Principal Red Team Operator

Verizon Verizon · Telecom · Irving, TX +4

This role is for a Principal Red Team Operator at Verizon, focusing on leading and executing red team campaigns and penetration tests to evaluate and enhance security personnel, procedures, and technology. The operator will emulate adversarial thinking, identify vulnerabilities, and communicate findings to technical and executive audiences. The role involves developing adversary emulation plans, utilizing attacker tools, and creating scripts/tools to improve red teaming processes. It requires extensive offensive security experience, including adversary emulation and threat simulation.

What you'd actually do

  1. Leading and executing end-to-end Red Team assessments, including adversary/threat simulation and emulation, social-engineering testing, and cybersecurity control bypass techniques.
  2. Developing adversary emulation plans that align with MITRE ATT&CK by incorporating cyber threat intelligence.
  3. Configuring and safely utilizing attacker tools, tactics, and procedures for Verizon environments
  4. Developing presentations and reports that effectively communicate to both technical and executive audiences.
  5. Assisting offensive security assessment operations in support of Red, Blue, and Purple Teams.

Skills

Required

  • Bachelor's degree or four or more years of experience
  • Six or more years of relevant required, demonstrated through one or a combination of job-related work experience, military experience, or specialized training or education (non-collegiate)
  • Six or more years of direct offensive security experience, specifically leading engagements in Adversary Emulation, Adversary Simulation, Threat Emulation or Threat Simulation

Nice to have

  • Proven ability to modify TTPs to evade modern EDR/NDR/XDR solutions and bypass security controls like AMSI and ETW.
  • Deep knowledge of Operating System internals (Windows, Linux, macOS) including memory management, process injection, API hooking, and kernel-level structures.
  • Thorough understanding of network protocols, with the ability to design covert command-and-control channels that blend with legitimate traffic.
  • Expertise in Active Directory and Azure AD attacks, including advanced techniques like Kerberoasting, DCSync, Golden Ticket, and identity federation exploits.
  • Implementation-level familiarity with modern exploitation, including buffer overflows, heap spraying, ROP chains, and logic flaws.
  • Advanced proficiency in reading and modifying code in languages such as C#, C/C++, Go, or Java for the purpose of exploit development and custom tooling.
  • Solid understanding of cloud-native environments, specifically containerization platforms (Docker, Kubernetes) and major cloud infrastructure (AWS, Azure, GCP).
  • Advanced industry certifications such as OSEP, OSED, GXPN, CRTO, or OSCP/OSWE.
  • A track record of continuous evolution, demonstrated by participation in CTFs, contributions to open-source security tools, or speaking at industry conferences.
  • Fluency in Blue Team processes and technologies (SIEM logic, threat hunting, SOC triage) to better simulate realistic threats and provide actionable feedback.
  • Demonstrated proficiency in scripting and automation (Python, Bash, PowerShell) to develop custom offensive security tooling and bypass security controls.
  • A degree in a technical field.

What the JD emphasized

  • Six or more years of direct offensive security experience, specifically leading engagements in Adversary Emulation, Adversary Simulation, Threat Emulation or Threat Simulation.