Red Team Security Engineer
Conduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.
About the job
Responsibilities
- Plan and execute red team operations, adversary simulations, and targeted security assessments focused on cloud environments.
- Evaluate cloud infrastructure, identity architectures, CI/CD pipelines, containerized workloads, and cloud-native services.
- Identify and validate attack paths involving IAM misconfigurations, overprivileged roles, secrets exposure, metadata abuse, insecure automation, and weaknesses in cloud service configurations.
- Assess detection and response coverage by exercising logging, alerting, monitoring, and incident response processes with blue team and detection engineering functions.
- Track emerging attacker techniques, cloud exploitation trends, and abuse paths relevant to modern enterprise environments.
- Drive remediation efforts and communicate findings to software and engineering teams.
Requirements
- 5+ years of experience in offensive security, red teaming, penetration testing, and detection validation.
- Familiarity with attacker tactics, techniques, and procedures, including mapping findings to frameworks such as MITRE ATT&CK.
- Ability to write concise, actionable reports and communicate complex technical issues to diverse stakeholders.
- Relevant industry certifications such as OSCP, OSEP, GXPN, GPEN, or cloud security certifications.
Compensation
- CAD $146,000–$190,000 annually.
- Benefits include health, pharmacy, optical and dental care, paid time off, disability coverage, life insurance, and 401(k) contributions, subject to eligibility.
Skills
Cloud Security, Red Teaming, Adversary Emulation, Penetration Testing, Cloud Infrastructure, IAM, CI/CD, Containers, Mitre Att&Ck, Incident Response, Detection Engineering, Oscp, Osep, Gpen
Similar jobs
Security Engineering jobsThe Security Engineer will establish hardware and embedded security practices for connected devices, covering secure boot, firmware, manufacturing, architecture reviews, threat modeling, and lifecycle controls. The role requires at least five years of hardware security, product security design, and hands-on Python and C/C++ development experience.
Develop AI-augmented offensive security tooling, red-team internal AI systems, and automate vulnerability workflows. The role requires at least three years of application or offensive security experience, programming ability, and hands-on experience with LLM security.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.