Security Engineer (Offensive) - Red Team Operational Vulnerability Assessor
$150k - $165kResource Management Concepts, Inc.
Job Description
Job Description
Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.
We are seeking a highly skilled Red Team Operational Vulnerability Assessor (OVA)/Operator to join one of only eleven Department of War (DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United States Cyber Command (USCYBERCOM). This team is based out of Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security. You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.
The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.
Requirements
Responsibilities
● Primary role will be to plan and conduct Operational Vulnerability Assessments (OVA) of the security and defense of Operational Technology (OT) and Information Technology (IT) during discrete missions, often with additional objectives, including physical/wireless security, or specific vulnerabilities.
● For this specific position, we are seeking experience in Industrial Control Systems (ICS), Internet of Things (IoT), and Facility-Related Control System (FRCS) environments.
● This position may likely include supporting and conducting other roles within the Red Team, to include:
- Both Operational Technology (OT) and Information Technology (IT) vulnerability assessments
- Persistent Cyberspace Operations (PCO) adversary emulation
- Acquisition Penetration Testing (APT) via Adversarial Assessments of DoW systems
- Support exercise objectives and training goals as an Opposing Force Aggressor (OFA)
- Assist in the instruction of the customer's Red Team Operations Course (RTOC)
● Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.
● Identify and exploit network, host, and application-level vulnerabilities.
● Develop and refine proof-of-concept exploits and techniques to test defensive measures.
● Produce detailed technical findings and recommendations for remediation.
● Collaborate with defensive and engineering teams to improve detection and response.
● Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.
● Participate in after-action reviews and contribute to policy and playbook updates.
● Prepare, update, document, and present course materials that cover TTPs.
● Provide support required to maintain the customer’s Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.
● Considerable travel. Normal schedule is Monday-Friday unless on travel supporting a discrete mission. Approximately 25% of support and schedule is either onsite at Quantico, VA, or on travel. The remainder of the schedule is remote. This can change based on the needs of the customer's mission. During normal schedule and during remote support periods, candidates should be feasibly able to report onsite to Quantico, VA, within two hours.
Minimum Qualifications
● TS/SCI eligibility
● 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).
● Possess and maintain a DoD 8570 IAT Level III certification: SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP.
● Possess and maintain a DoD 8570 CSSP Auditor certification: CySA+, CEH, CISA, GSNA, CFR, PenTest.
● Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements: CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA.
● Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active Directory).
● Once placed in this role, candidates must pass the customer's Red Team Operations Course (RTOC) at the Red Team Certified Professional (RTCP) level upon the first attempt of the RTOC. Depending on timing and schedule of this course, course availability may or may not be immediate after starting the position.
Preferred Qualifications
● Experience with any of the following:
- AV/EDR evasion and detection-bypass techniques.
- Custom tooling, payload or, command-and-control (C2) development.
- Software development in C, C++, or a similar language.
- Malware analysis and reverse engineering.
- Cloud platforms and services (AWS, Azure, GCP).
- Physical security assessments or red-team intrusion exercises.
- Industrial control systems (ICS) and Internet of Things (IoT) environments.
● Offensive-security certifications such as OSCP, OSEP, OSCE, CRTO. CRTL, GXPN.
Benefits
At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.
RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.
Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $150,000 to $165,000 (annually).
#IND123
$146k - $234k
...is seeking an Information Systems Security Engineer - Security Control Assessors (SCA) to support its Federal Strategic... ...the implementation of technical, operational, and management controls... ...technical guidance and training to both team members and stakeholders. Track, report...SuggestedContract workShift work- ...Cyber Security Analyst Transform technology into opportunity as... ...part in improving how agencies operate. The Naval Criminal... ...requirements; provide Detailed Vulnerability List (DVL) Reports for use in... ...Support: An internal mobility team focused on helping you achieve...SuggestedContract workWorldwide
- ...actively hiring an Intermediate Okta Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out... ...join our dynamic cybersecurity team. The ideal candidate will be... ..., and maintain the daily operations of the Okta Identity Cloud platform...SuggestedWork experience placementWork at officeRemote work2 days per week
$100k - $110k
...RMF Cyber Security Analyst 2026-170 This position... ...methodologies. Maintain operational security posture for... ...in eMASS. Review vulnerability scan results (using tools... ...between technical engineers, Information System Security... ...trusted employees and team members. Our...SuggestedWork at office- ...emerging technologies, network vulnerabilities, adversary Courses of Action... ...may impact USMC systems and operations. This position will also... ...characteristics, including security measures, auditing procedures... ...Impact/Low-Impact Analysis Red Team Analysis Alternative...SuggestedWork at office
$155k - $185k
...logistics; asset management; engineering; customer service;... ...enterprise services operations and sustainment.... ...with major enterprise Security Information and Event... ...experience with DoD-standard vulnerability assessment tools such... ...or as part of a team. Preferred...Contract workWork experience placementWork at office- ...Quantico, VA. Responsibilities span SIEM operations, vulnerability tooling, risk management, and 24x7... ...years of cybersecurity experience, DoD/IC security knowledge, and Top Secret/SCI... ...are essential for collaboration across teams. #J-18808-Ljbffr UIC Arctic Response...Contract work
$103k - $128k
...DescriptionECS is seeking a TS-cleared Senior Information Systems Security Engineer (ISSE) to support one of our mission critical programs for... ...process improvement to strengthen quality, scalability, and team performance.Job RequirementsUS citizenship with active Top...Contract work- ...seeking a skilled Endpoint Security Solutions (ESS) Systems Engineer – Level 2 to support a... ...compliance, and vulnerability management. The selected... ...protection initiatives, security operations, compliance activities,... ...with cybersecurity teams, system administrators,...Contract work
- ...is seeking an Endpoint Security Solutions (ESS) Systems Engineer ? Level 1 to provide senior... ...endpoint security operations within a mission-critical... ...technical leadership, support vulnerability management and... ...Collaborate with cybersecurity teams, system administrators,...Contract work
$130k - $160k
...match to help you build long-term financial security Paid time off as part of our... ...products for defense intelligence. Lead teams in researching multifaceted or critical... ...tasks. Have in-depth analysis of analytic operations and knowledge management issues across organizational...Permanent employmentFull timeContract workTemporary workFor contractorsWork at officeLocal areaFlexible hours$125k - $145k
...Analyst to join our Cyber Defense Team. In this critical role, you... ...cyber counter-infiltration operations to detect and mitigate Advanced... ...contributing directly to national security by protecting enterprise... ...Incident Response: Support Red Team (penetration testing) exercises...Full timeContract workRelocation packageMonday to FridayShift workDay shift$100k - $130k
...DescriptionEverforth ECS is seeking a AWS Cloud Security Engineer to work in our Stafford, VA (hybrid)office.The ECS Team provides focused Agile... ...across cloud infrastructure, operating system baselines, and... ...on request, responding to assessor questions, and driving Plan...Work at officeLocal area$75k - $130k
...maintain a U.S. Government security clearance, as... ...supports the secure operation, modernization, and sustainment... ...& Middleware Engineering Administer, configure... ...controls. Perform vulnerability remediation and... ...stakeholders, and technical teams to resolve production...Full timeRemote work- ...adversary capabilities, system vulnerabilities, and battlespace conditions to inform acquisition, operational, and risk-management... ...battlespace characteristics, including security controls, auditing procedures... ...ability to lead analytic teams addressing complex, high-priority...
- ...Cyber Security Analyst MANTECH is seeking a motivated, customer-oriented Cyber Security Analyst to support our Marine Corps Systems... ...Management Framework (RMF) process to achieve an Authority to Operate (ATO). Responsibilities include, but are not limited to:...Contract workWork at office
- ...interpreting and implementing Cyber Tasking Orders, validating security controls and STIG compliance, developing cybersecurity... ...and manually validating STIG/SRG requirements on diverse operating systems (Windows, Red Hat Linux, Cisco IOS, Cisco ASA). Expert level...
- ...Description Job Description MANDATORY TS SCI SECURITY CLEARANCE REQUIRED THIS POSITION IS... ..., baseline activity, architecture, operating system, services, connectivity and... ..., baseline activity, peculiarities and vulnerabilities, capabilities, and conclusions that address...Immediate start
- ...Mid) - TS/SCI Quantico, VA TS/SCI Security Clearance Wiser offers innovative... ..., baseline activity, architecture, operating system, services, connectivity and bandwidth... ..., baseline activity, peculiarities and vulnerabilities, capabilities, and conclusions that...Work experience placementMonday to FridayDay shift
- A technology solutions company is seeking a Systems Engineer to enhance enterprise IT services for law enforcement and scientific missions... ...standards. This position plays a critical part in ensuring operational excellence for mission capabilities. #J-18808-Ljbffr Method,...
$52 - $63 per hour
Twenty First Services, a regional insurance inspection firm, is seeking independent inspectors to cover Triangle, VA and surrounding areas. The role is a 1099 contract with a flexible schedule; each commercial report pays $52-$63 and typically takes about an hour. Travel...Contract workFlexible hours- ...Job Description Job Description BCBA Assessor Part-Time | 15–20 Hours/Week | Hybrid |... ...a BCBA Assessor to join our clinical team in Virginia. This flexible, part-time hybrid... ...~ Collaborative clinical and operational support If you love assessment, clinical...Part timeRemote workFlexible hours
- Farmers Insurance in Virginia's Stafford area seeks a Field Property Claims Adjuster to investigate property damage, determine liability, and write loss estimates. This role combines on-site visits with virtual work, supported by claims software, a company vehicle, and ...Remote job
- Streamline Defense is seeking a junior Cyber Systems Analyst to support MCIA at Quantico, VA. The role focuses on all-source analysis, threat assessment, and IC-standard deliverables to inform Marine Corps decision makers. The position requires an active TS/SCI clearance...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer (Offensive) - Red Team Operational Vulnerability Assessor. Be the first to apply!




