For Employers

Kroll

Senior Consultant, Red Team Operator, Offensive Security

Posted 2 days ago
110K - 140K per year
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Senior Consultant will deliver complex red team, purple team, and adversary emulation engagements to identify and remediate security risks. They will also mentor junior consultants and produce clear, evidence-based reporting on attack paths and business impact.

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

 

Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We help our clients discover, understand, and remediate security risks across their networks, systems, applications, cloud environments, and identity platforms. Our clients trust us to use advanced offensive security tools, creativity, imagination, and expert knowledge to identify realistic attack paths and improve cyber resilience.

 

We are looking to grow our Red Team capability with a Senior Consultant / L3 Red Team Operator. Our expertise in red team operations, purple team engagements, assumed-breach testing, adversary emulation, and threat intelligence-led penetration testing is in high demand. Our collaborative ties to our forensic and incident response team, detection engineering team, threat intelligence team, and wider Cyber Risk practice enable us to deliver high-impact offensive security engagements for clients across a range of sectors.

 

Apply now to join One team, One Kroll.

 

What you’ll do

 

As a Senior Consultant, Red Team Operator, you will support the delivery of complex red team, purple team, assumed-breach, and adversary emulation engagements. You will work with clients to understand their environments, help define realistic attack objectives, develop attack paths, and execute authorised offensive security activity within agreed rules of engagement.

 

You will be expected to operate across a range of attack surfaces, including enterprise networks, Active Directory, Microsoft Entra ID, Microsoft 365, cloud platforms, endpoints, externally exposed services, and, where authorised, social engineering scenarios. You will also help clients understand the business impact of identified attack paths and provide clear, actionable recommendations to improve prevention, detection, and response.

 

In summary, you will:

  • Deliver red team, purple team, assumed-breach, and adversary emulation engagements for clients across multiple sectors

  • Support engagement planning, including threat-informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria

  • Execute hands-on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective-based testing

  • Assess and exploit attack paths across Microsoft Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms, where in scope

  • Build, adapt, and operate red team infrastructure, command-and-control tooling, payloads, and scripts during authorised client engagements

  • Apply detection-aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations

  • Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability

  • Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios

  • Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting

  • Produce clear, evidence-based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions

  • Present technical findings to security teams and communicate business risk to senior stakeholders

  • Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance

  • Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering

 

What you’ll need to succeed

  • 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed-breach engagements

  • Strong experience with Windows enterprise environments, Active Directory exploitation, privilege escalation, and lateral movement

  • Experienced and comfortable with performing social engineering techniques in support of red team operations, including email and voice phishing

  • Experience operating command-and-control frameworks such as, Mythic, Cobalt Strike, or similar tooling in authorised client engagements

  • Experience developing, modifying, or extending offensive security tooling, scripts, or payloads

  • Working knowledge of at least one of C, C#, Python, PowerShell, and/or JavaScript, to support offensive security objectives

  • Practical understanding of evasion techniques, endpoint security controls, operational security, and detection-aware tradecraft

  • Strong understanding of networking and web protocols, including TCP/IP, DNS, HTTP, HTTPS, and authentication flows

  • Experience conducting reconnaissance, attack path development, and objective-based testing

  • Excellent written and verbal communication skills, with the ability to explain complex technical issues clearly to technical and non-technical audiences

  • The ability to manage risk during live client engagements and operate within agreed rules of engagement

 

Nice to have

  • OSEP, OSCE3, CRTO, CRTL, GPEN, GXPN, or equivalent experience

  • Experience delivering threat intelligence driven red team engagements

  • Strong working knowledge of Microsoft Entra ID, Microsoft 365, and hybrid identity attack paths

  • Working knowledge of cloud platforms such as AWS, Azure, or GCP, including identity, privilege escalation, misconfiguration abuse, and cloud-native attack paths

  • Experience with exploit development, reverse engineering, malware analysis, or assembly-level debugging

  • Experience with macOS or Linux endpoint tradecraft

  • Experience with Kubernetes, Docker, CI/CD platforms, DevOps environments, or containerised workloads

  • Experience with physical security

  • Experience with employing modern AI tooling to support offensive engagements

  • Threat intelligence, detection engineering, or incident response experience

  • Experience writing blogs, presenting at industry events, publishing research, or contributing to offensive security tooling

  • Experience leading small teams or technical workstreams during complex offensive security engagements

 

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

 

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

 

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

 

About Kroll 

 

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. 

 

In order to be considered for a position, you must formally apply via careers.kroll.com.

 

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

 

The current salary range for this position is CAD $110,000 to $140,000

 

 

#LI-CN1

#LI-Remote


 

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Senior Consultant, ERP Services Delivery

Full Time United States $86300 - $172K per year Software Development

Lead Engineer - Infrastructure Specialist

Freelance Barbados, Dominica, Dominican Republic +3 more Software Development

AI-Scriptwriter

Full Time Ukraine Software Development

Forward Deployed Engineer – Bangalore, India

Full Time India $50000 per year Software Development

Forward Deployed Engineer – Rio de Janeiro, Brazil

Full Time Brazil $50000 per year Software Development

Pre-Sales Engineer – East Coast, United States

Full Time United States $80000 per year Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 214,488+ Jobs in Software Development

Answer easy questions

Answer easy questions

214,488+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified