1

Adversary Emulation Jobs (NOW HIRING)

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths * Design and execute campaign based ...

next page

Showing results 1-20

Adversary Emulation information

See salary details

$39

$58

$73

How much do adversary emulation jobs pay per hour?

As of Jun 30, 2026, the average hourly pay for adversary emulation in the United States is $58.47, according to ZipRecruiter salary data. Most workers in this role earn between $51.44 and $65.14 per hour, depending on experience, location, and employer.

What is adversary emulation?

Adversary emulation is a cybersecurity practice where security professionals simulate the tactics, techniques, and procedures of real threat actors to test and improve an organization's defenses. It involves creating realistic attack scenarios to identify vulnerabilities and enhance incident response capabilities, often using tools like red team exercises and threat intelligence. This role requires knowledge of cyber threats, attack methods, and security frameworks.

What is the difference between Adversary Emulation vs Penetration Tester?

AspectAdversary EmulationPenetration Tester
CredentialsCybersecurity certifications, threat intelligence knowledgeSecurity certifications, ethical hacking certifications
Work EnvironmentSimulates real-world adversary tactics in controlled environmentsIdentifies vulnerabilities through controlled testing
Industry UsageUsed in threat simulation, red teaming, and advanced security assessmentsUsed in vulnerability assessments and security audits

Adversary Emulation focuses on mimicking real-world attacker tactics to test defenses, while Penetration Testing identifies vulnerabilities by exploiting weaknesses. Both roles are essential for comprehensive cybersecurity strategies but differ in scope and approach.

What jobs pay 2000 a day?

In the field of adversary emulation, highly specialized roles such as senior cybersecurity consultants or penetration testers can sometimes command daily rates around $2,000, especially for freelance or contract work requiring advanced skills, certifications, and experience. These roles often involve simulated cyberattacks to test security defenses and may require knowledge of tools like Metasploit, Kali Linux, or custom scripting. Such high daily rates are typically associated with independent contractors or consultants working in high-demand environments.

How much do red teamers get paid?

Red teamers, or adversary emulation specialists, typically earn between $80,000 and $150,000 annually, depending on experience, certifications, and location. Senior professionals with advanced skills in penetration testing, scripting, and security tools can earn higher salaries, especially in high-demand industries.

What are the key skills and qualifications needed to thrive in Adversary Emulation, and why are they important?

To thrive in Adversary Emulation, you need deep knowledge of cybersecurity, attack methodologies, and penetration testing, often supported by degrees in computer science or related certifications such as OSCP or CISSP. Familiarity with tools like Cobalt Strike, Metasploit, and SIEM platforms is commonly required. Analytical thinking, creativity, and strong communication skills are essential to mimic real-world threats and report findings clearly. These skills are crucial for accurately simulating adversary tactics, identifying security gaps, and helping organizations strengthen their cyber defenses.

What is the salary of emulation engineer in Intel?

The salary of an emulation engineer at Intel typically ranges from $80,000 to $150,000 annually, depending on experience, location, and level. These roles often require knowledge of hardware design, verification tools, and scripting languages.

What are the typical challenges faced by professionals in Adversary Emulation roles?

Adversary Emulation specialists often encounter the challenge of staying ahead of rapidly evolving attack techniques and threat actor behaviors. They must continuously update their knowledge and adapt their methodologies to realistically mimic current adversaries, which requires ongoing research and collaboration with threat intelligence teams. Additionally, balancing the realism of simulated attacks with organizational risk tolerance and ensuring minimal disruption during assessments can be complex. Working closely with security operations, incident response, and IT teams is essential to maximize the value of each engagement and provide actionable insights for improving defenses.
More about Adversary Emulation jobs
What cities are hiring for Adversary Emulation jobs? Cities with the most Adversary Emulation job openings:
What states have the most Adversary Emulation jobs? States with the most job openings for Adversary Emulation jobs include:
What job categories do people searching Adversary Emulation jobs look for? The top searched job categories for Adversary Emulation jobs are:
Infographic showing various Adversary Emulation job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 89% Physical, 5% Hybrid, and 6% Remote job distribution, with an average salary of $121,624 per year, or $58.5 per hour.
Principal Red Team Operator

Principal Red Team Operator

Citizens

Charlotte, NC โ€ข Hybrid

Other

Medical, Dental, Vision, Retirement, PTO

Posted 14 days ago


Job description

Description

Principal Operator, Red Team

Role Summary
The Operator, Red Team is a hands on offensive security practitioner responsible for executing advanced adversary emulation and continuous red teaming operations across a modern, cloud and AI enabled enterprise. This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

Operating within high impact engagements, this individual will simulate real world attackers, identify and validate attack paths, and partner closely with defensive teams to ensure findings translate into measurable improvements in detection, response, and overall risk posture. Success in this role requires deep technical tradecraft, strong operational discipline, and a mindset focused not just on breaking systems, but on strengthening them through full lifecycle accountability.

This role reports to the Red Team Manager and works closely with Blue Team, Detection Engineering, Threat Intelligence, and Incident Response through Purple Teaming to continuously improve defensive effectiveness.

Locations & Work Arrangement: Remote is not an option, candidates must be willing to commute to one of the following hub locations with a hybrid schedule of 4 days onsite and 1 day remote per week with flexibility in one of the following hubs:

  • Phoenix
  • Johnston, RI
  • Boston, MA
  • Iselin, NJ
  • Pittsburgh, PAย 
  • Plano or Irving TX
  • Charlotte, NC
  • Manchester, NH

Key Responsibilities

  • Execute Red Team and Purple Team engagements as a primary operator, including adversary emulation, assumed breach scenarios, and intelligence driven attack paths
  • Design and execute campaign based attack operations that simulate real world adversary behavior across enterprise environments
  • Perform hands on exploitation and abuse across on prem, cloud, SaaS, and hybrid infrastructures
  • Simulate advanced attacker tradecraft, including living off the land techniques, identity abuse, privilege escalation, lateral movement, persistence, command and control, and controlled data exfiltration
  • Conduct testing against AI enabled systems and workflows, including abuse and misuse of AI assistants, copilots, and automation platforms
  • Execute prompt manipulation, indirect prompt injection, and AI model misuse scenarios to evaluate emerging attack surfaces
  • Collaborate closely with Detection Engineering and Blue Team during Purple Team engagements to validate detections, identify coverage gaps, and refine response effectiveness
  • Translate offensive findings into actionable remediation insights and partner with stakeholders to ensure vulnerabilities are addressed and control effectiveness is improved
  • Contribute to full lifecycle execution of engagements, ensuring findings are tracked through resolution and result in measurable risk reduction
  • Leverage and extend red team tooling and frameworks and develop targeted scripts or payloads to emulate specific adversary behaviors
  • Document findings clearly, including attack paths, control weaknesses, and detection gaps, contributing to engagement reports and technical debriefs
  • Operate within defined rules of engagement, safety protocols, and ethical guidelines to ensure realistic and controlled testing
  • Stay current on evolving adversary tactics, offensive tooling, and AI security research, incorporating new techniques into ongoing testing efforts

Experience and Skills

  • 4 to 8 years of hands on cybersecurity experience with a strong focus on Red Team operations, adversary emulation, or advanced offensive security
  • Demonstrated experience executing Red Team or Purple Team engagements in assumed breach or adversary based scenarios
  • Proven ability to design and execute attack paths rather than relying solely on automated tools or point in time testing
  • Strong technical capability across multiple attack surfaces, including identity and access attacks, endpoint and network exploitation, cloud and SaaS environments, and command and control frameworks
  • Understanding of campaign based red teaming and continuous testing approaches, including iterative and regression style validation
  • Working knowledge of AI security concepts, including how AI enabled systems, inputs, and workflows can be manipulated or abused
  • Ability to collaborate with Blue Team and Detection Engineering to translate offensive activity into improved detection and response capabilities
  • Strong operational discipline, including clear documentation, safe execution, and adherence to engagement constraints
  • Effective communication skills, with the ability to explain technical findings to security practitioners and cross functional partners
  • Demonstrated curiosity, adaptability, and ability to operate in rapidly evolving threat and technology environments

Education and Certifications

  • Bachelor's Degree in Security, Computer Science, Information Technology, or related field, or equivalent experience
  • Relevant industry certifications such as OSCP, OSEP, CRTO, CRTP, or similar advanced offensive security credentials
  • Exposure to AI security testing or AI red teaming through hands on work, training, or research is preferred

Pay Transparency
The salary range for this position is from $120,000 to $210,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to, the budget, work location, relevant skills, and experience.

We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens' paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.

#LI-Citizens1

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST