1

Cyber Threat Emulation Jobs (NOW HIRING)

We are seeking a Cyber Threat Emulation & Analyst at Lackland AFB in San Antonio, TX. What You'll Do: * Conduct both automated and manual enterprise vulnerability assessments, including conducting ...

We are seeking a Cyber Threat Emulation & Analyst at Lackland AFB in San Antonio, TX. What You'll Do: * Conduct both automated and manual enterprise vulnerability assessments, including conducting ...

next page

Showing results 1-20

Cyber Threat Emulation information

See salary details

$34K

$112.9K

$176K

How much do cyber threat emulation jobs pay per year?

As of Jul 26, 2026, the average yearly pay for cyber threat emulation in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What are the most common challenges faced by professionals in Cyber Threat Emulation roles?

Professionals in Cyber Threat Emulation often face the challenge of staying ahead of constantly evolving threat landscapes, requiring ongoing learning and adaptation of new techniques. Another common challenge is ensuring realistic simulations without disrupting business operations, as emulating real threats must be done safely within production or test environments. Collaboration with IT, security teams, and sometimes executive leadership is crucial to ensure findings are actionable and prioritized correctly. Additionally, balancing technical depth with clear communication to non-technical stakeholders is essential for driving security improvements.

What is cyber threat emulation?

Cyber threat emulation is the process of simulating real-world cyber attacks to test and evaluate an organization's security defenses. This practice involves replicating the tactics, techniques, and procedures (TTPs) used by cybercriminals or advanced persistent threats (APTs) to assess how well security systems and staff can detect and respond to threats. The goal is to identify vulnerabilities and improve incident response without causing actual harm to systems. Cyber threat emulation is commonly used in red teaming and penetration testing exercises.

What are the key skills and qualifications needed to thrive as a Cyber Threat Emulation specialist, and why are they important?

To thrive as a Cyber Threat Emulation specialist, you need a solid understanding of cybersecurity principles, network protocols, and penetration testing methodologies, often backed by a degree in information security or related field. Familiarity with tools such as Metasploit, Cobalt Strike, and knowledge of frameworks like MITRE ATT&CK, along with certifications like OSCP or CEH, are typically required. Strong analytical thinking, attention to detail, and effective communication skills help in assessing threats and conveying findings to stakeholders. These skills are crucial for simulating realistic cyberattacks, identifying vulnerabilities, and enhancing an organization’s security posture.

What is the difference between Cyber Threat Emulation vs Penetration Tester?

AspectCyber Threat EmulationPenetration Tester
CertificationsCEH, OSCP, CISSPCEH, OSCP, CPT
Work EnvironmentSimulates real-world attack scenarios to test defensesIdentifies vulnerabilities by attempting to exploit them
Employer & Industry UsageUsed by security teams to assess security postureHired by organizations to find security weaknesses
Search & Comparison IntentOften compared for security testing rolesRelated but focuses more on vulnerability discovery

Cyber Threat Emulation and Penetration Testing both involve security assessments, but emulation focuses on mimicking real-world attack scenarios to evaluate defenses, while penetration testing aims to find and exploit vulnerabilities. Both roles require similar certifications and are used within security teams to strengthen organizational security.

More about Cyber Threat Emulation jobs
What cities are hiring for Cyber Threat Emulation jobs? Cities with the most Cyber Threat Emulation job openings:
What states have the most Cyber Threat Emulation jobs? States with the most job openings for Cyber Threat Emulation jobs include:
Infographic showing various Cyber Threat Emulation job openings in the United States as of July 2026, with employment types broken down into 95% Full Time, 3% Part Time, and 2% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.
Cyber Threat Emulation & Analyst

Cyber Threat Emulation & Analyst

Bristol Bay Native Corporation

San Antonio, TX • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 24 days ago


Job description

STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Cyber Threat Emulation & Analyst at Lackland AFB in San Antonio, TX.
What You'll Do:
  • Conduct both automated and manual enterprise vulnerability assessments, including conducting regular patch & configuration vulnerability assessments as directed by operational flight leads.
  • Conduct Cyber Threat Emulation operations, and coordinate with security teams to strengthen the overall security posture of the AFNet and AFIN various tools and capabilities.
  • Test for real-time security vulnerabilities, conduct assessments, and assess vulnerability risk and impact.
  • Continuously develop and maintain safe and valid procedures to actively test Enterprise defensive measures. (CDRL A007 & A008)
  • Develop mitigations, policies, and procedures to coordinate with internal teams. (CDRL A007)
  • Work with incident response team to develop response policies and procedures.
  • Generate threat intelligence indicators during the course of Cyber Threat Emulation operations and provide reports back to operators. (CDRL A008)
  • Coordinate with internal and external intelligence teams in order to replicate threat actor (TA) Techniques, Tactics, and Procedures (TTPs).
  • Research & Evaluate threats and vulnerabilities to assist in the prioritization of remediation actions.
  • Utilize knowledge and understanding of the Cyber Threat Framework (ODNI) and production of Threat Emulation findings.
  • Utilize the MITRE ATT&CK framework to perform cyber security operations testing, and develop improvements based upon adversary behavior.
  • Formulate, lead and persuade individuals, large teams and communities on ideas, concepts, and opportunities.
  • Leverage research, frameworks, and best practices on the latest exploits and security trends and currency on industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
  • Provide information to operational leaderships tasking as required as it relates to CTE actions

What You Bring:
Requirements:
  • DoDD 8570.01-M/8140.01 I AT Level III CND
  • Active TS/SCI
  • Five years' of penetration testing experience. BA/BS or MA/MS
  • Five (5) years of penetration testing experience.
  • Demonstrated advanced knowledge of cyber security operations with master of two or more of the following: attack surface management, Security Operations Center (SOC) operations, Intrusion Detection/Intrusion Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM) use, threats (including Advanced Persistent Threat (APT), insider), vulnerabilities, and exploits; incident response, investigations and remediation.
  • Experience with PowerShell, BASH or Python scripting/programming language.
  • Must have a strong understanding of Linux Operating System.
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)

What We Offer:
STS Systems Support, LLC (SSS) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.
SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638