> Markdown version of [/jobs/ext/1858546-aousc-threat-emulation-readiness-lead-red-team-lead](https://www.wearedevelopers.com/jobs/ext/1858546-aousc-threat-emulation-readiness-lead-red-team-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AOUSC - Threat Emulation & Readiness Lead / Red Team Lead - **Company:** cFocus Software Incorporated - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Cloud Computing, Cyber Security, Computer Telephony Integration, Emulators, Intrusion Detection and Prevention, Red Team (Cyber Security), Mitre Att&ck, Purple Team (Cyber Security) - **Published:** July 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d0c5a6f1087279b6 ## About the Role * 10+ years of offensive security or advanced cybersecurity operations experience. * 5+ years leading red team or adversary emulation operations. * Experience conducting operations against: + enterprise Active Directory environments, + cloud infrastructure, + hybrid identity systems, + and modern endpoint defenses. * Deep understanding of: + adversary tradecraft, + post-exploitation, + detection evasion, + persistence, + and lateral movement techniques. * Experience conducting purple team engagements and readiness exercises. * Strong executive communication and briefing capabilities. Preferred Certifications * OSCP * OSEP * CRTO * GXPN * GPEN * CISSP * MITRE ATT&CK certifications ## Description The Threat Emulation & Readiness Lead will oversee adversary emulation, red team operations, cyber readiness exercises, and threat-informed defense initiatives supporting a federal enterprise cybersecurity program. The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft and MITRE ATT&CK methodologies to assess and improve organizational detection, response, resilience, and operational readiness., * Lead red team operations and adversary emulation exercises. * Design and execute: + threat emulation campaigns, + purple team exercises, + tabletop exercises, + crisis simulations, + and readiness drills. * Emulate advanced threat actor TTPs targeting enterprise, cloud, identity, and hybrid environments. * Develop attack chains aligned to: + MITRE ATT&CK, + intelligence reporting, + and real-world threat actor behaviors. * Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams. * Assess detection and response effectiveness across defensive technologies and operational workflows. * Develop after-action reports, findings, remediation recommendations, and improvement roadmaps. * Lead operational readiness assessments and continuous improvement initiatives. * Brief executives and operational leadership on adversary risk and organizational readiness. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [With AIs wide open - WeAreDevelopers at All Things Open 2025](https://www.wearedevelopers.com/magazine/641-with-ais-wide-open-wearedevelopers-at-all-things-open-2025) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)