Government Careers
  • Red-Team / Adversarial Security Lead

  • Steampunk.com
  • Mc Lean, Virginia 22107 United States View Map

Summary

OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls.The Red-Team / Adversarial Security Lead will analyze and document assessment results, communicate identified risks and vulnerabilities, recommend appropriate remediation actions, and support pass/fail safety-gate determinations based on established security criteria. This role requires strong technical cybersecurity experience across operating systems, infrastructure, and cloud environments.ContributionsDevelop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environmentsDevelop and execute red-team and adversarial security assessment plans based on defined objectives and security criteriaPerform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack pathsEvaluate the effectiveness of existing security controls through technical testing and adversarial techniquesAnalyze vulnerabilities and assessment findings to determine exploitability, potential impact, and associated security riskConduct security assessments across diverse operating systems and enterprise technology environmentsAssess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actionsEvaluate assessment results against established security and safety-gate criteria and support pass/fail determinationsCommunicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholdersCollaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risksValidate remediation of identified vulnerabilities and security weaknesses through follow-up testingMaintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practicesSupport the development and refinement of red-team methodologies, assessment procedures, and security testing criteriaQualificationsRequired:Ability to obtain and maintain a government security clearanceBachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplinesExperience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risksExperience planning and executing technical security assessments, penetration tests, or adversarial security assessmentsDeep technical experience across operating systems and associated security concepts, including environments such as Windows and LinuxExperience identifying, validating, and assessing vulnerabilities and potential attack pathsKnowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controlsExperience with cloud architecture and security concepts across AWS, Azure, and/or GCPAbility to analyze technical security findings and evaluate their potential impact and riskExperience documenting technical findings, supporting evidence, and remediation recommendationsStrong analytical, problem-solving, communication, and collaboration skillsPreferred:Experience conducting red-team assessments across complex enterprise environmentsExperience with multiple cloud platforms, including AWS, Azure, and GCPExperience with adversary emulation and penetration testing tools and methodologiesKnowledge of MITRE ATT&CK and related adversarial tactics, techniques, and proceduresExperience evaluating security assessment results against defined acceptance, release, or safety-gate criteriaExperience working within federal government or other highly regulated environmentsOffensive Security Certified Professional (OSCP) or comparable hands‑on offensive security/penetration testing certification strongly preferred; comparable certifications may include GIAC Penetration Tester (GPEN), Practical Network Penetration Tester (PNPT), Hack The Box Certified Penetration Testing Specialist (HTB CPTS), or equivalentAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $85,000 to $170,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here.Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.#J-18808-Ljbffr

Job Description

OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls.The Red-Team / Adversarial Security Lead will analyze and document assessment results, communicate identified risks and vulnerabilities, recommend appropriate remediation actions, and support pass/fail safety-gate determinations based on established security criteria. This role requires strong technical cybersecurity experience across operating systems, infrastructure, and cloud environments.ContributionsDevelop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environmentsDevelop and execute red-team and adversarial security assessment plans based on defined objectives and security criteriaPerform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack pathsEvaluate the effectiveness of existing security controls through technical testing and adversarial techniquesAnalyze vulnerabilities and assessment findings to determine exploitability, potential impact, and associated security riskConduct security assessments across diverse operating systems and enterprise technology environmentsAssess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actionsEvaluate assessment results against established security and safety-gate criteria and support pass/fail determinationsCommunicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholdersCollaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risksValidate remediation of identified vulnerabilities and security weaknesses through follow-up testingMaintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practicesSupport the development and refinement of red-team methodologies, assessment procedures, and security testing criteriaQualificationsRequired:Ability to obtain and maintain a government security clearanceBachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplinesExperience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risksExperience planning and executing technical security assessments, penetration tests, or adversarial security assessmentsDeep technical experience across operating systems and associated security concepts, including environments such as Windows and LinuxExperience identifying, validating, and assessing vulnerabilities and potential attack pathsKnowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controlsExperience with cloud architecture and security concepts across AWS, Azure, and/or GCPAbility to analyze technical security findings and evaluate their potential impact and riskExperience documenting technical findings, supporting evidence, and remediation recommendationsStrong analytical, problem-solving, communication, and collaboration skillsPreferred:Experience conducting red-team assessments across complex enterprise environmentsExperience with multiple cloud platforms, including AWS, Azure, and GCPExperience with adversary emulation and penetration testing tools and methodologiesKnowledge of MITRE ATT&CK and related adversarial tactics, techniques, and proceduresExperience evaluating security assessment results against defined acceptance, release, or safety-gate criteriaExperience working within federal government or other highly regulated environmentsOffensive Security Certified Professional (OSCP) or comparable hands‑on offensive security/penetration testing certification strongly preferred; comparable certifications may include GIAC Penetration Tester (GPEN), Practical Network Penetration Tester (PNPT), Hack The Box Certified Penetration Testing Specialist (HTB CPTS), or equivalentAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $85,000 to $170,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here.Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.#J-18808-Ljbffr

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS