PowerShell, and/or JavaScript, to support offensive security objectives
  • Practical understanding of evasion techniques, endpoint security controls, operational security, and detection-aware tradecraft
  • Strong understanding of networking and web protocols, including TCP/IP, DNS, HTTP, HTTPS, and authentication flows
  • Experience conducting reconnaissance, attack path development, and objective-based testing
  • Excellent written and verbal communication skills, with the ability to explain complex technical issues clearly to technical and non-technical audiences
  • The ability to manage risk during live client engagements and operate within agreed rules of engagement

Nice to have

  • OSEP, OSCE3, CRTO, CRTL, GPEN, GXPN, or equivalent experience
  • Experience delivering threat intelligence driven red team engagements
  • Strong working knowledge of Microsoft Entra ID, Microsoft 365, and hybrid identity attack paths
  • Working knowledge of cloud platforms such as AWS, Azure, or GCP, including identity, privilege escalation, misconfiguration abuse, and cloud-native attack paths
  • Experience with exploit development, reverse engineering, malware analysis, or assembly-level debugging
  • Experience with macOS or Linux endpoint tradecraft
  • Experience with Kubernetes, Docker, CI/CD platforms, DevOps environments, or containerised workloads
  • Experience with physical security
  • Experience with employing modern AI tooling to support offensive engagements
  • Threat intelligence, detection engineering, or incident response experience
  • Experience writing blogs, presenting at industry events, publishing research, or contributing to offensive security tooling
  • Experience leading small teams or technical workstreams during complex offensive security engagements

Salary

Salary range for this role is $110,000 - $150,000 USD

In order to be considered for a position, you must formally apply via careers.kroll.com.

Kroll is committed to creating an inclusive work environment. We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age, or disability.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Consultant, Red Team Operator, Offensive Security @Kroll
All Others
Salary usd 110,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 123,993+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later