> Markdown version of [/jobs/ext/1240716-senior-threat-emulation-engineer](https://www.wearedevelopers.com/jobs/ext/1240716-senior-threat-emulation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat Emulation Engineer - **Company:** Interactive Resources LLC - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Emulators, Intrusion Detection and Prevention, Web Applications, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=51d39f188b167e41 ## About the Role * 5+ years in security with real offensive depth: penetration testing, adversary emulation, web app exploitation, vulnerability research * You've worked from threat intel - taking actual actor TTPs and reproducing them, not just running Cobalt Strike defaults * You can read an environment, find the weak points, and chain them * You can explain your kill chain to a non-technical audience without losing them * Degree in a related field or the experience that makes it irrelevant Strongly preferred: * OSCP, OSWE, OSEP, or equivalent - certs from the practical, hands-on-keyboard side * Large enterprise experience, especially regulated environments If your background is SOC, detection engineering, or vuln management and you're looking to move offensive - this isn't the transition role. We need someone already doing this work. ## Description You'll run adversary emulation campaigns against enterprise infrastructure - replicating the tradecraft of real threat actors, not just running scanners and handing over a report. Pen tests, web app assessments, threat modeling, exploit research against our own stack. You find the path in before someone else does. When you break something, you'll write it up so it actually gets fixed: what you did, why it worked, what it means in business terms, and how to close it. You'll work directly with detection and response teams so your findings sharpen their rules - your attacks make the defense better, but you're not the one writing signatures. You'll also mentor junior offensive talent and stay current on emerging tradecraft, because the job is emulating what attackers do now, not what they did three years ago. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)