[Remote] Red Team Operator - Assistant Director Job Details | EY

Other Jobs To Apply

Note: The job is a remote job and is open to candidates in USA. EY is a global leader in assurance, consulting, tax, strategy and transactions, committed to building a better working world. The Red Team Operator will emulate advanced threat actors through offensive security testing and provide actionable recommendations to improve defenses, while collaborating with teams to enhance overall security posture.


Responsibilities

  • Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact
  • Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures
  • Perform social engineering (e.g., phishing) as part of integrated engagements
  • Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks
  • Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience
  • Produce high-quality deliverables: detailed technical reports, executive summaries, risk assessments, and remediation recommendations
  • Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts)
  • Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development

Skills

  • 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security
  • Demonstrated experience executing red team or advanced penetration testing engagements
  • Relevant certifications including OSCP, CPTS (or equivalents such as GPEN, CRTO, OSEP, OSCE)
  • Ability to work effectively in a fully remote environment
  • Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, BloodHound, Nmap, Burp Suite, and others)
  • Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols
  • Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling
  • Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders
  • Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence
  • Independently research and stay knowledgeable of Threat Actor TTP's and how they may be leveraged
  • Excellent analytical, problem-solving, and technical writing skills
  • Strong teamwork, independence, and communication skills
  • Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU)
  • Prior consulting or client-facing experience (where applicable)
  • Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering
  • Creation of, or contributions to open-source tools or projects, CTF participation, or public research/blogging

Benefits

  • Comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business
  • Medical and dental coverage
  • Pension and 401(k) plans
  • A wide range of paid time off options
  • Team-led and leader-enabled hybrid model (most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year)
  • Flexible vacation policy (decide how much vacation time you need based on your own personal circumstances)
  • Time off for designated EY Paid Holidays
  • Winter/Summer breaks
  • Personal/Family Care
  • Other leaves of absence when needed to support your physical, financial, and emotional well-being

Company Overview

  • EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets. It was founded in 1989, and is headquartered in London, England, GBR, with a workforce of 10001+ employees. Its website is http://www.ey.com.

  • Company H1B Sponsorship

  • EY has a track record of offering H1B sponsorships, with 3 in 2026, 3 in 2025, 16 in 2023. Please note that this does not guarantee sponsorship for this specific role.

  • Back to blog