Skip to main content
SIXGEN

Senior Red & Purple Team Operator

RemoteUnited States onlyArchived
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Highly experienced and self-sufficient Senior Red & Purple Team Operator with 7+ years of offensive cybersecurity experience. Must be able to independently plan, execute, and document advanced offensive cybersecurity assessments against enterprise systems, networks, applications, cloud environments, and security controls. Ability to be Cleared is required.

Core skills

penetration testingRed Team operationsadversary emulation

Required skills

AWSAzureWindowsLinuxActive Directorynetworkingauthentication protocolsMITRE ATT&CK

Optional skills

OSCPOSEPOSWEGPENGXPNCRTOCRTO IIcustom offensive security tooling

What you'll do

  • Independently plan and execute end-to-end Red Team engagements simulating sophisticated real-world adversaries and advanced persistent threats (APTs).
  • Develop realistic attack scenarios based on organizational risk, threat intelligence, and adversary tactics, techniques, and procedures (TTPs).
  • Conduct reconnaissance, initial access, exploitation, privilege escalation, credential access, persistence, defense evasion, lateral movement, command and control, and other authorized adversary activities.
  • Evaluate the organization’s ability to prevent, detect, investigate, respond to, and recover from advanced cyberattacks.
  • Identify weaknesses across people, processes, technologies, security controls, and operational procedures.
  • Maintain operational security throughout Red Team engagements and ensure testing remains within established Rules of Engagement (ROE).
  • Plan and conduct collaborative Purple Team exercises with SOC, Threat Hunting, Incident Response, Detection Engineering, and other security personnel.
  • Execute specific adversary TTPs to evaluate existing detection and response capabilities.
  • Validate alerts, telemetry, detection logic, and investigative procedures.
  • Identify visibility, telemetry, detection, and response gaps and provide actionable recommendations for improvement.
  • Assist defensive teams in translating offensive techniques into new or improved detections and threat-hunting opportunities.
  • Conduct iterative testing to validate that newly implemented detections and mitigations operate as intended.
  • Assess organizational response capabilities and recommend targeted training or operational improvements.
  • Assist in conducting comprehensive penetration testing of enterprise networks, systems, applications, cloud environments, and security infrastructure.
  • Simulate realistic attack paths to determine whether identified vulnerabilities can be exploited and chained to achieve meaningful objectives.
  • Perform manual testing and validation rather than relying exclusively on automated vulnerability scanning.
  • Evaluate technical vulnerabilities in the context of actual exploitability and organizational impact.
  • Develop clear, actionable remediation recommendations for identified vulnerabilities and attack paths.
  • Utilize appropriate AI-enabled penetration testing technologies to supplement manual testing and improve assessment efficiency.
  • Independently design, deploy, configure, secure, and maintain offensive security infrastructure required to conduct authorized operations.
  • Build cloud-based Red Team infrastructure in environments such as AWS.
  • Configure and maintain redirectors, command-and-control infrastructure, payload delivery infrastructure, testing systems, and supporting operational services as required.
  • Implement appropriate operational security controls to protect assessment infrastructure and authorized activities.
  • Tear down and sanitize temporary infrastructure following completion of engagements.
  • Troubleshoot attack infrastructure and tooling independently during active operations.
  • Translate threat intelligence into realistic adversary emulation plans.
  • Emulate known threat actors and advanced adversary behaviors using the MITRE ATT&CK framework.
  • Develop custom attack scenarios based on relevant TTPs rather than relying solely on predefined penetration testing procedures.
  • Evaluate security controls against realistic attack chains and determine opportunities for bypass or evasion.
  • Collaborate with Threat Intelligence and Threat Hunting personnel to improve adversary-focused defensive capabilities.
  • Maintain detailed records of testing activities, timestamps, commands, screenshots, artifacts, affected systems, and supporting evidence throughout each engagement.
  • Maintain appropriate evidence integrity and handling practices.
  • Document attack paths and map offensive activities to relevant MITRE ATT&CK techniques.
  • Independently produce comprehensive assessment reports describing: Scope and methodology, Attack narrative and timeline, Tactics, techniques, and procedures used, Vulnerabilities and security weaknesses identified, Evidence supporting findings, Risk and potential business impact, Detection and response observations, Prioritized remediation recommendations.
  • Produce executive-level summaries that clearly communicate risk and assessment outcomes to non-technical leadership.
  • Conduct technical and executive out-briefings following completion of engagements.

What they require

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent professional experience.
  • 7+ years of offensive cybersecurity experience involving penetration testing, Red Team operations, adversary emulation, or comparable security assessment activities.
  • Demonstrated ability to independently plan and execute Red Team and penetration testing engagements from initial scoping through final reporting.
  • Hands-on experience conducting advanced network, Active Directory, identity, endpoint, application, and cloud attacks.
  • Strong understanding of the MITRE ATT&CK framework and adversary tactics, techniques, and procedures.
  • Experience developing and operating offensive security infrastructure in AWS, Azure, or comparable cloud environments.
  • Experience with command-and-control frameworks and offensive security tooling.
  • Strong understanding of Windows, Linux, Active Directory, networking, authentication protocols, and enterprise security architecture.
  • Experience performing manual exploitation, privilege escalation, lateral movement, credential attacks, persistence, and defense evasion.
  • Demonstrated experience collecting and documenting technical evidence during offensive security engagements.
  • Strong technical writing skills with demonstrated experience producing professional penetration testing or Red Team reports.
  • Ability to work independently with minimal technical oversight while maintaining strict adherence to authorized scope and Rules of Engagement.
  • Ability to be Cleared
  • Preferred: Experience conducting Red Team or adversary emulation exercises within federal government environments.
  • Preferred: Experience working directly with SOC, Threat Hunting, Incident Response, and Detection Engineering teams.
  • Preferred: Experience developing custom offensive security tooling, scripts, payloads, or automation.
  • Preferred: Experience with cloud-native offensive security testing across AWS and/or Azure environments.
  • Preferred: Experience leveraging AI-enabled tools to augment reconnaissance, penetration testing, analysis, and reporting activities.

Benefits

  • Employer-paid health insurance premiums (medical, dental, vision) for you and your family
  • Employer-paid short/long term disability insurance and basic life/AD&D insurance
  • 401K with a 4% employer contribution
  • Professional development reimbursement options available (training, certification, education, etc.)
  • Flexible and remote work policies for most positions
  • Flexible PTO and holiday schedule

SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.

Cybersecurity
Salary not disclosed