Plan, design, and execute red (and purple) team engagements to simulate advanced adversarial tactics and techniques
Perform in-depth penetration tests on web applications, endpoint agents, internal systems, and people
Utilize a mix of traditional scripting and generative AI platforms to prototype tools, replicate threats, and automate workflows
Conduct social engineering campaigns to evaluate human vulnerabilities
Collaborate closely with the Security Operations Center and CSIRT teams to enhance detection and response capabilities
Stay informed on emerging threats and update red teaming methodologies
Partner with Product Security to prioritize testing efforts for new releases
Analyze and exploit vulnerabilities through detailed logging and provide remediation guidance
Develop and deliver detailed technical and executive-level reports post-engagement
Integrate red team tools, techniques, and processes into a broader security strategy
Lead or participate in after-action reviews to identify lessons learned
Assist in designing and implementing security controls based on red team findings