AOUSC - Threat Emulation & Readiness Lead / Red Team Lead

cFocus Software Incorporated
Washington, DC, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Cloud Computing Cyber Security Computer Telephony Integration Emulators Intrusion Detection and Prevention Red Team (Cyber Security) Mitre Att&ck Purple Team (Cyber Security)

Job description

The Threat Emulation & Readiness Lead will oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise cybersecurity program. The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft and MITRE ATT&CK methodologies to assess and improve organizational detection, response, resilience, and operational readiness., * Lead red team operations and adversary emulation exercises.

  • Design and execute:
  • threat emulation campaigns,
  • purple team exercises,
  • tabletop exercises,
  • crisis simulations,
  • and readiness drills.
  • Emulate advanced threat actor TTPs targeting enterprise, cloud, identity, and hybrid environments.
  • Develop attack chains aligned to:
  • MITRE ATT&CK,
  • intelligence reporting,
  • and real-world threat actor behaviors.
  • Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams.
  • Assess detection and response effectiveness across defensive technologies and operational workflows.
  • Develop after-action reports, findings, remediation recommendations, and improvement roadmaps.
  • Lead operational readiness assessments and continuous improvement initiatives.
  • Brief executives and operational leadership on adversary risk and organizational readiness.

Requirements

  • 10+ years of offensive security or advanced cybersecurity operations experience.
  • 5+ years leading red team or adversary emulation operations.
  • Experience conducting operations against:
  • enterprise Active Directory environments,
  • cloud infrastructure,
  • hybrid identity systems,
  • and modern endpoint defenses.
  • Deep understanding of:
  • adversary tradecraft,
  • post-exploitation,
  • detection evasion,
  • persistence,
  • and lateral movement techniques.
  • Experience conducting purple team engagements and readiness exercises.
  • Strong executive communication and briefing capabilities.

Preferred Certifications

  • OSCP
  • OSEP
  • CRTO
  • GXPN
  • GPEN
  • CISSP
  • MITRE ATT&CK certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

58 sec

Navigating limitations of local Cosmos DB emulators

Radu Vunvulea Radu Vunvulea · World Congress 2022

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

Videos

See all

Related articles

See all