Senior Red Team Operator / SME

🏢 CACI International Inc · all CACI International Inc jobs (110)
📍 United States
💰 USD 90,300 - 189,600 / annual
📅 Posted 2026-09-10 · via Himalayas
🏷 Red-Team-Operations,Offensive-Security,Adversary-Emulation,Penetration-Testing,Cybersecurity,Red-Team-Security-Engineer,Red-Team-Specialist,Red-Team-Engineer,Red-Team-Operator,Senior-Penetration-Tester,Red-Team-Expert,Red-Teamer,Red-Team-Consultant,Senior-Offensive-Security-Specialist,Red-Team-Lead
Apply on original site ↗

Job Title: Senior Red Team Operator / SMEJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: Public TrustEmployee Type: RegularPercentage of Travel Required: Up to 25%Type of Travel: Continental US* * * The Opportunity:

CACI is seeking a Senior Red Team Operator and subject-matter expert to lead assigned adversary-emulation engagements. This role translates threat behavior and customer objectives into safe, realistic campaigns; directs operator execution; maintains operational security; and ensures evidence, reports, out-briefs, and recommendations are technically sound. The role leads individual engagements. This SME role includes cradle‑to‑grave engagement ownership, ensuring operational safety, evidence integrity, and measurable defensive improvement outcomes.

This position will provide continuous technical assessment support for full‑time, proactive testing of externally and internally visible federal cyber assets. This expands federal visibility by conducting continual assessments of .gov domains, subdomains, and internet‑facing assets to uncover unknown exposures, validate vulnerabilities, and provide agencies with actionable remediation guidance. This role supports the Continuous Diagnostics and Mitigation (CDM) Program’s mission to safeguard and secure cyberspace in an environment where the threat of cyber-attack is continuously growing and evolving and is responsible for enhancing the security, resilience, and reliability of the Nation’s cyber and communications infrastructure. The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks.
Responsibilities:

- Lead assigned red-team engagements from scenario design and rules-of-engagement planning through infrastructure build, execution, deconfliction, reporting, and customer out-briefing.

- Develop multi-vector campaigns aligned to MITRE ATT&CK and modern APT profiles, integrating identity-layer exploitation, cloud lateral movement, and infrastructure pivoting.

- Design and oversee adversary infrastructure, redirectors, command-and-control channels, payload-delivery methods, operator access, logging, and teardown procedures.

- Construct secure cloud-based attack infrastructure and teardown workflows consistent with modern adversary tradecraft.

- Lead hands-on execution of advanced identity, endpoint, network, web, cloud, phishing, defense-evasion, persistence, and exfiltration-simulation techniques when authorized.

- Mentor junior operators, review tradecraft and scripts, enforce OPSEC and safety controls, and make real-time technical decisions during operations.

- Review payload/tooling for evasion capabilities (EDR/AV bypass and living-off-the-land techniques) within authorized scope.

- Coordinate with stakeholders to validate detection and response, develop hand-crafted purple-team scenarios, and translate observations into measurable defensive improvements.

- Own technical quality for operator logs, attack narratives, evidence, mitigation recommendations, assessment reports, and customer out-briefs.

- Escalate material risks, scope changes, operational impacts, and cross-engagement issues to the Technical Lead.

Qualifications:

Required:

- U.S. citizenship is required.

- The selected candidate must meet eligibility requirements for access to sensitive information and be able to obtain a Public Trust fitness determination (High Risk) .

- Ability to work in customer-provided remote environments, use customer-approved tools, and comply with rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria.

-
Five or more years of hands-on red-team , defensive-adversary-emulation, or advanced penetration-testing experience, including a

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you