Logo for Protiviti

Offensive Security Consultant – Red Team & Adversary Simulation

Role overview

Qualifications

  • Bachelor's degree in a relevant discipline or equivalent hands-on experience
  • 5+ years of hands-on offensive security experience—red teaming, penetration testing, or adversary simulation
  • Strong written and verbal communication skills
  • Certifications such as OSCP, OSEP, OSWE, or comparable SANS 600/700-level coursework

Responsibilities

  • Plan and execute red team, purple team, and threat-led penetration testing engagements
  • Test the newest attack surfaces, including AI-powered applications
  • Develop new tooling and contribute to a robust lab of testing tools
  • Partner with defenders to improve detection and response capabilities

Key facts

Hard skills

Other skills

  • Creative Problem Solving
  • Communication
  • Collaboration
  • Curiosity
  • Mentorship
  • Report Writing

About the company

Protiviti logo

Protiviti

Business Consulting & Services

Protiviti (www.protiviti.com) is a global consulting firm that delivers deep expertise, objective insights, a tailored approach and unparalleled collaboration to help leaders confidently face the future. Protiviti and its independent and locally owned member firms provide clients with consulting and managed solutions in finance, technology, operations, data, digital, legal, HR, risk and internal audit through a network of more than 90 offices in over 25 countries. Named to the 2023 Fortune 100 Best Companies to Work For® list, Protiviti has served more than 80 percent of Fortune 100 and nearly 80 percent of Fortune 500 companies. The firm also works with government agencies and smaller, growing companies, including those looking to go public. Protiviti is a wholly owned subsidiary of Robert Half Inc. (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index. © 2024 Protiviti Inc. An Equal Opportunity Employer

Company details

Company typeLarge
IndustryBusiness Consulting & Services
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

JOB REQUISITION

Offensive Security Consultant – Red Team & Adversary Simulation

LOCATION

NEW YORK CITY

ADDITIONAL LOCATION(S)

WASHINGTON DC - MCLEAN

JOB DESCRIPTION

You Belong Here  

The Protiviti Career provides opportunity to learn, inspire, and advance within a collaborative and inclusive culture.  We hire curious individuals for whom learning is a passion. We lean into our mission: We Care. We Collaborate. We Deliver.   

At every level, we champion leaders who live our values of integrity, inclusion, innovation, and commitment to success. Imagining our work as a journey, we believe integrity guides our way, inclusion moves us forward together, innovation creates new destinations, and our commitment to success empowers us to deliver on our vision to be the most trusted global consulting firm. 


Where We Need You 

Protiviti's Attack & Penetration team is growing, and we're looking for an offensive security professional who wants to do real adversary work—not checkbox testing. You'll join a team that runs red team, purple team, and threat-led engagements for organizations across nearly every industry, and you'll have the tools, lab, and backing to push the craft forward. 


What You Can Expect 

You'll be both a trusted advisor and a hands-on operator. You'll lead engagements from scoping through executive readout, build lasting relationships with client security teams, and help them understand not just what's broken, but how a real attacker would exploit it and what to fix first. You'll also coach and develop teammates—sharing what you know and learning from them in return. 

  • Plan and execute red team, purple team, and threat-led penetration testing (TLPT) engagements that emulate real-world threat actors across on-prem, cloud, identity, and SaaS environments. 
  • Test the newest attack surface, including AI/LLM-powered applications, agentic workflows, and the identity platforms that connect them. 
  • Use and build AI-assisted tooling and automation to move faster and go deeper during operations. 
  • Develop new tooling, design novel attacks, and contribute to a robust lab of testing tools and equipment built to tackle hundreds of adversary simulation scenarios. 
  • Partner with defenders to turn findings into better detections, faster response, and measurable improvement. 
  • Help shape the future of the practice—if you have an idea for a new service and there's demand for it, we'll help you build it. 

Why You'll Want to Join 

  • Real-world impact: Your work directly shapes how clients defend against the threats they're facing today. 
  • Room to build: Support to develop tooling, research new techniques, and turn ideas into new services. 
  • Industry visibility: We encourage and support presenting at local, national, and international security conferences. 
  • Variety: Engagements across industries, technologies, and environments—no two operations look the same. 
  • Growth: Work alongside experienced operators, mentor others, and grow your career within a global firm. 
  • Flexibility: A hybrid model that balances purposeful in-person time with remote work. 

What Will Help You Be Successful 

  • You love offensive security and get energized by finding the path an attacker would take. 
  • You stay current on the threat landscape—new TTPs, tooling, vulnerabilities, and how AI is changing both attack and defense. 
  • You thrive on the puzzle of targeting an organization, chaining weaknesses together, and evading defensive controls. 
  • You enjoy sharing what you know—coaching teammates on engagements, building training, or debating the latest technique. 
  • You care about the client outcome and can translate technical risk into business impact that resonates with security teams and executives alike. 
  • You're comfortable owning work end to end—scoping, execution, reporting, and readout. 
  • You're curious about your clients' businesses and how security risk shows up in their industries. 

Do Your Talents Include the Following? 


Technical Skills and Talents 

Red & Purple Teaming 

  • Experience running red team engagements that emulate real-world threat actors, with a strong command of TTPs and MITRE ATT&CK. 
  • Ability to partner with SOC and detection engineering teams to improve detection and response. 
  • Experience designing threat intel–driven scenarios, including ransomware simulations. Familiarity with DORA TLPT, TIBER-EU, or CBEST is a plus. 

Tradecraft & Tooling 

  • Hands-on experience attacking Active Directory, cloud and identity platforms (AWS, Azure, GCP, Entra ID, Okta), and CI/CD pipelines. 
  • Proficiency with C2 frameworks (e.g., Mythic, Sliver, Cobalt Strike) and building custom tooling in languages like C#, Go, Rust, Python, or PowerShell. 
  • Strong OpSec and experience evading EDR and other monitoring tools. Exploit development or reverse engineering skills are a plus. 

Network & Application Penetration Testing 

  • Experience performing internal and external network penetration tests, including vulnerability discovery, exploitation, and privilege escalation. 
  • Experience testing web applications, APIs, and mobile apps, with a solid grasp of the OWASP Top 10 and tools like Burp Suite. 
  • Ability to look past scanner output, validate findings manually, and chain issues into real attack paths. 

AI & LLM Security 

  • Understanding of attacks against LLM-enabled apps and agents (e.g., prompt injection, data leakage, tool abuse) and interest in using AI to speed up offensive work. 

Soft Skills 

  • Ability to turn technical findings into clear, actionable reports and conversations for both technical teams and executives. 
  • Creative problem solving—finding a way forward when the obvious path is blocked. 
  • A track record of research, tool releases, blogs, or conference involvement (e.g., Black Hat, DEF CON, BSides) is a plus. 

Your Educational and Professional Qualifications 

  • Bachelor's degree in a relevant discipline (e.g., CS, CE, IS, MIS, EE) or equivalent hands-on experience. 
  • 5+ years of hands-on offensive security experience—red teaming, penetration testing, or adversary simulation—in consulting or in-house. 
  • Strong written and verbal communication skills, including producing clear, client-ready reports and presentations. 
  • Certifications such as OSCP, OSEP, OSWE, OSED, CRTO/CRTL, GXPN, GPEN, BSCP, or comparable SANS 600/700-level coursework are a plus. 
  • Cloud security certifications (e.g., AWS Certified Security – Specialty, Microsoft AZ-500, Google Professional Cloud Security Engineer, CCSK) are a plus.  


Our Hybrid Workplace 

Protiviti practices a hybrid model, which is a combination of working in person with a purpose and working remotely. This model creates meaningful experiences for our people and our clients while offering a flexible environment. The ratio of remote to in-person requirements vary by client, project, team, and other business factors. Our people work both in-person in local Protiviti offices and on client sites, which can include local or out-of-state travel based on our projects and client requests and commitments.   



Protiviti is not registered to hire or employ personnel in the following states –  West Virginia, Alaska. 

Starting salary is based on a full-time equivalent schedule. Placement in the range is dependent upon experience, skills and geographic work location. Below is the salary range for this job.

$138,000.00 - $219,000.00

Our annual bonus plan provides eligible employees additional cash and/or discretionary stock compensation opportunities. Below is the bonus target opportunity for this job.

12%

The total cash range is estimated from the sum of the base salary range plus the bonus target opportunity. Below is the estimated total cash range for this job.

$154,560.00 - $245,280.00

Employees are eligible for medical, dental, and vision coverages, FSA and HSA healthcare accounts, life and accident insurance, adoption and fertility assistance, paid parental leave up to 10 weeks, and short/long term disability. We offer eligible employees a company 401(k) savings and investment plan with an employer match of 50% on the first 6% of your contributions. We provide Choice Time Off (CTO) for vacation, personal needs, and sick time. The amount of (CTO) varies based on years of service. New hires receive up to 20 days of CTO per calendar year. Protiviti also recognizes up to 11 paid holidays each calendar year.

Learn more about the variety of rewards we offer at Protiviti at https://www.protiviti.com/sites/default/files/2026-01/2026_u.s._benefit_highlights.pdf.

Any benefits outlined are part of our reward offerings for full-time employees in the U.S. Your Open Enrollment materials, insurance contracts, plan documents and Summary Plan Descriptions together comprise the official plan document which legally governs the administration of your benefit plans. Protiviti reserves the right to terminate or amend your benefit plans in any way and at any time.

Protiviti is an Equal Opportunity Employer. M/F/Disability/Veteran

As part of Protiviti’s employment process, any offer of employment is contingent upon successful completion of a background check.

Protiviti is committed to being an equal employment employer offering opportunities to all job seekers, including individuals with disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to apply for a position, please contact us by sending an email to HRSolutions@roberthalf.com or call 1.855.744.6947 for assistance.

In your email please include the following:

  • The specific accommodation requested to complete the employment application.

  • The location(s) (city, state) to which you would like to apply.

For positions located in San Francisco, CA: Protiviti will consider qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

For positions located in Los Angeles County, CA: Protiviti will consider for employment qualified applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Protiviti is not registered to hire or employ personnel in the following states – West Virginia, Alaska.

Protiviti is not licensed or registered as a public accounting firm and does not issue opinions on financial statements or offer attestation services.

JOB LOCATION

NY PRO NEW YORK CITY

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Consultant Related jobs

Other jobs at Protiviti

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.