Senior Threat Emulation Engineer

Interactive Resources LLC
Philadelphia, PA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$150,000.0 - $165,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Emulators Intrusion Detection and Prevention Web Applications Vulnerability Analysis

Job description

You’ll run adversary emulation campaigns against enterprise infrastructure - replicating the tradecraft of real threat actors, not just running scanners and handing over a report. Pen tests, web app assessments, threat modeling, exploit research against our own stack. You find the path in before someone else does.

When you break something, you’ll write it up so it actually gets fixed: what you did, why it worked, what it means in business terms, and how to close it. You’ll work directly with detection and response teams so your findings sharpen their rules - your attacks make the defense better, but you’re not the one writing signatures.

You’ll also mentor junior offensive talent and stay current on emerging tradecraft, because the job is emulating what attackers do now, not what they did three years ago.

Requirements

  • 5+ years in security with real offensive depth: penetration testing, adversary emulation, web app exploitation, vulnerability research
  • You’ve worked from threat intel - taking actual actor TTPs and reproducing them, not just running Cobalt Strike defaults
  • You can read an environment, find the weak points, and chain them
  • You can explain your kill chain to a non-technical audience without losing them
  • Degree in a related field or the experience that makes it irrelevant

Strongly preferred:

  • OSCP, OSWE, OSEP, or equivalent - certs from the practical, hands-on-keyboard side
  • Large enterprise experience, especially regulated environments

If your background is SOC, detection engineering, or vuln management and you’re looking to move offensive - this isn’t the transition role. We need someone already doing this work.

Benefits & conditions

Pulled from the full job description

  • Parental leave
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off
  • Vision insurance, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Parental leave
  • Relocation assistance
  • Retirement plan
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

58 sec

Navigating limitations of local Cosmos DB emulators

Radu Vunvulea Radu Vunvulea · WWC 2022

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:49 min

Testing with emulators, simulators, and real devices

Milica Aleksic Milica Aleksic · LIVE

Videos

See all

Related articles

See all