Responsibilities
- Design and execute complex, objective-based Red Team and adversary simulation campaigns modeled on real-world telecom threats.
- Attack modern software supply chains, full-stack applications, cloud environments, and AI-driven applications including MCP integrations and custom LLM agents.
- Use generative AI and modern tooling for vulnerability research, payload generation, and offensive workflow automation.
- Test detection, logging, alerting, and incident response pipelines using stealth techniques and Living off the Land methodologies.
- Conduct Purple Team replay exercises with Blue Teams, developers, and product teams to improve detections and secure coding practices.
- Deploy and maintain external AWS and GCP attack infrastructure using automated CI/CD pipelines.
- Map findings to security policies, regulatory requirements, cyber hygiene principles, and compliance controls.
- Maintain rules of engagement, asset inventories, operational safety, and legal compliance during engagements.
- Provide technical guidance and mentorship to junior Red Team operators and penetration testers.
Requirements
- Bachelor’s degree and four or more years of work experience in a relevant security field.
- Four or more years of dedicated hands-on experience in Red Teaming, adversary simulation, or advanced penetration testing.
- OSCP, CRTO, CRTP, or GXPN certification.
- Experience with MITRE ATT&CK, threat intelligence, APT emulation, and bypassing modern EDR/XDR solutions.
- Development experience with Node.js, Angular, and Java for source-code review, web application exploitation, and bespoke attack tooling.
- Knowledge of AI security risks, prompt engineering, LLM jailbreaking, AI agent frameworks and APIs such as MCP, and AI-assisted offensive workflows.
- Knowledge of cyber hygiene, NIST CSF, CIS Controls, and translating offensive findings for compliance, risk, and audit stakeholders.
- Experience configuring and safely using C2 frameworks such as Cobalt Strike, Mythic, or Sliver.
- Experience with collaborative Purple Teaming and converting attack narratives into detection engineering rules.
- Master’s degree, cloud-native and containerization experience, advanced certifications such as OSEP, OSWE, or OSED, cloud security architecture experience, programming or scripting with C#, C++, Go, Rust, Python, Bash, or PowerShell, attack surface management, OSINT, telecommunications compliance frameworks, and strong communication skills are preferred.
Benefits
- Hybrid work arrangement with work from home and assigned office days determined by the manager.
- Scheduled workweek of 40 hours.
Tech Stack
Categories
About Verizon
We get you. You want more out of a career. A place to share your ideas freely — even if they’re daring or different. Where the true you can learn, grow, and thrive. You’ll find all that here. Because we empower you. We power and empower how people live, work and play by connecting them to what brings them joy. The same is true inside our walls. We do what we love — driving innovation, creativity, and impact in the world. And wherever you go, we got your back. This is a team sport. Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together— lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the V Team Life.
