Skip to main content
Hexens

Senior Red Team Operator - Social Engineering Focus

RemoteWorldwide
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Hexens is looking for a Senior Red Team Operator with a strong focus on social engineering to join our team. This is a fully remote role with no location restrictions.

Core skills

red teamadversary simulationsocial engineering

Required skills

phishingspear phishingpretextingvishingweb application penetration testingnetwork penetration testingC2 deploymentcontrol bypasspost-exploitation techniques

Optional skills

phishing simulationsecurity awareness training programscryptoweb3smart contract engagementBugcrowdHackerOneOSCP

What you'll do

  • Plan and execute red team and adversary simulation engagements across enterprise, cloud, financial, and web3 environments.
  • Run social engineering campaigns as an initial-access vector: phishing, spear phishing, pretexting, and vishing, including executive-level targeting.
  • Carry engagements through post-access: lateral movement, privilege escalation, persistence, and objective completion.
  • Deploy and manage C2 infrastructure and supporting tooling.
  • Perform security control validation and evasion (firewall, proxy, DLP, EDR).
  • Conduct web application and network penetration testing as part of broader engagements.
  • Write clear, client-ready findings and remediation guidance.
  • Lead engagements independently when needed.

What they require

  • Proven red team / adversary simulation experience across multiple sectors.
  • Hands-on social engineering experience with a demonstrable track record (phishing, pretexting, executive-level testing).
  • Strong web application and network penetration testing skills.
  • Comfort with C2 deployment, control bypass, and standard post-exploitation techniques.
  • Ability to run an engagement solo, from scoping through reporting.
  • Clear written and verbal communication for client-facing deliverables.
  • Big plus if any of the following apply: Experience building phishing simulation and security awareness training programs.
  • Crypto / web3 or smart contract engagement experience.
  • Bug bounty track record (e.g. Bugcrowd, HackerOne).
  • Relevant certifications such as OSCP, CRTO, or OSCE3.
  • Conference talks or published research.

We deliver full-scope adversary simulations against some of the hardest targets out there, spanning banks, crypto and web3 platforms, and industrial environments. We address complex security challenges, replicating real-world attackers to prove impact against the applications and infrastructures our clients rely on.

Unknown
Salary not disclosed