1

Phishing Simulation Jobs in Virginia (NOW HIRING)

Showing results 21-40

Phishing Simulation information

What are some common challenges faced by professionals running phishing simulation programs, and how can they be addressed?

Professionals managing phishing simulation programs often encounter challenges such as employee resistance, maintaining engagement, and ensuring simulations stay relevant to evolving threats. To address these, it's important to communicate the purpose of simulations clearly, provide timely feedback and education, and regularly update campaigns to reflect current phishing tactics. Collaborating closely with IT, HR, and leadership teams helps foster a culture of security awareness and ensures the program's effectiveness.

What is a phishing simulation?

A phishing simulation is a cybersecurity exercise where organizations send fake phishing emails to employees to test their ability to recognize and report malicious messages. The goal is to raise awareness about phishing tactics and improve employees' responses to real threats. These simulations help identify vulnerabilities within the organization and guide future training efforts to reduce the risk of successful phishing attacks.

What is the difference between Phishing Simulation vs Security Analyst?

AspectPhishing SimulationSecurity Analyst
CredentialsCertifications like CEH, CompTIA Security+Certifications like CISSP, CISA, CEH
Work EnvironmentTypically in cybersecurity teams, focusing on training and awarenessIn IT/security departments, analyzing threats and implementing security measures
Employer & IndustryUsed by organizations to test employee awareness in cybersecurityEmployed by organizations to protect IT infrastructure and respond to security incidents

While both roles are part of cybersecurity, Phishing Simulation focuses on testing and training employees against phishing attacks, whereas Security Analysts monitor, analyze, and respond to security threats within an organization.

What are the key skills and qualifications needed to thrive as a phishing simulation specialist, and why are they important?

To thrive as a Phishing Simulation Specialist, you need a solid understanding of cybersecurity principles, social engineering tactics, and experience with security awareness training programs, usually backed by a degree in information security or related certifications like CEH or CISSP. Familiarity with phishing simulation platforms (e.g., KnowBe4, Cofense), email security systems, and data analytics tools is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for designing realistic scenarios and educating users. These skills and qualifications are essential for helping organizations identify vulnerabilities, reduce human risk, and strengthen their overall security posture.
What job categories do people searching Phishing Simulation jobs in Virginia look for? The top searched job categories for Phishing Simulation jobs in Virginia are:
What cities in Virginia are hiring for Phishing Simulation jobs? Cities in Virginia with the most Phishing Simulation job openings:
Infographic showing various Phishing Simulation job openings in Virginia as of August 2026, with employment types broken down into 100% Part Time. Highlights an 100% In-person job distribution.

Security Engineer III, Red Team Operator (TS Clearance)

Deloitte

Rosslyn, VA • On-site

Full-time

Re-posted 20 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

We are seeking a skilled Red Team Operator to simulate real-world adversary tactics, techniques, and procedures to assess and improve the organization's detection, response, and resilience capabilities. This role is responsible for planning and executing adversary emulation, penetration testing, social engineering, and post-exploitation activities in a controlled and authorized manner. The ideal candidate combines deep offensive security expertise with strong operational discipline and clear reporting skills.

Work you'll do

As a Red Team Operator on the Cyber Defense & Resilience team, you will be responsible for...

  • Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
  • Emulate advanced threat actors using realistic attack paths, tools, and techniques.
  • Conduct reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration simulations.
  • Assess the effectiveness of security controls, monitoring, and incident response processes.
  • Perform phishing, social engineering, and credential attack exercises where authorized.
  • Develop custom payloads, scripts, and attack workflows to support engagements.
  • Document findings, attack chains, gaps in defenses, and recommendations for remediation.
  • Deliver clear after-action reports and debriefs to technical and leadership stakeholders.
  • Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
  • Maintain strict adherence to rules of engagement, legal requirements, and operational safety.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

Qualifications

Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance
  • Ability to work onsite up to 5 days a week.
  • 2+ years of experience within the following:
    • Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
    • Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
    • Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
    • Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
    • Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
    • Experience with MITRE ATT&CK mapping and threat emulation.
    • Ability to write high-quality reports that connect technical findings to business risk.
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
  • Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Experience with C2 Frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
  • Experience with cloud red teaming in AWS, Azure, or GCP.
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
  • Experience developing custom tooling or modifying public offensive tools.
  • Knowledge of malware analysis, reverse engineering, or exploit development.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $110,700- $218,300.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

We are seeking a skilled Red Team Operator to simulate real-world adversary tactics, techniques, and procedures to assess and improve the organization's detection, response, and resilience capabilities. This role is responsible for planning and executing adversary emulation, penetration testing, social engineering, and post-exploitation activities in a controlled and authorized manner. The ideal candidate combines deep offensive security expertise with strong operational discipline and clear reporting skills.

Work you'll do

As a Red Team Operator on the Cyber Defense & Resilience team, you will be responsible for...

  • Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
  • Emulate advanced threat actors using realistic attack paths, tools, and techniques.
  • Conduct reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration simulations.
  • Assess the effectiveness of security controls, monitoring, and incident response processes.
  • Perform phishing, social engineering, and credential attack exercises where authorized.
  • Develop custom payloads, scripts, and attack workflows to support engagements.
  • Document findings, attack chains, gaps in defenses, and recommendations for remediation.
  • Deliver clear after-action reports and debriefs to technical and leadership stakeholders.
  • Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
  • Maintain strict adherence to rules of engagement, legal requirements, and operational safety.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

Qualifications

Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance
  • Ability to work onsite up to 5 days a week.
  • 2+ years of experience within the following:
    • Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
    • Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
    • Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
    • Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
    • Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
    • Experience with MITRE ATT&CK mapping and threat emulation.
    • Ability to write high-quality reports that connect technical findings to business risk.
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
  • Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Experience with C2 Frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
  • Experience with cloud red teaming in AWS, Azure, or GCP.
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
  • Experience developing custom tooling or modifying public offensive tools.
  • Knowledge of malware analysis, reverse engineering, or exploit development.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $110,700- $218,300.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom