Security Engineer (Offensive) - Red Team Operational Vulnerability Assessor

Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Eligible for TS/SCI clearance
  • 5 years of cybersecurity experience (Red Team, penetration testing, etc.)
  • DoD 8570 IAT Level III certification (e.g., CISSP, CASP+)
  • DoD 8570 CSSP Auditor certification (e.g., CEH, CySA+)
  • Understanding of Windows/Linux systems and networking fundamentals

Responsibilities

  • Plan and conduct Operational Vulnerability Assessments of Operational Technology
  • Support and conduct vulnerability assessments for both OT and IT
  • Execute persistent adversary emulation and adversarial assessments
  • Identify and exploit network and application-level vulnerabilities
  • Develop proof-of-concept exploits to test defenses
  • Produce detailed findings and remediation recommendations
  • Collaborate with teams to improve incident response capabilities

Benefits

  • Investment in employee training and certifications
  • Support for career growth and professional development
  • Paid relocation assistance available
  • Monday to Friday work schedule with flexible options
  • Competitive vacation and federal holidays package
  • High-quality healthcare plans with low deductibles
  • 401K plans with company matching
Full Job Description
We are seeking a highly skilled Red Team Operational Vulnerability Assessor (OVA)/Operator to join one of only eleven Department of War (DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United States Cyber Command (USCYBERCOM). This team is based out of Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security. You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.

The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.

Requirements

Responsibilities
• Primary role will be to plan and conduct Operational Vulnerability Assessments (OVA) of the security and defense of Operational Technology (OT) during discrete missions, often with additional objectives, including physical/wireless security, or specific vulnerabilities.
• For this specific position, we are seeking experience in Industrial Control Systems (ICS), Internet of Things (IoT), and Facility-Related Control System (FRCS) environments.
• This position may likely include supporting and conducting other roles within the Red Team, to include:
  • Both Operational Technology (OT) and Information Technology (IT) vulnerability assessments
  • Persistent Cyberspace Operations (PCO) adversary emulation
  • Acquisition Penetration Testing (APT) via Adversarial Assessments of DoW systems
  • Support exercise objectives and training goals as an Opposing Force Aggressor (OFA)
  • Assist in the instruction of the customer's Red Team Operations Course (RTOC)

• Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.
• Identify and exploit network, host, and application-level vulnerabilities.
• Develop and refine proof-of-concept exploits and techniques to test defensive measures.
• Produce detailed technical findings and recommendations for remediation.
• Collaborate with defensive and engineering teams to improve detection and response.
• Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.
• Participate in after-action reviews and contribute to policy and playbook updates.
• Prepare, update, document, and present course materials that cover TTPs.
• Provide support required to maintain the customer's Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.
• Considerable travel. Normal schedule is Monday-Friday unless on travel supporting a discrete mission. Approximately 25% of support and schedule is either onsite at Quantico, VA, or on travel. The remainder of the schedule is remote. This can change based on the needs of the customer's mission. During normal schedule and during remote support periods, candidates should be feasibly able to report onsite to Quantico, VA, within two hours.

Minimum Qualifications
• TS/SCI eligibility
• 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).
• Possess and maintain a DoD 8570 IAT Level III certification: SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP.
• Possess and maintain a DoD 8570 CSSP Auditor certification: CySA+, CEH, CISA, GSNA, CFR, PenTest.
• Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements: CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA.
• Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active Directory).
• Once placed in this role, candidates must pass the customer's Red Team Operations Course (RTOC) at the Red Team Certified Professional (RTCP) level upon the first attempt of the RTOC. Depending on timing and schedule of this course, course availability may or may not be immediate after starting the position.

Preferred Qualifications
• Experience with any of the following:
  • AV/EDR evasion and detection-bypass techniques.
  • Custom tooling, payload or, command-and-control (C2) development.
  • Software development in C, C++, or a similar language.
  • Malware analysis and reverse engineering.
  • Cloud platforms and services (AWS, Azure, GCP).
  • Physical security assessments or red-team intrusion exercises.
  • Industrial control systems (ICS) and Internet of Things (IoT) environments.

• Offensive-security certifications such as OSCP, OSEP, OSCE, CRTO. CRTL, GXPN.

Benefits

At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.

RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.

Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $150,000 to $165,000 (annually).

#LI-LL1

About Resource Management Concepts, Inc.

Resource Management Concepts, Inc. Careers

Joining Resource Management Concepts, Inc. presents an unparalleled opportunity to advance one's career amidst a team of professionals dedicated to innovation and excellence. As a leader in providing high-quality technical solutions, Resource Management Concepts, Inc. is the perfect place for talented individuals looking to make a significant impact in their professional lives.

Explore Job Opportunities

Resource Management Concepts, Inc. offers a variety of job opportunities that cater to a range of skills and interests. Each position is designed to challenge team members while providing them with the chance to grow both personally and professionally. From technical roles to leadership positions, Resource Management Concepts, Inc. ensures that every team member can find a path that best suits their career ambitions.

Internship Programs

Students and recent graduates can gain invaluable experience through an internship at Resource Management Concepts, Inc. These positions are crafted to bridge the gap between academic understanding and practical professional experience, providing a robust platform for growth and learning in a real-world setting.

Commitment to Diversity and Inclusion

Resource Management Concepts, Inc. believes that diversity drives innovation. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Through diversity training and leadership programs, the company fosters a culture of openness and respect that enhances team performance and creativity.

Benefits and Culture

Resource Management Concepts, Inc. is dedicated to supporting its employees by offering a comprehensive benefits package that addresses health, financial security, and work-life balance. The company culture is built on a foundation of respect, integrity, and collaboration, making Resource Management Concepts, Inc. not just a great place to work, but a community.

Professional Growth and Development

Employees at Resource Management Concepts, Inc. are encouraged to continuously develop their skills through professional development opportunities and leadership training programs. The company supports career advancement through internal promotions and networking opportunities, ensuring that every employee has the resources to succeed.

Hiring Process

The hiring process at Resource Management Concepts, Inc. is designed to be transparent and efficient, starting from the initial application to the final interview. Candidates are encouraged to showcase their skills and experience in their resumes and during interviews, where they meet with current team members who are eager to welcome new talents to the company.

Stay Connected with Careers at Resource Management Concepts, Inc.

Potential candidates are invited to explore open positions that match their skills and interests on the Resource Management Concepts, Inc. careers page. Stay updated with the latest news, career tips, and job alerts by subscribing to the Resource Management Concepts, Inc. careers newsletter.

Join the Team

Resource Management Concepts, Inc. is continuously searching for curious, creative, and solution-driven team players. Check out the current job listings and find where one's talent can make a difference.

Networking and Career Insights

Engage with Resource Management Concepts, Inc. through various professional networks. Gain insights into the company's innovative projects and team dynamics, and see how Resource Management Concepts, Inc. is a leader in fostering professional growth and technological advancement. Resource Management Concepts, Inc. is not just a company—it's a place where careers are nurtured, innovation thrives, and opportunities abound.
Learn more about Resource Management Concepts, Inc.

Similar Jobs

More Jobs at Resource Management Concepts, Inc.

More Technical Services Jobs

Find similar Security Engineer (Offensive) - Red Team Operational Vulnerability Assessor jobs: