1

Adversary Emulation Jobs in Alabama (NOW HIRING)

The ideal candidate will have experience conducting adversary emulation, penetration testing, and red team operations against enterprise, aerospace, and mission-critical environments. This role ...

Adversary Emulation information

What is adversary emulation?

Adversary emulation is a cybersecurity practice in which security professionals simulate real-world cyber attackers, or adversaries, to test and improve an organization’s defenses. By mimicking the tactics, techniques, and procedures (TTPs) used by actual threat actors, adversary emulation helps organizations identify vulnerabilities, assess detection and response capabilities, and strengthen their overall security posture. These exercises are often based on threat intelligence and frameworks like MITRE ATT&CK to ensure realistic scenarios.

What are the key skills and qualifications needed to thrive in adversary emulation?

To thrive in Adversary Emulation, you need deep knowledge of cybersecurity, attack methodologies, and penetration testing, often supported by degrees in computer science or related certifications such as OSCP or CISSP. Familiarity with tools like Cobalt Strike, Metasploit, and SIEM platforms is commonly required. Analytical thinking, creativity, and strong communication skills are essential to mimic real-world threats and report findings clearly. These skills are crucial for accurately simulating adversary tactics, identifying security gaps, and helping organizations strengthen their cyber defenses.

What are the typical challenges faced by professionals in adversary emulation roles?

Adversary Emulation specialists often encounter the challenge of staying ahead of rapidly evolving attack techniques and threat actor behaviors. They must continuously update their knowledge and adapt their methodologies to realistically mimic current adversaries, which requires ongoing research and collaboration with threat intelligence teams. Additionally, balancing the realism of simulated attacks with organizational risk tolerance and ensuring minimal disruption during assessments can be complex. Working closely with security operations, incident response, and IT teams is essential to maximize the value of each engagement and provide actionable insights for improving defenses.

What is the difference between Adversary Emulation vs Penetration Tester?

AspectAdversary EmulationPenetration Tester
CredentialsCybersecurity certifications, threat intelligence knowledgeSecurity certifications, ethical hacking certifications
Work EnvironmentSimulates real-world adversary tactics in controlled environmentsIdentifies vulnerabilities through controlled testing
Industry UsageUsed in threat simulation, red teaming, and advanced security assessmentsUsed in vulnerability assessments and security audits

Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.

What are popular job titles related to Adversary Emulation jobs in Alabama?

For Adversary Emulation jobs in Alabama, the most frequently searched job titles are:

What job categories do people searching Adversary Emulation jobs in Alabama look for?

The top searched job categories for Adversary Emulation jobs in Alabama are:

Infographic showing various Adversary Emulation job openings in Alabama as of August 2026, with employment types broken down into 93% Full Time, 5% Part Time, 1% Contract, and 1% Nights. Highlights an 99% Physical, and 1% Remote job distribution.

AI-Focused Red Team Operator

Millennium Corporation

Huntsville, AL • On-site

Full-time

Posted 16 days ago


Job description

Overview

Millennium is proud to be part of the Markon enterprise, a network of specialized organizations united in support of critical national security missions. This partnership strengthens our ability to deliver results by expanding our technical depth, operational reach, and access to a broader bench of proven experts, ensuring our customers continue to receive best-in-class cybersecurity support.Since 2004, Millennium has operated at the forefront of cybersecurity. Our elite team of over 300 professionals brings an unmatched record of performance across Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. As home to the largest contingent of contracted Red Team operators supporting the Department of Defense, Millennium delivers unparalleled threat intelligence and battle-tested expertise to both DoD and federal civilian customers.

What We Believe

Millennium is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state, or local law.

Responsibilities

Millennium is hiring a skilled AI-Focused Red Team Operator to support advanced cyber operations for a government customer in the Washington, DC area (Position contingent upon contract award/additional funding). The candidate must have an active Top Secret clearance. 

The ideal candidate possesses extensive experience in offensive and defensive cybersecurity operations and is passionate about applying artificial intelligence to improve cyber mission effectiveness. Th candidate will get an opportunity to work at the forefront of AI-enabled cyber operations, combining traditional penetration testing, adversary emulation, threat hunting, and detection engineering with emerging AI technologies.

  • Conduct authorized penetration testing, adversary emulation, and Red Team assessments against enterprise, cloud, and AI-enabled environments.
  • Perform Blue Team activities including threat hunting, detection engineering, incident response support, and defensive security assessments.
  • Evaluate AI and machine learning systems for security weaknesses throughout the model lifecycle.
  • Assess Large Language Model (LLM) applications against emerging AI threats and industry frameworks such as the OWASP LLM Top 10.
  • Identify vulnerabilities involving prompt injection, retrieval-augmented generation (RAG), model manipulation, indirect prompt injection, tool abuse, data poisoning, and model extraction techniques.
  • Develop offensive tradecraft to evaluate AI-enabled systems while ensuring responsible and authorized testing practices.
  • Design and implement defensive controls including guardrails, monitoring, content filtering, evaluation frameworks, and AI-specific security controls.
  • Leverage AI technologies to improve offensive and defensive cyber operations through automation, large-scale reconnaissance, code analysis, detection engineering, report generation, and security analytics.
  • Collaborate with cybersecurity engineers, analysts, and stakeholders to improve organizational resilience against emerging AI-enabled threats.
  • Produce high-quality technical documentation, assessment reports, and executive briefings.

AI Engineering & Automation

Successful candidates should demonstrate experience building or integrating AI-assisted security workflows, including:

  • Agentic workflows for security operations and incident response
  • Automated alert triage and enrichment
  • Detection tuning and threat hunting using AI
  • AI-assisted report generation and documentation
  • Secure integration of LLMs into cybersecurity workflows
  • Evaluation and testing of security-focused language models
Qualifications
  • Active Top Secret security clearance.
  • Bachelor's and total 5+ years experience. Additonal 4+ YoE would be considered in lieu of degree.
  • Experience conducting Red Team operations, penetration testing, or adversary emulation.
  • Design, develop, and evaluate AI agents capable of automating routine penetration testing tasks within authorized environments, employing strict operational guardrails, human oversight, and defined rules of engagement to ensure safe, controlled, and repeatable security assessments.
  • Experience supporting Blue Team operations including threat hunting, detection engineering, incident response, or security operations.
  • Strong understanding of enterprise networking, operating systems, identity management, cloud technologies, and modern attack methodologies.
  • Experience developing scripts or automation using Python, PowerShell, Bash, or similar languages.
  • Familiarity with AI/ML concepts, Large Language Models, and AI security risks.
  • Strong written and verbal communication skills.
Preferred Qualifications: Experience with one or more of the following:
  • AI Red Teaming
  • Prompt injection testing
  • Retrieval-Augmented Generation (RAG) security
  • Adversarial machine learning
  • Model evasion and data poisoning
  • AI governance and secure model deployment
  • MITRE ATT&CK
  • MITRE ATLAS
  • OWASP LLM Top 10
  • NIST AI Risk Management Framework (AI RMF)

One or more of the following certifications are desirable:

  • CISSP or CEH or OSCP or GPEN or GCIH or PNPT or Security+ or AI Security coursework or certifications (e.g., AI Security Fundamentals, LLM Red Teaming, or equivalent training)
  •  
Business Development

Assist with Business Development activities as required to support Millennium's strategic business objectives, which may include but not limited to participation in technical interviews, creation of technical documentation, general proposal writing support and proposal color reviews.

Physical Requirements
  • Must be comfortable with prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 10-15 pounds at a time.
COMPENSATION:

$130,000-$133,000

The salary range provided for this position is intended as a general guideline and does not guarantee a specific salary or compensation amount. Final compensation will be determined based on a variety of factors, including, relevant education, experience, knowledge, skills, and abilities.

Employment Type: OTHER