1

Cyber Threat Emulation Jobs (NOW HIRING)

Cyber threat emulation to assess defensive posture and capabilities while in a controlled environment * Threat hunting to identify advanced persistent threats * Technical writing in support of ...

New

Cyber threat emulation to assess defensive posture and capabilities while in a controlled environment * Threat hunting to identify advanced persistent threats * Technical writing in support of ...

New

Cyber threat emulation to assess defensive posture and capabilities while in a controlled environment * Threat hunting to identify advanced persistent threats * Technical writing in support of ...

New

Cyber threat emulation to assess defensive posture and capabilities while in a controlled environment * Threat hunting to identify advanced persistent threats * Technical writing in support of ...

New

Lead Cyber Threat Analyst

Washington, DC · On-site

$165K - $200K/yr

This position requires deep expertise in threat analysis, malware research, and adversary emulation within highly regulated environments. Responsibilities: * Lead cyber threat analysis and ...

Showing results 21-40

Cyber Threat Emulation information

See salary details

$34K

$112.9K

$176K

How much do cyber threat emulation jobs pay per year?

As of Aug 9, 2026, the average yearly pay for cyber threat emulation in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What are the most common challenges faced by professionals in cyber threat emulation roles?

Professionals in Cyber Threat Emulation often face the challenge of staying ahead of constantly evolving threat landscapes, requiring ongoing learning and adaptation of new techniques. Another common challenge is ensuring realistic simulations without disrupting business operations, as emulating real threats must be done safely within production or test environments. Collaboration with IT, security teams, and sometimes executive leadership is crucial to ensure findings are actionable and prioritized correctly. Additionally, balancing technical depth with clear communication to non-technical stakeholders is essential for driving security improvements.

What is cyber threat emulation?

Cyber threat emulation is the process of simulating real-world cyber attacks to test and evaluate an organization's security defenses. This practice involves replicating the tactics, techniques, and procedures (TTPs) used by cybercriminals or advanced persistent threats (APTs) to assess how well security systems and staff can detect and respond to threats. The goal is to identify vulnerabilities and improve incident response without causing actual harm to systems. Cyber threat emulation is commonly used in red teaming and penetration testing exercises.

What are the key skills and qualifications needed to thrive as a cyber threat emulation specialist?

To thrive as a Cyber Threat Emulation specialist, you need a solid understanding of cybersecurity principles, network protocols, and penetration testing methodologies, often backed by a degree in information security or related field. Familiarity with tools such as Metasploit, Cobalt Strike, and knowledge of frameworks like MITRE ATT&CK, along with certifications like OSCP or CEH, are typically required. Strong analytical thinking, attention to detail, and effective communication skills help in assessing threats and conveying findings to stakeholders. These skills are crucial for simulating realistic cyberattacks, identifying vulnerabilities, and enhancing an organization’s security posture.

What is the difference between Cyber Threat Emulation vs Penetration Tester?

AspectCyber Threat EmulationPenetration Tester
CertificationsCEH, OSCP, CISSPCEH, OSCP, CPT
Work EnvironmentSimulates real-world attack scenarios to test defensesIdentifies vulnerabilities by attempting to exploit them
Employer & Industry UsageUsed by security teams to assess security postureHired by organizations to find security weaknesses
Search & Comparison IntentOften compared for security testing rolesRelated but focuses more on vulnerability discovery

Cyber Threat Emulation and Penetration Testing both involve security assessments, but emulation focuses on mimicking real-world attack scenarios to evaluate defenses, while penetration testing aims to find and exploit vulnerabilities. Both roles require similar certifications and are used within security teams to strengthen organizational security.

More about Cyber Threat Emulation jobs
What cities are hiring for Cyber Threat Emulation jobs? Cities with the most Cyber Threat Emulation job openings:
What states have the most Cyber Threat Emulation jobs? States with the most job openings for Cyber Threat Emulation jobs include:
Infographic showing various Cyber Threat Emulation job openings in the United States as of August 2026, with employment types broken down into 93% Full Time, 3% Part Time, and 4% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.

Cyber Defense Analyst

SAIC

Fort George G Meade, MD

$120K - $160K/yr

Full-time

Posted 3 days ago

New


SAIC rating

7.9

Company rating: 7.9 out of 10

Based on 79 frontline employees who took The Breakroom Quiz

78th of 223 rated it services


Job description

Job ID: 2615324

Location: Fort Meade, MD, US

Date Posted: 2026-08-06

Category: Cyber

Subcategory: Cybersecurity Ops

Schedule: Full-Time

Shift: Day Job

Travel: Yes - 10% of the time

Minimum Clearance Required: TS.SCI_wPoly

Clearance Level Must Be Able to Obtain: None

Potential for Remote Work: ORA_ON_SITE


Description

SAIC is seeking a candidate to fill a Cyber Defense Analyst position on a joint Contractor-Government Cyber Protection Team with our customer at Ft. Meade, MD.

Job Duties:

  • Configuration, management, and optimization of intrusion detection systems for both host and network
  • Integrate and manage network sensors
  • Conduct threat analysis utilizing various sources to identify threats
  • Configuration, management and optimization of intrusion detection systems
  • Configuration and design of deployable network kits that include switches, routers, taps, hypervisors and network storage devices to ensure seamless integration and optimal performance
  • Malware triage
  • Cyber threat emulation to assess defensive posture and capabilities while in a controlled environment
  • Threat hunting to identify advanced persistent threats
  • Technical writing in support of findings and providing security recommendations in order to secure networks 

Qualifications

Required Education and Experience:

  • BS and nine (9) years or more experience; four (4) years additional in lieu of degree
  • Digital Forensics of Windows, Linux and networking devices
  • Incident Response Team Experience: Proven experience leading or supporting the detection, containment, and recovery of cybersecurity incidents in complex environments
  • Security Operations Center Analyst Tier 2 and 3 Expertise: Demonstrated ability to investigate advanced threats, manage escalated incidents, and develop and refine SOC response procedures
  • Cyber Protection Team Knowledge: Practical experience identifying vulnerabilities and implementing proactive measures to defend systems, networks, and data against evolving cyber threats

Required Security Clearance:

  • Must has an active TS/SCI with a CI Poly (poly must have been completed within the last 5 years)

Required Certification:

  • Information Assurance Technical (IAT) Level III

Desired Certification/Skills:

  • Global Information Assurance Certification (GIAC), Offensive Security
  • Zero Trust Architecture
  • ICS/SCADA

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom