- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- Yesterday
About this role
About Us
At Armadin, we're a group of engineers, researchers, and security researchers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on.
We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite security practioners into purpose-built security models and agents that discover risk and remediate it before organizations are breached.
Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, Georgia Tech, Waterloo, Berkeley, and MIT to reinvent security for an adversary that never sleeps.
Role Overview
As an Operational Technology (OT) Red Team Operator, you will conduct adversary-focused offensive operations in highly sensitive Operational Technology (OT), Critical Infrastructure, and converged enterprise environments where the margin for error is zero. Modern OT environments do not exist in isolation; they are deeply interconnected with corporate networks, Active Directory, cloud systems, and specialized web/thick-client software management layers. These engagements are designed to simulate complex, multi-stage real-world attacks spanning the entire attack surface - from enterprise network perimeters down to cyber-physical and industrial control systems.
This role requires far more than executing automated scanners - you will analyze environments holistically, discover complex attack paths across network boundaries and applications, and operate with discipline, creativity, and intent. You will emulate motivated threat actors by chaining application vulnerabilities, Active Directory misconfigurations, network trust relationships, and protocol weaknesses to achieve operational objectives while minimizing detection and ensuring process safety.
Beyond direct engagement work, you will partner closely with internal engineers and researchers to help define, build, and test adversarial evaluations that model real attacker behavior across OT, network, and application domains. You will translate engagement outcomes - such as complex kill chains, privilege escalation techniques, and custom operational tradecraft - into structured inputs that support the training and validation of AI systems intended to learn how to plan, execute, and reason about offensive operations at scale. This role plays a direct part in shaping how cross-domain offensive expertise is captured, operationalized, and automated.
What You'll Do
Execute Cyber-Physical & Converged Penetration Tests: Plan and execute semi-automated and manual red team operations across sensitive OT environments (e.g., ICS, SCADA, DCS, BMS, IIoT, Embedded Systems) where testing requires human expertise and judgement to maintain safety, process integrity, and uptime.
Exploit Multi-Domain Attack Surfaces: Identify and exploit weaknesses across converged IT, network, application, and OT layers including:
OT services and industrial protocols (e.g., Modbus, DNP3, EtherNet/IP, Profinet).
Active Directory attacks (Kerberoasting, pass-the-hash, BloodHound enumeration, domain trust abuse) to pivot laterally from corporate networks into OT control zones.
OT software applications, engineering workstations, embedded web applications, and management APIs (OWASP Top 10, logic flaws, insecure authentication).
Container technologies, virtualization, and edge computing layers supporting modern industrial architectures.
Certificate services, PKI infrastructure abuse, and network perimeter controls (firewalls, VPNs, jump boxes).
Adversary Emulation & Post-Exploitation: Conduct stealthy lateral movement, privilege escalation, and persistence activities while evading EDR, SIEM, and network monitoring solutions across segmented network zones.
Maintain Operational Security & Infrastructure: Deploy and operate covert command-and-control (C2) infrastructure (Cobalt Strike, Sliver, Mythic, custom frameworks) while practicing strict attribution management, infrastructure isolation, and network OPSEC.
Custom Tooling & Exploit Development: Develop scripts, proof-of-concept exploits, and custom plugins (Python, PowerShell, Go, C/C++) to manipulate proprietary network protocols, reverse engineer thick clients, or bypass specialized safety/security controls.
Operational Discipline: Demonstrate meticulous operational discipline, including rigid scope adherence, cleanup, evidence handling, and time management across concurrent engagements.
Reporting & Stakeholder Communication: Produce actionable, technical reports and present findings to plant managers, engineering teams, CISOs, and executive leadership, clearly articulating exploitable risk vs. theoretical risk.
AI Safety & Guidance: Define the reasoning paths, protocol logic, and strict "No-Go" parameters that our AI models use to navigate sensitive industrial networks, serving as the ultimate safety guardrail for autonomous operations.
What You'll Bring
Hands-on experience in offensive security with a primary focus on OT/ICS/SCADA, combined with strong competency in network or application penetration testing. Including technical knowledge of industrial protocols (Modbus, DNP3, EtherNet/IP, Profinet, OPC UA) and the ability to perform manual packet manipulation, traffic analysis, and firmware/embedded software assessments.
Additionally, you bring hands-on experience in at least one of the following areas:
Network & Active Directory Security: Proven experience with enterprise network exploitation, including Active Directory kill chains (Kerberoasting, BloodHound, delegation abuse, forest trusts), network device manipulation (routers, firewalls, VPNs), and covert communication channels across segmented environments (Purdue Model).
Application Security: Proven experience with web application security testing methodologies (OWASP Top 10, business logic flaws, authentication/authorization bypass, injection attacks, API security).
Systems & Automation: Strong operating system fundamentals (Linux, Windows) and proficiency in scripting/programming in at least one language (Python, Go, PowerShell, Bash, or C/C++) to modify or extend offensive tooling.
Risk Contextualization: Ability to quantify exploitability and impact in a way that balances cyber risk with operational safety and uptime requirements.
Communication: Exceptional technical writing and verbal skills to communicate with both plant engineers and C-level executives.
Work Authorization: Must be eligible to work in the United States without sponsorship.
Even Better With
OT/ICS Certifications: GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), GCIP (GIAC Critical Infrastructure Protection), or equivalent.
Specialized Experience: On one or more of the following: Mobile application testing, source code reviews, reverse engineering, embedded device testing, encryption/decryption, packet analysis, and covert communication channels
Network & Offensive Security Certifications: OSCP, OSEP, CRTO/CRTE (Certified Red Team Operator/Expert), CPTS, or PNPT.
AppSec Certifications: GWAPT, eWPTXv2, OSWE, CWES, or TCM Practical Web/Mobile Pentest.
Tooling & AI Focus: Experience developing custom C2 modules/extensions, or interest/experience in how LLMs and agentic AI workflows apply to offensive security operations.
Background: Prior experience within specialized government offensive units, top-tier offensive security consultancies, or Fortune 500 red teams with operational technology scope.
Location
Remote within the United States
Benefits & Perks | FTE
🏥 Full Health, Dental, & Vision Coverage
📈 Meaningful Equity Ownership
🥙 In-Office Meals
✂️ Haircuts at the Office
🎉 Company Sponsored Conferences & Events
💸 401(k), HSA, and FSA Plans
🌴 Flexible PTO
As published by Armadin Security. Applications are handled on their site.
Skills this posting mentions
About Armadin Security
Computer and Network Security
All 23 openings at Armadin SecurityOne click, then it is written
Apply to Armadin Security with a resume written for this role.
Queue Red Team Operator, Operational Technology (OT) and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Armadin Security’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Armadin Security
See all- Yesterday
- Yesterday
- 3 days ago
- 3 days ago
Member of Technical Staff - Distributed Systems
Palo Alto, CaliforniaRemote
$140k - $250k/yrStaffEngineering - 3 days ago
- 3 days ago
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Armadin Security publishes. Refolk is not the employer and does not handle their hiring. Applications go to Armadin Security directly.