1

Adversary Emulation Jobs in Colorado (NOW HIRING)

Red Team Operator

Colorado Springs, CO · On-site

$155K - $180K/yr

Unlike a standard penetration testing role, this position focuses heavily on high-fidelity nation-state adversary emulation, advanced capability development, and specialized domain exploitation ...

Be Seen First

Familiarity with penetration testing, red team support, or adversary emulation. * Scripting proficiency (Python, PowerShell, Bash) for assessment automation and data reduction. Company Description ...

Be Seen First

Familiarity with penetration testing, red team support, or adversary emulation. * Scripting proficiency (Python, PowerShell, Bash) for assessment automation and data reduction. Company Description ...

... emulation, cyber range experimentation, and model-based simulation, defining experimental objectives and strategies. * Independently design, execute, and evaluate complex adversary-defender studies ...

Senior Penetration Testing (Red Team

Denver, CO · On-site

$88K - $109K/yr

The Red Team conducts advanced adversary emulation operations to challenge assumptions and emulate cyber and criminal threat actors targeting or attacking the business. As a Red Team member, you will ...

Conduct comprehensive threat emulation exercises, actively simulating cyber-attacks to uncover ... achieve adversary goals. * Strong experience and expertise in phishing techniques, social ...

Conduct comprehensive threat emulation exercises, actively simulating cyber-attacks to uncover ... achieve adversary goals. * Strong experience and expertise in phishing techniques, social ...

Threat Hunt Analyst

Lakewood, CO · Hybrid

$99K - $225K/yr

Knowledge of adversary tactics, techniques, and procedures (TTPs) * Ability to translate cyber ... Experience with threat emulation or purple teaming * Knowledge of OT protocols such as Modbus or ...

Threat Hunt Analyst

Lakewood, CO · On-site

$99K - $225K/yr

Knowledge of adversary tactics, techniques, and procedures (TTPs) * Ability to translate cyber ... Experience with threat emulation or purple teaming * Knowledge of OT protocols such as Modbus or ...

Threat Hunt Analyst

Lakewood, CO · On-site +1

$99K - $225K/yr

Knowledge of adversary tactics, techniques, and procedures (TTPs) * Ability to translate cyber ... Experience with threat emulation or purple teaming * Knowledge of OT protocols such as Modbus or ...

Adversary Emulation information

What is adversary emulation?

Adversary emulation is a cybersecurity practice in which security professionals simulate real-world cyber attackers, or adversaries, to test and improve an organization’s defenses. By mimicking the tactics, techniques, and procedures (TTPs) used by actual threat actors, adversary emulation helps organizations identify vulnerabilities, assess detection and response capabilities, and strengthen their overall security posture. These exercises are often based on threat intelligence and frameworks like MITRE ATT&CK to ensure realistic scenarios.

What are the key skills and qualifications needed to thrive in adversary emulation?

To thrive in Adversary Emulation, you need deep knowledge of cybersecurity, attack methodologies, and penetration testing, often supported by degrees in computer science or related certifications such as OSCP or CISSP. Familiarity with tools like Cobalt Strike, Metasploit, and SIEM platforms is commonly required. Analytical thinking, creativity, and strong communication skills are essential to mimic real-world threats and report findings clearly. These skills are crucial for accurately simulating adversary tactics, identifying security gaps, and helping organizations strengthen their cyber defenses.

What are the typical challenges faced by professionals in adversary emulation roles?

Adversary Emulation specialists often encounter the challenge of staying ahead of rapidly evolving attack techniques and threat actor behaviors. They must continuously update their knowledge and adapt their methodologies to realistically mimic current adversaries, which requires ongoing research and collaboration with threat intelligence teams. Additionally, balancing the realism of simulated attacks with organizational risk tolerance and ensuring minimal disruption during assessments can be complex. Working closely with security operations, incident response, and IT teams is essential to maximize the value of each engagement and provide actionable insights for improving defenses.

What is the difference between Adversary Emulation vs Penetration Tester?

AspectAdversary EmulationPenetration Tester
CredentialsCybersecurity certifications, threat intelligence knowledgeSecurity certifications, ethical hacking certifications
Work EnvironmentSimulates real-world adversary tactics in controlled environmentsIdentifies vulnerabilities through controlled testing
Industry UsageUsed in threat simulation, red teaming, and advanced security assessmentsUsed in vulnerability assessments and security audits

Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.

What cities in Colorado are hiring for Adversary Emulation jobs?

Cities in Colorado with the most Adversary Emulation job openings:

Red Team Operator

Dark Wolf Solutions

Colorado Springs, CO • On-site

$155K - $180K/yr

Full-time

Re-posted 26 days ago


Job description

Dark Wolf is seeking an elite Red Team Operator to join our pack. In this role, you will serve as a high-impact, strategic catalyst for a broader Cyber Purple Team initiative, bridging the gap between offensive operations and defensive engineering. The team is actively developing, testing, and maintaining advanced cybersecurity solutions to protect space-ground systems, data links, and specialized infrastructure against complex modern threats. As part of this mission, our Red Team aggressively stress-tests defensive stacks, including the integration and deployment of the out-of-band cybersecurity tool Manticore and the in-band respond-and-protect solution Kraken.
Unlike a standard penetration testing role, this position focuses heavily on high-fidelity nation-state adversary emulation, advanced capability development, and specialized domain exploitation (including RF and satellite communication protocols). You will move beyond passive security to actively harden defenses, identify hidden vulnerabilities, and provide actionable insights to fortify critical infrastructure.
This position is located in Colorado Springs, CO. Supporting at a flexible hybrid schedule.
Key Responsibilities:
  • Research, develop, and maintain custom offensive toolsets, including C2 frameworks, initial access payloads, and post-exploitation modules
  • Translate real-world threat intelligence into automated tradecraft and sophisticated, multi-layered simulated adversarial operations to achieve high-fidelity nation-state emulation
  • Architect and deploy resilient, obfuscated redirector networks and sophisticated Command and Control (C2) infrastructure using covert channels to ensure operational persistence and bypass advanced EDR/XDR and NDR solutions
  • Conduct vulnerability exploitation across diverse operating systems, complex mission architectures, and specialized hardware, including the reverse-engineering of embedded systems and exploiting RF and satellite communication protocols
  • Provide real-world offensive intelligence essential for stress-testing and refining defensive counter-measures. Directly support the evaluation of the Manticore and Kraken security platforms to elevate the organization's collective security posture
  • Conduct deep-dive analysis into modern defensive technologies (AMSI, ETW, Kernel-level monitoring) to develop novel bypass techniques against state-of-the-art Blue Team detection stacks

Required Qualifications:
  • Bachelor's degree in Computer Science, Cybersecurity or related field
  • 6 minimum years proficiency in low-level languages for tool development and memory injection (C, C++, Go, Rust) as well as scripting languages (Python, PowerShell)
  • Required Certifications: Must meet DoDM 8140 / IAWD 8570 IAT Level II minimum requirements
  • Deep understanding of Windows Internals (PE format, API hooking, process hollowing), Linux, and/or Cloud architectures (AWS, Azure, GCP) from an offensive perspective
  • Proven experience reverse-engineering embedded/specialized systems and transforming proof-of-concept (PoC) code into stable, operationally ready exploits
  • Deep familiarity with the MITRE ATT&CK® framework and the ability to emulate the full lifecycle of an Advanced Persistent Threat (APT)
  • US Citizenship and active Top Secret security clearance

Preferred Skills & Certifications
  • Certifications: Technical designations such as OSEP (Offensive Security Experienced Penetration Tester), CRTO (Certified Red Team Operator), CRTL (Certified Red Team Leader) or GXPN (Giac Exploit Researcher and Advanced Penetration Tester).
  • DevOps Mindset: Experience with CI/CD pipelines and infrastructure-as-code (Terraform, Ansible) to rapidly deploy and tear down operational environments.

The Ideal Candidate
The ideal candidate is a technical specialist who thinks like an engineer but acts like an adversary. You are someone who isn't satisfied with using "off-the-shelf" tools and prefers to understand the underlying code to modify it for specific mission requirements. You thrive in the "preparation" phase, knowing that a successful operation is won or lost before the first packet is sent. This a role that will include hybrid on site duties.
The estimated salary range for this position is $155,000.00 - $180,000.00, commensurate on experience and technical skillset.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.