2

Remote Red Team Jobs in Spring, TX (NOW HIRING)

... Red Team, Caldera, or custom scripting. Support documentation of detection logic, coverage ... remote friendly work environment, as well as training opportunities to expand your skill set (to ...

... Red Team, Caldera, or custom scripting. • Support documentation of detection logic, coverage rationale, and response guidance. • Actively contribute to continuous improvement of detection ...

Ability to explain red flag findings and describe daily credentialing productivity (e.g., provider ... remote * Assignment Type: Contract (6 months) * Environment: Business office, professional and team ...

next page

Showing results 1-20

Remote Red Team information

What is a remote red team?

A Remote Red Team job involves simulating cyberattacks to test an organization's security defenses while working remotely. These professionals assess vulnerabilities, exploit weaknesses, and provide recommendations to improve security. They use ethical hacking techniques, penetration testing, and social engineering to mimic real-world threats. The goal is to help organizations strengthen their security posture by identifying and addressing risks before malicious hackers can exploit them.

What does a typical day look like for someone on a remote red team?

A typical day in a remote Red Team role involves planning and executing security assessments, crafting realistic attack scenarios, and documenting vulnerabilities discovered during penetration tests or simulated breaches. You’ll often work collaboratively with other Red Team members and interact with Blue Teams or IT staff to coordinate exercises and share findings. The workflow is usually a mix of independent tasks—such as research, reporting, and tool development—and regular virtual meetings to strategize or debrief. Flexibility, clear communication, and critical thinking are crucial as projects and threat simulations can vary frequently. This dynamic environment allows you to continuously develop your technical skills while contributing to the evolving security of diverse organizations.

What are the key skills and qualifications needed to thrive in the remote red team position, and why are they important?

To thrive as a Remote Red Team professional, you need a strong background in penetration testing, vulnerability assessment, network security, and a deep understanding of attacker tactics, techniques, and procedures (TTPs). Familiarity with common cybersecurity tools (e.g., Metasploit, Cobalt Strike, Nmap), scripting languages, and certifications like OSCP or CEH are highly valued. Exceptional problem-solving, written communication, and teamwork skills help in delivering comprehensive assessments and collaborating with clients or internal security teams. These competencies are essential for identifying security weaknesses, simulating real-world threats, and effectively improving an organization’s overall security posture.

What are popular job titles related to Remote Red Team jobs in Spring, TX?

For Remote Red Team jobs in Spring, TX, the most frequently searched job titles are:

What job categories do people searching Remote Red Team jobs in Spring, TX look for?

The top searched job categories for Remote Red Team jobs in Spring, TX are:

What cities near Spring, TX are hiring for Remote Red Team jobs?

Cities near Spring, TX with the most Remote Red Team job openings:

Detection Engineer - REMOTE

Binary Defense

Houston, TX • Remote

Full-time

Medical, Dental, Vision, Retirement

Posted 21 days ago


Job description

Description


Binary Defense is seeking  an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You'll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.
 

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.


Responsibilities


Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).

Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.

Leverage APIs to automate rule deployment, validation, and telemetry inspection-reducing reliance on GUIs.

Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.

Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.

Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.

Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.

Support documentation of detection logic, coverage rationale, and response guidance.

Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Requirements

2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response.

Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.

Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.

Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.

Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.

Ability to quickly learn new security technologies and adapt detection strategies accordingly.

Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.


Preferred


Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).

Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).

Exposure to multi-tenant or MDR environments and scaling detections across customer environments.

Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.

Experience in IR consulting and working across diverse EDR/SIEM stacks.


About Binary Defense


Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.


For more information, visit our website, check out our blog, or follow us on LinkedIn.


Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you're interested in joining a growing team with great perks, we encourage you to apply!