Red Team Analyst Security Threat Hunting Penetration Testing

External job listingat Bot Tech

The Red Team Operator plans and executes authorized adversary simulations designed to evaluate the organization’s ability to prevent, detect, investigate, and respond to realistic cyberat...

External source - not verified2 weeks agoOpen until: Sep 26, 2026

Salary

Not provided

Location

Bogotá, Colombia

Employment type

Full time

Workplace

Not provided

Red Team Analyst Security Threat Hunting Penetration Testing

Bogotá, Colombia

Job description

The Red Team Operator plans and executes authorized adversary simulations designed to evaluate the organization’s ability to prevent, detect, investigate, and respond to realistic cyberattacks. This role is intended for a mid-career offensive security professional with approximately three to five years of experience conducting red team operations, penetration tests, adversary emulation exercises, or similar offensive security engagements. The operator is responsible for executing attack objectives, deploying and maintaining evasive red team infrastructure, adapting tools and techniques to bypass security controls, and identifying weaknesses across endpoint, identity, network, cloud, application, and security-monitoring environments. The role also supports the development and use of AI-enabled offensive security pipelines to accelerate reconnaissance, attack-path analysis, tooling, infrastructure management, payload development, and reporting. ## Key Responsibilities * Plan and execute authorized red team operations that emulate the tactics, techniques, and procedures of relevant threat actors. * Research threat actor groups, campaigns, malware, tooling, infrastructure, operational patterns, and emerging attack techniques. * Translate threat intelligence into realistic adversary emulation plans and attack scenarios. * Conduct reconnaissance, initial-access testing, privilege escalation, credential access, lateral movement, persistence, command-and-control, defense evasion, and data-access simulations. * Identify weaknesses in enterprise infrastructure by reproducing realistic attacker behaviors and evaluating how systems and defenders respond. * Develop attack paths across Windows, Linux, Active Directory, cloud platforms, identity providers, applications, network infrastructure, and security controls. * Deploy, configure, operate, monitor, and maintain red team infrastructure throughout the engagement lifecycle. * Manage command-and-control servers, redirectors, payload-hosting systems, phishing infrastructure, domains, DNS records, TLS certificates, cloud resources, VPNs, proxies, and supporting operational services. * Design infrastructure architectures that provide campaign separation, operational resilience, access control, attribution reduction, and secure teardown. * Maintain evasive infrastructure capable of operating against modern endpoint, network, email, identity, and cloud security controls. * Develop, modify, and troubleshoot payloads, scripts, implants, loaders, tooling, and automation used during authorized operations. * Adapt public and internally developed tools to meet engagement requirements and reduce common detection signatures. * Evaluate and improve operational security practices, including credential management, infrastructure segmentation, logging, access restrictions, data protection, and resource cleanup. * Use AI-enabled offensive security pipelines to support reconnaissance, code development, attack-path discovery, payload analysis, infrastructure deployment, reporting, and repetitive operational tasks. * Build or maintain workflows that integrate large language models, offensive security tools, data sources, automation frameworks, and agent-based systems. * Review AI-generated code, commands, payloads, infrastructure configurations, and attack recommendations for accuracy, safety, scope compliance, and unintended behavior. * Assess AI-enabled applications, agents, retrieval systems, model integrations, and automated workflows for exploitable security weaknesses. * Analyze logs, alerts, and telemetry generated during red team operations to determine which activities were detected, prevented, missed, or incorrectly classified. * Collaborate with threat hunting, detection engineering, incident response, and security operations teams during purple team exercises. * Reproduce attacker behaviors to validate detection rules, security controls, investigation procedures, and response capabilities. * Review detections generated during operations and help distinguish effective alerts from false positives, duplicate signals, or low-value noise. * Recommend improvements to detection logic, alert fidelity, telemetry collection, investigative context, and response procedures. * Provide investigative and analytic support during complex security incidents when offensive security expertise is required. * Document attack paths, operational timelines, infrastructure configurations, indicators, evidence, control failures, and detection opportunities. * Develop clear technical reports and executive summaries describing business impact, attack feasibility, defensive gaps, and recommended remediation. * Present findings to technical teams, security leadership, system owners, and other stakeholders. * Follow all authorization requirements, rules of engagement, data-handling procedures, communication plans, and emergency-stop conditions. * Support infrastructure teardown, credential rotation, evidence retention, data disposal, and post-engagement cleanup. * Contribute to team playbooks, tooling, infrastructure standards, automation, training materials, and operational processes. * Mentor junior operators and provide technical guidance during defined portions of red team operations. ## Knowledge and Experience * Typically requires a college degree in cybersecurity, computer science, information technology, engineering, or a related field, or equivalent practical experience. * Typically requires three to five years of professional experience in red teaming, penetration testing, adversary emulation, offensive security, vulnerability research, or a closely related discipline. * Demonstrated experience conducting offensive security assessments in enterprise environments. * Working knowledge of red team methodologies and adversary frameworks such as MITRE ATT&CK. * Experience conducting reconnaissance, initial access, privilege escalation, credential access, lateral movement, persistence, defense evasion, command-and-control, and post-exploitation activities. * Strong working knowledge of Windows, Linux, Active Directory, enterprise networking, authentication systems, web applications, and common infrastructure services. * Experience evaluating cloud environments such as Amazon Web Services, Microsoft Azure, or Google Cloud Platform is preferred. * Experience with identity platforms, single sign-on systems, multifactor authentication, privileged-access systems, and cloud identity is preferred. * Experience deploying and operating command-and-control frameworks and supporting red team infrastructure. * Familiarity with commercial and open-source command-and-control platforms, implants, redirectors, payload delivery mechanisms, and post-exploitation tooling. * Experience managing domains, DNS, TLS certificates, virtual private servers, cloud resources, proxies, VPNs, containers, and infrastructure-as-code. * Understanding of operational security principles, including attribution reduction, campaign separation, access control, credential hygiene, telemetry management, evidence protection, and secure teardown. * Experience adapting tools, payloads, or infrastructure to operate against endpoint detection and response, antivirus, network monitoring, email security, application controls, and identity protections. * Proficiency in one or more scripting or programming languages such as Python, PowerShell, Bash, C#, Go, C, C++, or JavaScript. * Ability to review, modify, debug, and safely execute offensive security code. * Experience with endpoint detection and response platforms, security information and event management systems, network monitoring, logging platforms, and defensive security controls. * Ability to analyze security telemetry and determine whether offensive activity was prevented, detected, missed, or misclassified. * Familiarity with phishing simulations, payload delivery, credential capture, social engineering infrastructure, or related initial-access techniques. * Experience documenting findings, preserving evidence, developing reports, and presenting technical results. * Familiarity with AI-assisted software development or AI-enabled offensive security workflows. * Experience integrating large language models, automation platforms, agents, security tools, APIs, or structured datasets is preferred. * Familiarity with prompt injection, indirect prompt injection, model manipulation, insecure tool use, retrieval-augmented generation, model context protocols, agent security, or AI application testing is preferred. * Demonstrated commitment to ethical conduct, authorized testing, data protection, and strict adherence to defined scope. * Other hands-on red team, penetration testing, exploit development, cloud security, infrastructure, or AI security certifications

Is this your job posting?

Claim it for free and receive video applications on CazVid.

Similar jobs