AOUSC - Threat Emulation & Readiness Lead / Red Team Lead
cFocus Software Incorporated
Washington, DC, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Active Directory
Cloud Computing
Cyber Security
Computer Telephony Integration
Emulators
Intrusion Detection and Prevention
Red Team (Cyber Security)
Mitre Att&ck
Purple Team (Cyber Security)
Job description
The Threat Emulation & Readiness Lead will oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise cybersecurity program. The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft and MITRE ATT&CK methodologies to assess and improve organizational detection, response, resilience, and operational readiness., * Lead red team operations and adversary emulation exercises.
- Design and execute:
- threat emulation campaigns,
- purple team exercises,
- tabletop exercises,
- crisis simulations,
- and readiness drills.
- Emulate advanced threat actor TTPs targeting enterprise, cloud, identity, and hybrid environments.
- Develop attack chains aligned to:
- MITRE ATT&CK,
- intelligence reporting,
- and real-world threat actor behaviors.
- Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams.
- Assess detection and response effectiveness across defensive technologies and operational workflows.
- Develop after-action reports, findings, remediation recommendations, and improvement roadmaps.
- Lead operational readiness assessments and continuous improvement initiatives.
- Brief executives and operational leadership on adversary risk and organizational readiness.
Requirements
- 10+ years of offensive security or advanced cybersecurity operations experience.
- 5+ years leading red team or adversary emulation operations.
- Experience conducting operations against:
- enterprise Active Directory environments,
- cloud infrastructure,
- hybrid identity systems,
- and modern endpoint defenses.
- Deep understanding of:
- adversary tradecraft,
- post-exploitation,
- detection evasion,
- persistence,
- and lateral movement techniques.
- Experience conducting purple team engagements and readiness exercises.
- Strong executive communication and briefing capabilities.
Preferred Certifications
- OSCP
- OSEP
- CRTO
- GXPN
- GPEN
- CISSP
- MITRE ATT&CK certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
CH
Chris Heilmann
With AIs wide open - WeAreDevelopers at All Things Open 2025
11 months ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago