CareerPlanSign in

Senior Red Team Operator

Madrid (Hubs Spain)💼 Full-time🗓 2026-06-26 → 2026-09-26

Core

Lead advanced red team engagements by designing and executing long-term, intelligence-led campaigns to simulate advanced threat actors and test the bank's global security posture.

Role type

Senior Red Team Operator (Offensive Security)

Builds

Custom command-and-control (C2) infrastructure, bespoke tools, implants, and loaders to bypass modern security controls.

Domain

Cybersecurity / Offensive Security / Financial Services

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Advanced offensive security certifications (OSEP, OSCE/OSEE, CREST CCSAS, GXPN, CRTO), low-level language development (C++, C#, Go, Rust), scripting (Python, PowerShell), Active Directory exploitation, cloud security (Azure, AWS, GCP), Operational Security (OPSEC), covert operation execution, tool development for EDR bypass.

Preferred skills

Experience with Cobalt Strike or Sliver, purple teaming collaboration, mentoring junior operators.

Technologies

Cobalt Strike, Sliver, Azure, Google Cloud, AWS, GCP, C++, C#, Go, Rust, Python, PowerShell, EDR, Active Directory.

Responsibilities

Design and conduct complex, long-run red team campaigns mirroring top-tier intelligence-led exercises. Execute the full attack lifecycle from initial access to data exfiltration while evading Blue Teams. Build, operate, and customize command-and-control (C2) infrastructure. Develop custom tooling to bypass advanced defenses like EDR and application allow-listing. Partner with SOC and defensive teams in purple team exercises to tune detection rules. Author comprehensive reports translating technical findings into actionable recommendations for executives.

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.