Senior Adversary Emulation Engineer
Core
Design and execute controlled adversary emulation scenarios to validate threat detection coverage, generate high-fidelity telemetry for threat hunting, and improve enterprise security posture against real-world attacks.
Role type
Senior Adversary Emulation Engineer (Red/Purple Team)
Builds
Repeatable adversary emulation operating models, detection validation workflows, and high-fidelity telemetry for threat hunting
Domain
Cybersecurity, Threat Detection, Adversary Emulation
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Adversary emulation, MITRE ATT&CK, threat-informed defense, detection engineering, threat hunting, incident response, security operations, Python scripting, automation, AI-assisted workflows, SIEM/XDR/EDR telemetry analysis, query languages (SPL/KQL/SQL/Sigma/YARA)
Preferred skills
Adversary emulation tooling (Atomic Red Team, MITRE Caldera, Cymulate, AttackIQ), cloud/SaaS/identity security testing, production detection development
Technologies
MITRE ATT&CK, Python, PowerShell, Bash, SIEM, XDR, EDR, SPL, KQL, SQL, Sigma, YARA
Responsibilities
Establish adversary emulation operating models and rules of engagement; design and execute controlled emulation scenarios; build automation for emulation planning and evidence collection; validate detection coverage and alert fidelity; generate high-fidelity telemetry for threat hunting; document logging gaps and telemetry quality issues; develop repeatable emulation playbooks and reporting artifacts; evaluate emerging AI-enabled security technologies; support purple team exercises and continuous improvement efforts.
Seniority
Senior, hands-on IC