Senior Red Team Operator - Social Engineering Focus

 Posted 8 hours ago
  
 Worldwide
  
⭐ 5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Plan and execute full-scope adversary simulations and red team engagements across enterprise, cloud, and web3 environments. Lead social engineering campaigns and manage the full attack lifecycle from initial access to objective completion.

Hexens is looking for a Senior Red Team Operator with a strong focus on social engineering to join our team. We deliver full-scope adversary simulations against some of the hardest targets out there, spanning banks, crypto and web3 platforms, and industrial environments. We address complex security challenges, replicating real-world attackers to prove impact against the applications and infrastructures our clients rely on.



Remote Availability: Work from anywhere! This is a fully remote role with no location restrictions.



Responsibilities:

  • Plan and execute red team and adversary simulation engagements across enterprise, cloud, financial, and web3 environments.
  • Run social engineering campaigns as an initial-access vector: phishing, spear phishing, pretexting, and vishing, including executive-level targeting.
  • Carry engagements through post-access: lateral movement, privilege escalation, persistence, and objective completion.
  • Deploy and manage C2 infrastructure and supporting tooling.
  • Perform security control validation and evasion (firewall, proxy, DLP, EDR).
  • Conduct web application and network penetration testing as part of broader engagements.
  • Write clear, client-ready findings and remediation guidance.
  • Lead engagements independently when needed.


Required skillset:

  • Proven red team / adversary simulation experience across multiple sectors.
  • Hands-on social engineering experience with a demonstrable track record (phishing, pretexting, executive-level testing).
  • Strong web application and network penetration testing skills.
  • Comfort with C2 deployment, control bypass, and standard post-exploitation techniques.
  • Ability to run an engagement solo, from scoping through reporting.
  • Clear written and verbal communication for client-facing deliverables.


Big plus if any of the following apply:

  • Experience building phishing simulation and security awareness training programs.
  • Crypto / web3 or smart contract engagement experience.
  • Bug bounty track record (e.g. Bugcrowd, HackerOne).
  • Relevant certifications such as OSCP, CRTO, or OSCE3.
  • Conference talks or published research.

Similar Jobs

See all Remote Software Development jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified