1

Adversary Emulation Jobs (NOW HIRING)

Consult on, design, and execute adversary emulation operations * Conduct research into real-world threat actor tactics, techniques, and procedures to develop proof-of-concept tools and playbooks

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

next page

Showing results 1-20

Adversary Emulation information

See salary details

$39

$58

$73

How much do adversary emulation jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for adversary emulation in the United States is $58.47, according to ZipRecruiter salary data. Most workers in this role earn between $51.44 and $65.14 per hour, depending on experience, location, and employer.

What is adversary emulation?

Adversary emulation is a cybersecurity practice in which security professionals simulate real-world cyber attackers, or adversaries, to test and improve an organization’s defenses. By mimicking the tactics, techniques, and procedures (TTPs) used by actual threat actors, adversary emulation helps organizations identify vulnerabilities, assess detection and response capabilities, and strengthen their overall security posture. These exercises are often based on threat intelligence and frameworks like MITRE ATT&CK to ensure realistic scenarios.

What is the difference between Adversary Emulation vs Penetration Tester?

AspectAdversary EmulationPenetration Tester
CredentialsCybersecurity certifications, threat intelligence knowledgeSecurity certifications, ethical hacking certifications
Work EnvironmentSimulates real-world adversary tactics in controlled environmentsIdentifies vulnerabilities through controlled testing
Industry UsageUsed in threat simulation, red teaming, and advanced security assessmentsUsed in vulnerability assessments and security audits

Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.

What are the key skills and qualifications needed to thrive in Adversary Emulation, and why are they important?

To thrive in Adversary Emulation, you need deep knowledge of cybersecurity, attack methodologies, and penetration testing, often supported by degrees in computer science or related certifications such as OSCP or CISSP. Familiarity with tools like Cobalt Strike, Metasploit, and SIEM platforms is commonly required. Analytical thinking, creativity, and strong communication skills are essential to mimic real-world threats and report findings clearly. These skills are crucial for accurately simulating adversary tactics, identifying security gaps, and helping organizations strengthen their cyber defenses.

What are the typical challenges faced by professionals in Adversary Emulation roles?

Adversary Emulation specialists often encounter the challenge of staying ahead of rapidly evolving attack techniques and threat actor behaviors. They must continuously update their knowledge and adapt their methodologies to realistically mimic current adversaries, which requires ongoing research and collaboration with threat intelligence teams. Additionally, balancing the realism of simulated attacks with organizational risk tolerance and ensuring minimal disruption during assessments can be complex. Working closely with security operations, incident response, and IT teams is essential to maximize the value of each engagement and provide actionable insights for improving defenses.
More about Adversary Emulation jobs
What cities are hiring for Adversary Emulation jobs? Cities with the most Adversary Emulation job openings:
What states have the most Adversary Emulation jobs? States with the most job openings for Adversary Emulation jobs include:
Infographic showing various Adversary Emulation job openings in the United States as of July 2026, with employment types broken down into 99% Full Time, and 1% Part Time. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $121,624 per year, or $58.5 per hour.
Staff Security Engineer - Red Team (AI)

Staff Security Engineer - Red Team (AI)

GEICO

Seattle, WA • On-site

Full-time

Retirement

Posted 11 days ago


Job description

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.
Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers' expectations while making a real impact for our company through our shared purpose.
When you join our company, we want you to feel valued, supported and proud to work here. That's why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.
We are seeking a hands-on Staff Security Engineer for our Red Team with deep technical expertise in running AI-driven adversary operations that measurably improve detection and response processes. You'll execute at the intersection of offensive security and AI, developing novel Red Team capabilities and running operations against AI-powered systems.
This role is responsible for working with other stakeholders in planning, executing, and delivering Red Team, Purple Team, and other Adversary Emulation operations. Outcomes will directly inform detection engineering, incident response readiness, and control validation. You will be responsible for the testing/evaluation of AI applications and agents as well as the leveraging of agentic AI to gain efficiencies for Red Team and penetration testing efforts.
Success in this role means you can champion operations end-to-end: shape the scope and objectives, define safety controls and deconfliction, build or tailor emulation plans, execute advanced operator tradecraft in authorized environments, and deliver clear findings mapped to TTPs, telemetry gaps, and detection opportunities. You are someone with progressive experience on Offensive Security operations who can consistently translate realistic adversary behavior into practical defensive improvements and repeatable emulation capability.
This role offers a unique opportunity to expand your influence, forge critical alliances, and lead the evolution of Adversary Emulation programs in a fast-paced environment. Your impact will be felt across the organization as we strengthen our defenses against ever-evolving cyber threats through simulation of real-world cyberattacks and attempts to breach the organization's defenses.
Responsibilities:
  • Participate in AI-focused adversary operations: plan, execute and deliver Red Team, Purple Team and other Adversary Emulation operations.

  • Scope and design operations: define objectives, target scope, success criteria, safety controls.

  • Develop and run emulations: build, customize, and execute emulation plans using platforms such as MITRE Caldera, or similar products.

  • Execute advanced AI-leveraged tradecraft across enterprise environments (identity, endpoints, networks, cloud, SaaS) in a controlled, measurable way.

  • Partner with defenders: work directly with Detection Engineering, Threat Intelligence, and Risk Management to validate telemetry coverage, tune detections, improve response playbooks, and close visibility gaps.

  • Champion continuous improvement and innovation in adversary operations techniques, tools, and methodologies.

Required Qualifications:
  • 8+ years of experience in Offensive Security operations.

  • 5+ years of hands-on experience running Red Team, Purple Team, and other Adversary operations in enterprise environments.

  • Deep understanding of LLM architecture and familiarity with how models process input, manage context, and generate output.

  • Experience with AI frameworks and tools such as PyTorch, TensorFlow, Hugging Face, and LangChain.

  • Experience with Azure, AWS, GCP or other cloud providers.

  • Strong working knowledge of MITRE ATLAS and ATT&CK, and the ability to translate TTPs into repeatable emulations and measurable detection outcomes.

  • Hands-on experience with adversary emulation platforms, including building/maintaining emulations and running operations.

  • Demonstrated capability with core operator tradecraft (C2, payload delivery, privilege escalation, lateral movement, persistence, and operational security) appropriate to authorized testing.

  • Extensive use of red team frameworks: Cobalt Strike, Sliver, Metasploit, Empire, BloodHound.

Preferred Qualifications:
  • OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs.

  • GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus.

  • Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.

  • Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions).

  • Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections.

Education:
  • Bachelor's degree in Cybersecurity, Computer Science or a related field.

Annual Salary
$110,000.00 - $260,000.00
The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate's work experience, education and training, the work location as well as market and business considerations.
GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.
The GEICO Pledge:
Great Company: At GEICO, we help our customers through life's twists and turns. Our mission is to protect people when they need it most and we're constantly evolving to stay ahead of their needs.
We're an iconic brand that thrives on innovation, exceeding our customers' expectations and enabling our collective success. From day one, you'll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people's lives.
Great Careers: We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career - and your potential - in mind. You'll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels.
Great Culture: We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose.
As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers.
Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future.
  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family's overall well-being.
  • Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance.
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.
GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

GEICO logo

About GEICO

Sourced by ZipRecruiter

GEICO is built on ingenuity, perseverance, innovation, resilience, and hard, honest work. From its humble beginnings in the midst of the Great Depression to its current place as one of the most successful companies in the nation, GEICO represents a quintessential American success story. At GEICO, we love that our associates are proud goal-seekers, and that's why we believe in celebrating their milestones and rewarding their achievements. Throughout the year we reward performance and accomplishments, host programs that recognize personal successes, and acknowledge innovation, service, and leadership.

Industry

Insurance services

Company size

10,000+ Employees

Headquarters location

Chevy Chase, MD, US

Year founded

1936