- Responsible for simulating real world adversary tactics techniques and procedures TTPs to test the
- organization s ability to prevent and detect cyberattacks
- This role helps identify security gaps in people
- processes and technology by conducting controlled offensive security exercises in an authorized and ethical
- manner
- Conduct authorized red teaming exercises that emulate threat actors targeting enterprise environments cloud identity endpoints applications and networks
- Simulate realistic attack scenarios
- Assess the effectiveness of preventive and detective controls
- Evaluate blue team SOC readiness against simulated attacks
- Identify exploitable weaknesses in systems applications identities and configurations
- Perform controlled exploitation only within approved scope
- Prioritize issues based on attack feasibility and business impact
- Map attack paths that an adversary could use to reach critical assets
- Test the scenarios based on business impact driven objectives
- Work closely with Incident Response Detection Engineering and Platform teams to improve defensive capabilities
- Support purple team exercises to tune detections and strengthen response playbooks
- Improve internal methodologies playbooks and automation for red team operations
- Manager ensures flow of information required between team members happens
- Define the responsibilities of the team members and their interdependencies
- Red Team tools Kali Linux Cobalt Strike Metasploit
- Empire Sliver BloodHound
- Strong understanding of Windows Linux internals AD
- identity attacks
- Scripting Python PowerShell Bash
- Certifications preferred OSCP CRTO CEH GWAPT
- Reporting and risk communication skills
Technology->Infrastructure Security->SOC Operations