Back to jobs
Red Team Analyst
Accelon ConsultingBengaluru, Karnataka, IndiaPosted 8h ago
Cybersecurity Analyst
Job Description
Project Overview
- Role sits within the Security Threat Analytics Group, supporting a greenfield Red Team capability being built from inception
- Mission: emulate realistic threat actors, validate security controls, measure detection and response capabilities, and improve the organization's ability to prevent, detect, and respond to cyber threats
- Scope spans enterprise, cloud, product, AI, and infrastructure environments
- Team operates at the intersection of deep technical knowledge and creative problem-solving, with a focus on innovation and precision
Role & Responsibilities
- Plan and execute hands-on Red Team operations across enterprise, cloud, identity, endpoint, network, product, AI/LLMs, and infrastructure environments via controlled threat actor emulation and security control validation
- Design adversary emulation scenarios using threat intelligence, reflecting relevant threat actors, TTPs, attack paths, and business-impacting objectives
- Support development of Red Team capability from the ground up: methodologies, rules of engagement, safety controls, tooling standards, reporting formats, metrics, and operational processes
- Support external vendor-led penetration tests (scope definition, technical oversight, quality review, findings validation)
- Collaborate with Threat Intelligence, Detection Engineering, Threat Hunting, SIRT, Security Engineering, Cloud Security, Application Security, Infrastructure, and AI Security teams
- Rapidly assess newly disclosed 0-days and actively exploited vulnerabilities; validate exploitability and partner with Detection Engineering and SIRT to develop detections and response capabilities
- Participate in purple team exercises to validate telemetry, detections, alert fidelity, response procedures, and security control effectiveness
- Conduct threat-informed Red Team assessments during M&A due diligence and onboarding to identify attack paths, validate controls, and uncover integration risks
- Partner with Application Security penetration testing teams to align activities, share findings, validate weaknesses, and support coordinated remediation
- Produce high-quality Red Team reports, executive summaries, technical findings, briefings, and remediation guidance
- Design, implement, and measure phishing and vishing campaigns as part of social engineering testing
- Continuously evaluate and improve offensive security tools, methodologies, testing standards, and operational processes
- Mentor junior team members through technical coaching, peer review, tradecraft development, and operational guidance
Required Skills & Qualifications
Must-Haves:
- Demonstrated experience building, scaling, and operating a Red Team, penetration testing, or offensive security program from inception through maturity
- Proven hands-on experience safely compromising enterprise environments through controlled offensive security operations
- Proven experience designing and leading adversary emulation capabilities, including realistic attack scenarios, threat-informed methodologies, purple team exercises, detection validation, and control effectiveness assessments aligned to MITRE ATT&CK
- Strong understanding of adversary TTPs and their application in offensive security assessments
- Advanced knowledge of cloud platforms (AWS and Azure) from both offensive and defensive perspectives
- Strong understanding of enterprise networking, operating systems, security architectures, and common attack paths
- Experience measuring Red Team effectiveness through metrics, reporting, and continuous improvement
- Practical experience using AI within Red Team workflows
- BA/BS in Computer Science, Information Security, or related field, or equivalent experience
Nice-to-Haves:
- Relevant certifications: OSCP, OSEP, OSWE, CRTO, CRTM, GXPN, GPEN, CISSP, or equivalent offensive security certifications