FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Offensive Security Consultant – Red Team, Adversary Simulation
Protiviti. Plan and execute red team, purple team, and threat-led penetration testing (TLPT) engagements emulating real-world threat actors across on-premises, cloud, identity, and SaaS environments .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in offensive security, including red teaming and penetration testing, with a strong focus on developing custom tooling and improving detection and response capabilities. Proficient in producing actionable reports and leading engagements while fostering collaboration with client security teams.
Highest-signal resume keywords
Red Team EngagementsPenetration TestingC2 Frameworks (Mythic, Sliver, Cobalt Strike)Cloud Security (AWS, Azure, GCP)Offensive Security Certifications (OSCP, OSWE)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Offensive SecurityPenetration TestingThreat IntelligenceActive Directory AttacksVulnerability DiscoveryExploitationPrivilege EscalationWeb Application TestingAPI TestingMobile Application Testing
Soft Skills
CommunicationCoachingRelationship BuildingTeam CollaborationReport Writing
Tools & Technologies
Burp SuiteCI/CD PipelinesAI-Assisted ToolingAutomation ToolsEDR Evasion Techniques
Certifications & Qualifications
OSCPOSEPOSWEOSEDCRTOCRTLGXPNGPENBSCPCloud Security Certifications
Industry Keywords
MITRE ATT&CKTTPsRansomware SimulationsSaaS EnvironmentsIdentity Platforms
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformPythonRustGo
About the role
Key responsibilities & impact- Plan and execute red team, purple team, and threat-led penetration testing (TLPT) engagements emulating real-world threat actors across on-premises, cloud, identity, and SaaS environments
- Test attack surfaces including AI/LLM-powered applications, agentic workflows, and identity platforms
- Use and build AI-assisted tooling and automation during operations
- Develop new tooling, design novel attacks, and contribute to a testing lab for adversary simulation scenarios
- Lead engagements from scoping through executive readout
- Build lasting relationships with client security teams and explain exploitation paths and remediation priorities
- Partner with defenders to improve detections, response, and measurable security outcomes
- Coach and develop teammates by sharing knowledge and supporting training
- Contribute ideas for new services and help shape the future of the practice
- Produce clear, client-ready reports and presentations
- Work with organizations across industries, technologies, and environments
Requirements
What you’ll need- Bachelor's degree in a relevant discipline (e.g., CS, CE, IS, MIS, EE) or equivalent hands-on experience
- 5+ years of hands-on offensive security experience in red teaming, penetration testing, or adversary simulation, in consulting or in-house
- Experience running red team engagements that emulate real-world threat actors, with strong command of TTPs and MITRE ATT&CK
- Ability to partner with SOC and detection engineering teams to improve detection and response
- Experience designing threat intelligence-driven scenarios, including ransomware simulations
- Hands-on experience attacking Active Directory, cloud and identity platforms (AWS, Azure, GCP, Entra ID, Okta), and CI/CD pipelines
- Proficiency with C2 frameworks such as Mythic, Sliver, and Cobalt Strike
- Ability to build custom tooling in C#, Go, Rust, Python, or PowerShell
- Strong operational security (OpSec) and experience evading EDR and other monitoring tools
- Experience performing internal and external network penetration tests, including vulnerability discovery, exploitation, and privilege escalation
- Experience testing web applications, APIs, and mobile apps, with knowledge of the OWASP Top 10 and tools such as Burp Suite
- Ability to manually validate findings and chain issues into real attack paths
- Understanding of attacks against LLM-enabled applications and agents, including prompt injection, data leakage, and tool abuse
- Ability to produce clear, actionable reports and communicate with technical teams and executives
- Certifications such as OSCP, OSEP, OSWE, OSED, CRTO/CRTL, GXPN, GPEN, BSCP, or comparable SANS 600/700-level coursework are a plus
- Cloud security certifications such as AWS Certified Security – Specialty, Microsoft AZ-500, Google Professional Cloud Security Engineer, or CCSK are a plus
- Successful completion of a background check is required as a condition of employment
Benefits
Comp & perks- Annual bonus plan providing eligible employees additional cash and/or discretionary stock compensation opportunities, with a 12% bonus target opportunity
- Medical, dental, and vision coverages
- FSA and HSA healthcare accounts
- Life and accident insurance
- Adoption and fertility assistance
- Paid parental leave up to 10 weeks
- Short- and long-term disability
- 401(k) savings and investment plan with employer match of 50% on the first 6% of contributions
- Choice Time Off (CTO) for vacation, personal needs, and sick time; new hires receive up to 20 days per calendar year
- Up to 11 paid holidays each calendar year
- Hybrid work model with remote work and purposeful in-person time
- Support to develop tooling, research new techniques, and turn ideas into new services
- Support for presenting at local, national, and international security conferences