Consultant, Advanced Adversarial Simulation
Ensign InfoSecurity- Posted 16 hours ago
- Be among the first 10 applicants
Job Description
Red Team Engagements
- Plan and conduct authorised Red Team engagements, adversarial simulations, and objective-based security assessments.
- Translate relevant threats and customer risks into realistic attack scenarios.
- Perform reconnaissance, initial-access testing, social engineering, privilege escalation, lateral movement, persistence, and data-access simulations where authorised.
- Assess security controls across networks, endpoints, applications, cloud platforms, identity systems, and operational processes.
- Identify and demonstrate attack paths that could expose critical systems or business assets.
- Develop or adapt tools, scripts, payloads, and supporting infrastructure to achieve engagement objectives.
- Maintain operational security and minimise the risk of unintended disruption throughout each engagement.
Purple Team Engagements
- Collaborate with Blue Teams, Security Operations Centres, incident response teams, and other defensive stakeholders.
- Design and execute controlled attack scenarios to validate preventive, detective, and responsive security controls.
- Map simulated adversary behaviours to recognised frameworks such as MITRE ATT&CK.
- Evaluate security alerts, telemetry, logging coverage, investigation workflows, and response procedures.
- Help defensive teams develop and refine detection rules, use cases, playbooks, and response processes.
- Facilitate knowledge-sharing sessions to explain attacker techniques and strengthen defensive capabilities.
- Conduct validation and retesting to confirm that identified security gaps have been addressed.
- Document improvements and remaining areas of security exposure.
Engagement Planning and Governance
- Define engagement objectives, scope, assumptions, success criteria, and rules of engagement with relevant stakeholders.
- Ensure all activities are conducted within approved legal, ethical, safety, and customer-defined boundaries.
- Follow applicable change-control, data-handling, access-control, and escalation procedures.
- Maintain accurate records of actions, evidence, findings, and attack paths.
- Communicate critical findings, operational concerns, and potential business risks promptly.
- Coordinate with project managers, internal teams, and customer stakeholders throughout the engagement lifecycle.
Reporting and Stakeholder Communication
- Produce clear technical reports, executive summaries, attack narratives, and prioritised remediation recommendations.
- Explain technical findings in terms of their operational and business impact.
- Present engagement outcomes to technical teams, senior management, and executive stakeholders.
- Deliver engagement debriefs and remediation workshops where required.
- Support remediation planning, validation, and retesting.
Capability Development
- Contribute to the improvement of Red Team and Purple Team methodologies, tools, procedures, and knowledge bases.
- Research emerging threats, vulnerabilities, attack techniques, defensive approaches, and security technologies.
- Share technical knowledge, lessons learned, and good practices with team members.
- Support the development of reusable attack scenarios and detection-validation content.
Customer Engagement and Adaptability
- Deliver assignments of varying scope, complexity, and duration based on customer and business needs.
- Work at customer premises when required.
- Adapt to different industries, technologies, operating environments, and levels of security maturity.
- Remain flexible in supporting planned and ad-hoc project requirements.
- Communicate effectively with internal teams and customer stakeholders throughout each assignment.
Requirements:
- Offensive Security Certified Professional (OSCP) is required.
- Advanced or specialist certifications, such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN, GXPN, would be advantageous.
- Demonstrated experience in Red Teaming, Purple Teaming, adversarial simulation, penetration testing, or a related offensive security role.
- Strong knowledge of adversary tactics, techniques, and procedures, including the MITRE ATT&CK framework.
- Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud, and identity-based attack techniques.
- Experience collaborating with defensive security teams to validate and improve security controls.
- Understanding of defensive technologies and processes, including SIEM, endpoint detection and response, network monitoring, security logging, threat hunting, and incident response.
- Proficiency with relevant commercial or open-source offensive security tools and frameworks.
- Ability to develop or modify tools and scripts using languages such as Python, PowerShell, Bash, C#, or another relevant programming language.
- Ability to analyse complex attack paths and translate technical findings into clear business risks and actionable recommendations.
- Strong report-writing, presentation, communication, and stakeholder-management skills.
- Sound professional judgement and a strong commitment to ethics, confidentiality, operational security, and authorised testing boundaries.
- Ability to work independently and collaboratively within multidisciplinary teams.
- Willingness and ability to undertake customer-facing assignments of varying duration, including working at customer premises when required.
- Flexibility to support ad-hoc assignments and changing project requirements.
- Eligibility to obtain any security clearance or customer-specific access approval required for assigned engagements.
- A degree or diploma in cybersecurity, computer science, information technology, or a related discipline is preferred; equivalent practical experience will also be considered.
More Info
Key Skills
offensive security tools and frameworks
endpoint detection and response
security logging
identity-based attack techniques
Windows


