Offensive Security Technical Lead
Summary
Serves as the senior technical authority leading penetration testing and red-team engagements for sensitive U.S. federal cyber environments, defining methodologies and rules of engagement while hands-on supporting network, application, Active Directory/identity, and cloud (AWS/Azure) assessments. Fully remote within the U.S., with up to 25% domestic travel.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Offensive Security Technical Lead based in the United States.
The Offensive Security Technical Lead will serve as the senior technical authority for penetration testing and red-team activities supporting sensitive federal cyber environments.
This role focuses on continuous, proactive assessments of externally and internally visible assets to uncover exposures, validate vulnerabilities, and strengthen cyber resilience.
You will establish technical methodologies, govern rules of engagement, manage operational risk, and ensure the quality of complex security assessments.
The position combines strategic technical leadership with hands-on offensive security expertise across networks, applications, identity, cloud, and adversary infrastructure.
You will guide specialized teams across concurrent assessments while resolving challenging technical issues and mentoring experienced security professionals.
The role also requires close engagement with government customers, translating technical attack paths and vulnerabilities into clear mission and operational risks.
This is a fully remote opportunity for an accomplished offensive security leader who wants to contribute to high-impact national cybersecurity missions.
Accountabilities:
- Serve as the senior technical authority for penetration testing and red-team delivery across assigned programs, ensuring alignment among customer objectives, authorization, safety, methodology, staffing, and deliverables.
- Define and continuously improve assessment standards, rules-of-engagement patterns, technical review gates, evidence requirements, severity methodologies, reporting expectations, and reusable technical playbooks.
- Review and approve engagement plans, adversary scenarios, infrastructure designs, tooling exceptions, exploitation approaches, data-handling controls, and other high-risk technical activities.
- Guide technical teams, allocate specialized expertise across concurrent assessments, mentor staff, conduct technical readiness reviews, and resolve complex cross-domain challenges.
- Provide hands-on technical support for advanced network, application, Active Directory and identity, cloud, exploit-development, adversary-infrastructure, and defense-evasion challenges.
- Govern technical risk and ensure testing activities comply with authorization, deconfliction, evidence-control, data-handling, and stop-work requirements.
- Own final technical quality and acceptance for assessment reports, attack-path narratives, severity determinations, remediation recommendations, customer briefings, and purple-team scenarios.
- Lead technical customer discussions and communicate security findings, mission implications, and business risk to stakeholders.
- Coordinate with project management on schedules, staffing, dependencies, and issue escalation while maintaining primary ownership of technical delivery.
- Capture lessons learned, measure technical quality and repeatability, and continuously evolve offensive security capabilities as customer environments, processes, and tools develop.
- Support the maturity of repeatable technical delivery standards, training practices, quality metrics, and offensive security capabilities.
- U.S. citizenship is required.
- Ability to meet eligibility requirements for access to sensitive information and obtain a High Risk Public Trust fitness determination.
- Ability to work within customer-provided remote environments, use approved tools, and comply with rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria.
- 8+ years of progressively responsible offensive security experience, including substantial hands-on penetration testing and red-team or adversary-emulation delivery.
- 5+ years of experience leading complex technical engagements, multiple concurrent assessments, or senior offensive security teams.
- Expert-level ability to scope and govern safe testing across enterprise networks, applications and APIs, Windows/Active Directory and identity environments, Linux, AWS/Azure, external attack surfaces, and production environments.
- Demonstrated technical authority in rules of engagement, operational risk management, deconfliction, exploit validation, evidence quality, severity decisions, report acceptance, and customer out-briefing.
- Strong scripting, automation, or security tool-development capabilities, combined with sound judgment when evaluating and approving high-risk technical methods.
- One or more advanced hands-on certifications such as OSEP/OSCE, OSWE, GXPN, GPEN, OSED/OSEE, CRTO/CRTL, or equivalent expert-level experience.
- 12+ years of experience across offensive security, security research, adversary emulation, or technical assessment leadership is preferred.
- Experience supporting CISA, DHS, federal high-value-asset, critical infrastructure, ICS/OT, or similarly sensitive assessment programs is preferred.
- Experience maturing offensive security programs, establishing technical quality metrics, developing training, or building repeatable delivery standards is preferred.
- Advanced expertise in areas such as cloud security, identity, exploit development, malware and payload development, detection engineering, or purple teaming is preferred.
- Ability to brief senior government leadership and translate technical attack paths and vulnerabilities into operational and mission risk.
- Strong analytical, problem-solving, communication, mentoring, and technical leadership skills.
- Ability to work independently while coordinating effectively with technical teams, customers, and program stakeholders.
- Willingness to travel within the continental United States up to 25% as required.
- Proposed salary range of $105,100–$231,100 per year.
- Competitive compensation influenced by geographic location, contract requirements, relevant experience, technical skills, education, and certifications.
- Fully remote work opportunity from any U.S. state.
- Flexible time-off benefits designed to support work-life balance.
- Comprehensive healthcare and wellness benefits.
- Financial and retirement benefits.
- Family support programs and time-off benefits.
- Continuing education and professional learning opportunities.
- Robust learning and development resources to support career growth.
- Opportunities to work on high-impact federal cybersecurity and national security missions.
- Exposure to advanced penetration testing, red teaming, adversary emulation, cloud security, identity, exploit development, and purple-team operations.
- Opportunity to lead specialized technical teams and influence the maturity of offensive security capabilities.
- Up to 25% travel within the continental United States.
Requirements
Benefits
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company