Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
OCC

Lead Associate Principal, Adversarial Red Team

OCC

Adversarial Red Team lead strengthening OCC’s equity-derivatives clearing security. Conducting offensive assessments across networks, applications, cloud, mobile, physical, and social-engineering domains.

Posted 8/4/2026full-time🇺🇸 United StatesSenior💰 $142,900 - $228,800 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in penetration testing, including network, application, and cloud security, while leveraging AI/LLM tools for enhanced offensive research and threat modeling. Proficient in developing Command and Control (C2) infrastructure and conducting comprehensive security assessments aligned with regulatory standards.

Highest-signal resume keywords
Penetration TestingCommand and Control (C2) DevelopmentAI/LLM ToolingSecurity Risk AssessmentVulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Network Penetration TestingApplication Penetration TestingCloud Security TestingExploit DevelopmentThreat ModelingOSINTCryptographyCustom ScriptingDatabase Security TestingSecurity Controls Validation
Soft Skills
Analytical SkillsProblem-SolvingCommunication SkillsCollaborationLeadership
Tools & Technologies
KaliMetasploitCobalt StrikeNmapNessusBurp SuiteWiresharkCrowdStrikeCarbon BlackMicrosoft Office
Certifications & Qualifications
OSCPOSWEOSCEGPENGXPNGWAPT
Industry Keywords
CybersecurityInformation AssuranceRegulatory StandardsVulnerability ManagementCritical Infrastructure

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityMacOSMySQLPythonUnix

About the role

Key responsibilities & impact
  • Execute comprehensive Red Team simulations covering network/application penetration testing, cloud security, social engineering, physical security, mobile testing, and OSINT
  • Develop and deploy Command and Control (C2) infrastructure using evasion and obfuscation techniques
  • Leverage AI/LLM tooling to accelerate offensive research, exploit development, and Red Team effectiveness
  • Conduct ad-hoc white-box testing on pre-production and in-development infrastructure
  • Validate remediated findings with IT owners
  • Perform threat modeling, security risk assessments, and independent reviews of OCC security, network, and applications
  • Develop evidence-based reports with actionable remediation recommendations
  • Debrief stakeholders on findings
  • Ensure security controls and testing align with regulations, industry best practices, and OCC policies
  • Cross-train Red Team and Security/IT teams on adversarial threats, attack vectors, and remediation strategies
  • Monitor emerging threats, threat intelligence, and attack techniques, advising IT leadership on mitigation
  • Support audits and contribute to security roadmap development
  • Review or guide junior Red Team professionals
  • Foster collaboration with OCC’s defensive security teams
  • Perform other duties as assigned

Requirements

What you’ll need
  • 7+ years of penetration testing experience
  • 7+ years of experience in Information Assurance or Cybersecurity work environments
  • Broad expertise in network/application, web application, and mobile application penetration testing
  • Command and Control (C2) infrastructure development experience
  • Cyber Defense evasion techniques, social engineering, OSINT, basic emissions testing, and physical security testing
  • Strong working knowledge of AI/LLMs and agentic systems, including autonomous agents, orchestration frameworks, and MCP
  • Proven open-source research and due diligence ability
  • Strong familiarity with enterprise technologies and security-related technologies
  • Operational experience as an administrator, engineer, or developer preferred
  • Direct experience testing commercial cloud environments including AWS, Azure, IaaS, PaaS, and SaaS
  • Knowledge of policy and procedure development, systems analysis, IA policy, vulnerability and risk management, and regulatory standards including CSF, NIST, PCI, FIPS 199, and COBIT 5
  • Strong knowledge of cryptography, enterprise infrastructure technology stacks, and network configurations
  • Ability to understand and probe/exploit diverse network and Internet protocols
  • Ability to understand and modify code across multiple programming languages and frameworks, with practical experience in at least one high-level language
  • Ability to facilitate meetings and translate business needs into project deliverables
  • Security-related certifications such as OSCP, OSWE, OSCE, GPEN, GXPN, GWAPT, or ARTE highly desired
  • BS in Computer Science, Information Management, Information Security, or comparable technical degree is desired but not required
  • Strong proficiency in network, web application, cloud, and mobile device security testing
  • Exploit, payload, and attack framework development experience
  • Knowledge of EDR detection capabilities such as CrowdStrike and Carbon Black, and behavioral-alert defense evasion
  • Custom scripting and process automation experience using Python, PowerShell, Bash, or similar
  • Database security testing experience with MSSQL, DB2, MySQL, or similar
  • Proficiency with penetration testing tools including Kali, Metasploit, Cobalt Strike, Nmap, Nessus, Burp Suite, Wireshark, Hashcat, BloodHound, Ghidra, Mimikatz, Impacket, and others
  • Track record of vulnerability research and CVE assignments
  • Knowledge of Windows APIs and Living off the Land binaries
  • Experience with Mainframes, Windows, Unix, macOS, and Cisco platforms and controls
  • Proficiency with Microsoft Office and basic Microsoft SharePoint document management
  • High energy, results-driven approach with strong analytical, problem-solving, and tactical planning skills
  • Exceptional verbal, written communication, and listening skills
  • Ability to work independently and guide junior Red Team professionals
  • Experience with critical infrastructure in a regulated environment is a plus

Benefits

Comp & perks
  • A highly collaborative and supportive environment developed to encourage work-life balance and employee wellness
  • A hybrid work environment, up to 2 days per week of remote work
  • Tuition Reimbursement to support your continued education
  • Student Loan Repayment Assistance
  • Technology Stipend allowing you to use the device of your choice to connect to our network while working remotely
  • Generous PTO and Parental leave
  • 401k Employer Match
  • Competitive health benefits including medical, dental and vision
  • Annual discretionary incentive compensation award, target range 8% to 15% (not guaranteed)