Red Team Operator, Operational Technology (OT)

Armadin

1d ago • 1 views • 0 applications
Full-time Remote
Remote
Competitive
Full-time

Job Description

About Us
Join Armadin and stand at the forefront of cybersecurity innovation in the AI era. We are a pioneering team of elite engineers, researchers, and security experts, united by a singular mission: to redefine proactive security. As cyberattacks grow increasingly autonomous and relentless, we believe in a future where organizations are defended not reactively, but proactively – neutralizing threats before they ever materialize. This is how we protect the institutions the world depends on.
We are engineering autonomous proactive security solutions from the ground up, embedding the unparalleled tradecraft of elite security practitioners into purpose-built AI security models and agents. These intelligent systems discover risks and orchestrate their remediation long before a breach can occur.
Helmed by Kevin Mandia, the visionary founder behind Mandiant's $5.4B acquisition by Google, Armadin is powered by minds from Google, xAI, Meta, Stanford, Georgia Tech, Waterloo, Berkeley, and MIT. We're assembling a dream team to build the future of security for an adversary that never sleeps.

Role Overview: OT Red Team Operator
Are you a master of offensive security, driven by a mission to protect the world's most critical infrastructure? As an **Operational Technology (OT) Red Team Operator** at Armadin, you'll embark on high-stakes, adversary-focused offensive operations within the most sensitive OT, Critical Infrastructure, and converged enterprise environments. Here, precision is paramount, and the margin for error is non-existent.
Modern OT environments are no longer isolated; they are intricate tapestries woven with corporate networks, Active Directory, cloud systems, and specialized web/thick-client management layers. Your engagements will simulate complex, multi-stage real-world attacks spanning this entire attack surface — from enterprise network perimeters down to the very core of cyber-physical and industrial control systems.
This role demands far more than automated scanning. You will holistically analyze environments, uncover intricate attack paths across network boundaries and applications, and operate with discipline, creativity, and intent. Emulating sophisticated threat actors, you'll chain application vulnerabilities, Active Directory misconfigurations, network trust relationships, and protocol weaknesses to achieve operational objectives, all while minimizing detection and rigorously ensuring process safety.
Beyond direct engagement work, you'll play a pivotal role in shaping the future of autonomous security. You will partner closely with our internal engineers and researchers to define, build, and test adversarial evaluations that meticulously model real attacker behavior across OT, network, and application domains. Your unique insights—derived from complex kill chains, privilege escalation techniques, and custom operational tradecraft—will be translated into structured inputs. These inputs are critical for training and validating our AI systems, teaching them to plan, execute, and reason about offensive operations at scale. This is your chance to directly influence how cross-domain offensive expertise is captured, operationalized, and automated for global impact.

What You'll Do

Lead Cyber-Physical & Converged Penetration Tests: Plan and execute sophisticated semi-automated and manual red team operations across sensitive OT environments (e.g., ICS, SCADA, DCS, BMS, IIoT, Embedded Systems). Your human expertise and judgment will be critical for maintaining safety, process integrity, and uptime during these critical assessments.
Exploit Multi-Domain Attack Surfaces: Discover and exploit weaknesses across converged IT, network, application, and OT layers, including:

OT services and industrial protocols (e.g., Modbus, DNP3, EtherNet/IP, Profinet).
Active Directory attacks (Kerberoasting, pass-the-hash, BloodHound enumeration, domain trust abuse) to pivot laterally from corporate networks into OT control zones.
OT software applications, engineering workstations, embedded web applications, and management APIs (OWASP Top 10, logic flaws, insecure authentication).
Container technologies, virtualization, and edge computing layers supporting modern industrial architectures.
Certificate services, PKI infrastructure abuse, and network perimeter controls (firewalls, VPNs, jump boxes).

Master Adversary Emulation & Post-Exploitation: Conduct stealthy lateral movement, privilege escalation, and persistence activities while expertly evading EDR, SIEM, and network monitoring solutions across segmented network zones.
Maintain Operational Security & Infrastructure: Deploy and operate covert command-and-control (C2) infrastructure (Cobalt Strike, Sliver, Mythic, custom frameworks) with strict attribution management, infrastructure isolation, and network OPSEC.
Drive Custom Tooling & Exploit Development: Develop custom scripts, proof-of-concept exploits, and plugins (Python, PowerShell, Go, C/C++) to manipulate proprietary network protocols, reverse engineer thick clients, or bypass specialized safety/security controls.
Practice Impeccable Operational Discipline: Demonstrate meticulous operational discipline, encompassing rigid scope adherence, thorough cleanup, precise evidence handling, and effective time management across concurrent engagements.
Deliver Impactful Reporting & Stakeholder Communication: Produce actionable, highly technical reports and present findings to diverse audiences—from plant managers and engineering teams to CISOs and executive leadership—clearly articulating exploitable risk versus theoretical risk.
Shape AI Safety & Guidance: Define the reasoning paths, protocol logic, and strict "No-Go" parameters that our AI models will utilize to navigate sensitive industrial networks, serving as the ultimate safety guardrail for autonomous operations.

What You'll Bring

Hands-on Offensive Expertise: Demonstrated experience in offensive security with a primary focus on OT/ICS/SCADA environments, combined with strong competency in network or application penetration testing. This includes technical knowledge of industrial protocols (Modbus, DNP3, EtherNet/IP, Profinet, OPC UA) and the ability to perform manual packet manipulation, traffic analysis, and firmware/embedded software assessments.
Additionally, proven hands-on experience in at least one of the following specialized areas:

Network & Active Directory Security: Expertise in enterprise network exploitation, including Active Directory kill chains (Kerberoasting, BloodHound, delegation abuse, forest trusts), network device manipulation (routers, firewalls, VPNs), and covert communication channels across segmented environments (Purdue Model).
Application Security: Proficiency in web application security testing methodologies (OWASP Top 10, business logic flaws, authentication/authorization bypass, injection attacks, API security).

Systems & Automation Acumen: Strong operating system fundamentals (Linux, Windows) and proficiency in scripting/programming in at least one language (Python, Go, PowerShell, Bash, or C/C++) to modify or extend offensive tooling.
Exceptional Risk Contextualization: Ability to accurately quantify exploitability and impact in a way that meticulously balances cyber risk with critical operational safety and uptime requirements.
Superior Communication Skills: Exceptional technical writing and verbal skills, capable of communicating complex findings effectively to both plant engineers and C-level executives.
Work Authorization: Must be eligible to work in the United States without sponsorship.

Even Better With

OT/ICS Certifications: GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), GCIP (GIAC Critical Infrastructure Protection), or equivalent.
Specialized Technical Experience: Proficiency in one or more of the following: mobile application testing, source code reviews, reverse engineering, embedded device testing, encryption/decryption, advanced packet analysis, and covert communication channels.
Network & Offensive Security Certifications: OSCP, OSEP, CRTO/CRTE (Certified Red Team Operator/Expert), CPTS, or PNPT.
AppSec Certifications: GWAPT, eWPTXv2, OSWE, CWES, or TCM Practical Web/Mobile Pentest.
Tooling & AI Focus: Experience developing custom C2 modules/extensions, or a demonstrated interest/experience in how Large Language Models (LLMs) and agentic AI workflows apply to offensive security operations.
Elite Background: Prior experience within specialized government offensive units, top-tier offensive security consultancies, or Fortune 500 red teams with operational technology scope.

Location
Remote within the United States

Benefits & Perks | FTE

🏥 Full Health, Dental, & Vision Coverage
📈 Meaningful Equity Ownership
🥙 In-Office Meals
✂️ Haircuts at the Office
🎉 Company Sponsored Conferences & Events
💸 401(k), HSA, and FSA Plans
🌴 Flexible PTO

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.