We are seeking a Senior Adversary Emulation Engineer to help establish and mature adversary emulation as a repeatable capability within Threat Detection. This role sits at the intersection of ...
We are seeking a Senior Adversary Emulation Engineer to help establish and mature adversary emulation as a repeatable capability within Threat Detection. This role sits at the intersection of ...
$150 - $225/hr
The Adversary Emulation function plays a critical role in proactively improving the firm's security posture by leveraging vulnerability intelligence of real‑world threats, identifying systemic ...
$150 - $225/hr
The Adversary Emulation function plays a critical role in proactively improving the firm's security posture by leveraging vulnerability intelligence of real‑world threats, identifying systemic ...
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Bedford, MA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Bedford, MA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Fairfax, VA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Fairfax, VA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Sentar is seeking a Red Team Adversary Emulation Tech Lead in Quantico, VA! We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations ...
New
Quick apply
Sentar is seeking a Red Team Adversary Emulation Tech Lead in Quantico, VA! We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations ...
New
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
El Segundo, CA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
El Segundo, CA · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Colorado Springs, CO · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Colorado Springs, CO · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Fairborn, OH · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Fairborn, OH · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Huntsville, AL · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Huntsville, AL · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Annapolis Junction, MD · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Annapolis Junction, MD · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
San Antonio, TX · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
San Antonio, TX · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Aberdeen, MD · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Aberdeen, MD · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Honolulu, HI · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Operational Technology (OT) Adversary Emulation Engineer with Security Clearance
Honolulu, HI · On-site
Applying adversary emulation and protocol analysis expertise in support of sponsors. * Leading and developing adversary emulation capabilities like Caldera for OT. * Managing small tasks and projects.
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
Quick apply
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
AOUSC - Threat Emulation & Readiness Lead / Red Team Lead
Washington, DC · On-site
$180 - $240/hr
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
AOUSC - Threat Emulation & Readiness Lead / Red Team Lead
Washington, DC · On-site
$180 - $240/hr
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
Sentar is seeking a Red Team Adversary Emulation Tech Lead in Quantico, VA! We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations ...
New
Sentar is seeking a Red Team Adversary Emulation Tech Lead in Quantico, VA! We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations ...
New
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat ... The Lead will direct realistic adversary simulation activities aligned to nation-state tradecraft ...
Manager, Adversary Intelligence
Charleston, WV · On-site +1
Direct the unified intelligence collection, analysis, and adversary emulation programs, ensuring CTI directly informs and shapes targeted red team campaigns. * Pioneer AI & Agentic Innovation:
Manager, Adversary Intelligence
Charleston, WV · On-site +1
Direct the unified intelligence collection, analysis, and adversary emulation programs, ensuring CTI directly informs and shapes targeted red team campaigns. * Pioneer AI & Agentic Innovation:
Manager, Adversary Intelligence
Austin, TX · On-site
Direct the unified intelligence collection, analysis, and adversary emulation programs, ensuring CTI directly informs and shapes targeted red team campaigns. * Pioneer AI & Agentic Innovation:
Manager, Adversary Intelligence
Austin, TX · On-site
Direct the unified intelligence collection, analysis, and adversary emulation programs, ensuring CTI directly informs and shapes targeted red team campaigns. * Pioneer AI & Agentic Innovation:
Adversary Emulation information
See salary details
$39.66 - $42.70
2% of jobs
$42.70 - $45.74
8% of jobs
$45.74 - $48.78
9% of jobs
$51.43 is the 25th percentile. Wages below this are outliers.
$48.78 - $51.81
6% of jobs
$51.81 - $54.85
11% of jobs
$54.85 - $57.89
7% of jobs
The median wage is $59.75 / hr.
$57.89 - $60.93
9% of jobs
$60.93 - $63.96
16% of jobs
$64.59 is the 75th percentile. Wages above this are outliers.
$63.96 - $67
24% of jobs
$67 - $70.04
4% of jobs
$70.04 - $73.08
2% of jobs
$39
$58
$73
How much do adversary emulation jobs pay per hour?
What is adversary emulation?
What are the key skills and qualifications needed to thrive in adversary emulation?
What are the typical challenges faced by professionals in adversary emulation roles?
What is the difference between Adversary Emulation vs Penetration Tester?
| Aspect | Adversary Emulation | Penetration Tester |
|---|---|---|
| Credentials | Cybersecurity certifications, threat intelligence knowledge | Security certifications, ethical hacking certifications |
| Work Environment | Simulates real-world adversary tactics in controlled environments | Identifies vulnerabilities through controlled testing |
| Industry Usage | Used in threat simulation, red teaming, and advanced security assessments | Used in vulnerability assessments and security audits |
Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.
What cities are hiring for Adversary Emulation jobs?
Cities with the most Adversary Emulation job openings:
What states have the most Adversary Emulation jobs?
States with the most job openings for Adversary Emulation jobs include:
What job categories do people searching Adversary Emulation jobs look for?
The top searched job categories for Adversary Emulation jobs are:

Full-time
Re-posted 6 hours ago
Job description
Job Summary
Comcast Cybersecurity protects Comcast, our customers, our workforce, our partners, and our technology platforms from increasingly sophisticated cyber threats. We are seeking a Senior Adversary Emulation Engineer to help establish and mature adversary emulation as a repeatable capability within Threat Detection. This role sits at the intersection of adversary emulation, threat detection engineering, threat hunting, telemetry validation, and purple team operations. The successful candidate will design and execute controlled, threat-informed emulation scenarios; validate detection coverage across enterprise telemetry sources; generate high-fidelity data for threat hunting; and translate findings into improved detections, hunt content, logging requirements, automations, and actionable reporting. This is a hands-on senior engineering role for someone who can operate safely in complex enterprise environments, partner across cyber and engineering teams, and help Comcast continuously prove and improve its ability to detect real-world adversary behavior.Job Description
Core Responsibilities
-
Help establish and mature Comcast’s adversary emulation capability, including operating model, rules of engagement, approval workflows, success metrics, reporting standards, and repeatable validation processes.
-
Design, plan, and execute controlled adversary emulation scenarios based on current threat intelligence, priority adversary behaviors, emerging attack techniques, and Comcast-relevant risk scenarios.
-
Emulate real-world attacker tactics, techniques, and procedures using frameworks such as MITRE ATT&CK, while maintaining strict safety, deconfliction, and operational controls.
-
Build automation and AI-assisted workflows to streamline emulation planning, evidence collection, test execution, detection validation, reporting, and metrics tracking, with appropriate human review, auditability, and governance.
-
Partner with Threat Detection Engineering to validate detection coverage, alert fidelity, enrichment quality, triage workflows, and detection lifecycle effectiveness.
-
Partner with Threat Hunting to generate high-fidelity telemetry, validate hunt hypotheses, and convert emulation outcomes into reusable hunt content.
-
Identify and document logging gaps, telemetry quality issues, detection blind spots, enrichment deficiencies, and control weaknesses across endpoint, identity, cloud, network, email, SaaS, application, and data-platform sources.
-
Develop repeatable emulation playbooks, test cases, validation workflows, and reporting artifacts that can be reused across priority threats and enterprise environments.
-
Evaluate adversary emulation, breach-and-attack simulation, security validation, and emerging AI-enabled security technologies for use within Comcast’s threat operations environment.
-
Support purple team exercises, threat-informed defense initiatives, after-action reviews, and continuous improvement efforts across cyber operations.
-
Produce clear technical reports and executive-ready summaries that translate emulation results into prioritized recommendations, measurable detection improvements, and risk-informed remediation actions.
-
Collaborate across Cybersecurity, Security Operations, Security Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, Security Engineering, Cloud, Identity, Endpoint, Network, Product, and other technical teams.
Required Qualifications
-
Bachelor’s degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or a related field.
-
7+ years of relevant cybersecurity experience, including hands-on experience in adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations.
-
Strong understanding of adversary tradecraft, attacker lifecycle, MITRE ATT&CK, threat-informed defense, detection engineering, and enterprise security telemetry.
-
Experience safely planning and executing controlled security testing in large or complex enterprise environments, including rules of engagement, approvals, deconfliction, and evidence handling.
-
Proficiency with scripting or automation using Python and at least one additional language or shell such as PowerShell or Bash.
-
Experience applying AI-assisted workflows or agentic automation to cybersecurity use cases with appropriate safety, review, and governance controls.
-
Experience working with SIEM, XDR, EDR, endpoint telemetry, identity logs, cloud logs, network data, email security telemetry, and/or application security telemetry.
-
Ability to write, review, or validate detection and hunting logic using query languages or formats such as SPL, KQL, SQL, Sigma, YARA, or similar.
-
Strong analytical, documentation, and communication skills, including the ability to explain technical findings, detection gaps, and risk implications to technical and non-technical stakeholders.
-
Ability to work independently, exercise sound judgment, and collaborate across multiple teams in a fast-moving enterprise security environment.
Preferred Qualifications
-
Experience helping build or mature an adversary emulation, purple team, detection validation, or security validation function.
-
Experience with adversary emulation and validation tools such as Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, Prelude Operator, or similar platforms.
-
Experience turning emulation results into production detections, hunt content, logging requirements, dashboards, runbooks, and measurable detection coverage improvements.
-
Experience with cloud, SaaS, identity, container, CI/CD, endpoint, network, or large-scale data-platform security testing.
-
Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, CISSP, or equivalent experience.
What Success Looks Like
-
Comcast has a repeatable adversary emulation operating model with clear rules of engagement, test plans, approval workflows, metrics, and reporting.
-
Priority threat scenarios are translated into safe, repeatable emulation exercises mapped to MITRE ATT&CK and Comcast-relevant risk areas.
-
Detection Engineering receives clear validation results that improve detection coverage, alert fidelity, enrichment, and response workflows.
-
Threat Hunting receives high-quality telemetry and validated hypotheses that improve hunt effectiveness.
-
Logging gaps, blind spots, and data quality issues are documented, prioritized, and converted into actionable remediation work.
-
Emulation outcomes are consistently converted into detections, hunts, dashboards, reports, and measurable improvements to Comcast’s cyber defense posture.
-
Cross-functional partners view adversary emulation as a trusted, safe, and valuable capability that improves enterprise readiness against real-world threats.
Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.
Skills:
Cyber Threat Intelligence; Incident Response; Security Engineering; Penetration Testing; Artificial Intelligence Technologies; Security Testing; Cyber Defense
Base pay is one part of the Total Rewards that Comcast provides to compensate and recognize employees for their work. Most sales positions are eligible for a Commission under the terms of an applicable plan, while most non-sales positions are eligible for a Bonus. Additionally, Comcast provides best-in-class Benefits to eligible employees. We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That’s why we provide an array of options, expert guidance and always-on tools, that are personalized to meet the needs of your reality - to help support you physically, financially and emotionally through the big milestones and in your everyday life. Please visit the compensation and benefits summary on our careers site for more details.
Education
Bachelor's Degree
While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.
Relevant Work Experience
10 Years +