UltraViolet Cyber

UltraViolet Cyber is a cybersecurity company focused on unified offensive and defensive security operations. It describes itself as a practitioner-led MSSP delivering managed detection and response, SOC-as-a-Service, red teaming, penetration testing, application security testing, continuous threat exposure management, and dedicated defense, with its UV Lens Security-as-Code platform at the core of its integrated security operations approach.

Computer and Network Security
501-1000

Description

  • Lead full-lifecycle red team engagements, including scoping, planning, execution, and reporting.
  • Simulate advanced persistent threat (APT) tactics against enterprise network and cloud environments.
  • Execute multi-stage attack chains involving network compromise, Active Directory abuse, cloud access, and data exfiltration.
  • Design and run social engineering campaigns such as phishing, vishing, and smishing.
  • Conduct adversary simulation across hybrid and cloud-native environments, including AWS, Azure, and GCP.
  • Develop custom tooling, payloads, and tradecraft to evade defensive controls such as EDR, SIEM, and CASB.
  • Produce clear, actionable reports for both technical and executive stakeholders.
  • Collaborate with blue team and MDR teams to deliver purple team assessments.
  • Mentor junior consultants and help build internal offensive security capabilities.
  • Stay current on emerging threat actor tactics, techniques, procedures, tooling, and research.

Requirements

  • US citizenship is required.
  • 4+ years of experience in offensive security, penetration testing, or red team roles.
  • Proven experience leading or independently executing full red team engagements, not just component pentests.
  • Strong command of red teaming methodologies and attack patterns.
  • Proficiency with Cobalt Strike, Metasploit, Sliver, Havoc, or equivalent C2 frameworks.
  • Ability to develop and modify offensive tooling in Python, PowerShell, C/C#, or Go.
  • Deep knowledge of Active Directory attack paths, including Kerberoasting, AS-REP roasting, ACL abuse, DCSync, and delegation attacks.
  • Hands-on experience attacking cloud infrastructure in at least one major provider such as AWS, Azure, or GCP.
  • Experience designing and executing phishing simulation campaigns, including credential harvesting and malware delivery.
  • Ability to present findings clearly to C-suite and board-level stakeholders.
  • Willingness to travel for on-site engagements as needed, up to approximately 25%.
  • Preferred certifications include OSCP, CRTO, CRTE, PNPT, CRTL, or equivalent.
  • Cloud security certifications such as AWS Security Specialty or AZ-900+ are a plus.
  • Prior consulting or professional services experience in a client-facing capacity is preferred.
  • Experience with TIBER-EU, CBEST, or other regulated red team frameworks is preferred.
  • Published research, CVEs, or conference presentations such as DEF CON or Black Hat are preferred.
  • Familiarity with threat intelligence and threat actor emulation planning is preferred.

Benefits

  • $165,000 to $195,000 annual salary.
  • 401(k) with employer match of 100% of the first 3% contributed and 50% of the next 2% contributed.
  • Medical, dental, and vision insurance available on the first day of the month following your start date.
  • Group term life, short-term disability, and long-term disability coverage.
  • Voluntary life, hospital indemnity, accident, and critical illness insurance options.
  • Participation in the Discretionary Time Off (DTO) program.
  • 11 paid holidays annually.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Data Loss Prevention (DLP) Implementation Consultant - Part Time

Muller Internet Software & Services

Data Loss Prevention (DLP) Implementation Consultant at a company deploying enterprise security controls for customer environments, responsible for implementing and operationalizing a DLP solution aligned to security requirements.

Active Directory HIPAA macOS SIEM
1 day, 22 hours ago

Senior Consultant - ICS/OT Cybersecurity

Dragos 251-1K Professional Services

Dragos is hiring a Senior Consultant for its Professional Services team to lead cybersecurity engagements that help industrial organizations protect critical infrastructure.

Active Directory Cybersecurity SIEM SSH
2 days, 22 hours ago

RMF, Security & ATO Manager

Lever 251-1K Professional Services

Latitude IT Solutions is hiring an RMF, Security & ATO Manager to own compliance and authorization for a complex, multi-tenant VA health IT platform.

DevSecOps HIPAA
4 days, 22 hours ago

Business Information Security Officer - Remote/Defense Industrial Base (DIB) Exp

EVOTEK 51-250 IT Services

EVOTEK is hiring a Business Information Security Officer to help lead and evolve the company’s security strategy across business, technology, and compliance initiatives for client-facing operations.

Cybersecurity
4 days, 22 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers