JobStar
Solarwinds logo

Senior Red Team Engineer

SolarwindsBangalore, India

Apply on Solarwinds

At SolarWinds, we’re a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure solutions.

The ideal candidate thrives in an innovative, fast-paced environment and is collaborative, accountable, ready, and empathetic. We’re looking for individuals who believe they can accomplish more as a team and create lasting growth for themselves and others. We hire based on attitude, competency, and commitment. Solarians are ready to advance our world-class solutions in a fast-paced environment and accept the challenge to lead with purpose. If you’re looking to build your career with an exceptional team, you’ve come to the right place. Join SolarWinds and grow with us!

Position Overview

We are seeking a highly skilled and hands-on Senior Red Team Engineer to conduct realistic adversary simulations, breach and attack simulations, penetration tests, and phishing assessments across our network, cloud, application, and endpoint environments.

The successful candidate will be responsible for identifying weaknesses in people, processes, technology, and security controls. You will emulate real-world threat actors, validate detection and response capabilities, and work closely with defensive security and DevSecOps teams to improve the organization’s overall security posture.

This is a technical, hands-on role requiring strong experience in network security, phishing operations, attack infrastructure, privilege escalation, lateral movement, and breach and attack simulation.

Key Responsibilities

  • Plan and execute authorized red team operations and adversary emulation exercises.
  • Conduct network, internal, external, wireless, cloud, and application penetration testing.
  • Perform realistic phishing and social-engineering assessments in accordance with approved rules of engagement.
  • Develop and maintain attack infrastructure, including command-and-control environments, redirectors, payload delivery mechanisms, and testing domains.
  • Simulate real-world attack techniques, including:
      - Initial access
      - Credential harvesting and abuse
      - Privilege escalation
      - Active Directory attacks
      - Persistence
      - Lateral movement
      - Defense evasion
      - Data discovery and controlled exfiltration
      - Command and control
  • Perform breach and attack simulation exercises to validate security controls and detection coverage.
  • Assess the effectiveness of endpoint detection and response, SIEM, identity security, email security, network monitoring, and cloud security controls.
  • Use and customize tools such as Cobalt Strike, Mythic, Sliver, Metasploit, Impacket, BloodHound, Burp Suite, Nmap, Responder, and relevant open-source tooling.
  • Create or modify scripts, payloads, exploits, and automation to support authorized engagements.
  • Analyze security monitoring and incident-response activity during exercises.
  • Collaborate with SOC, threat intelligence, incident response, vulnerability management, infrastructure, and DevSecOps teams.
  • Translate technical findings into practical remediation recommendations.
  • Produce detailed technical reports, executive summaries, attack narratives, and remediation plans.
  • Track remediation activities and conduct follow-up validation testing.
  • Contribute to red team playbooks, testing methodologies, detection engineering, and security automation.
  • Follow strict rules of engagement, authorization procedures, safety controls, and responsible disclosure practices.

Required Qualifications

  • 5+ years of hands-on experience in red teaming, penetration testing, offensive security, or adversary emulation.
  • Demonstrable experience conducting full-scope red team engagements from planning through reporting.
  • Strong knowledge of network security and enterprise infrastructure, including:
      - TCP/IP, DNS, HTTP/S, SMTP, VPN, firewalls, proxies, and network segmentation
      - Windows and Linux systems
      - Active Directory, Kerberos, NTLM, LDAP, and Group Policy
      - Identity and access management
      - Endpoint and network security controls
  • Hands-on experience conducting phishing and social-engineering simulations, including campaign planning, payload delivery, landing pages, email security testing, and reporting.
  • Practical experience with breach and attack simulation platforms, attack-path analysis, or continuous security validation.
  • Experience with common red team tactics, techniques, and procedures mapped to the MITRE ATT&CK framework.
  • Strong understanding of:
      - Initial access and execution
      - Credential access
      - Privilege escalation
      - Persistence
      - Defense evasion
      - Lateral movement
      - Command and control
      - Exfiltration and impact techniques
  • Experience bypassing or testing defensive controls such as EDR, antivirus, email gateways, firewalls, web application firewalls, and SIEM detections.
  • Proficiency in at least one scripting or programming language, such as Python, PowerShell, Bash, or C#.
  • Experience using and customizing offensive-security tools and frameworks.
  • Ability to create reliable proof-of-concept exploits and demonstrate business impact safely.
  • Excellent technical writing, communication, and presentation skills.
  • Ability to work independently while collaborating effectively with blue team and engineering teams.
  • Strong understanding of ethical hacking principles, authorization requirements, and rules of engagement.

Preferred Qualifications

  • Experience with cloud red teaming in AWS, Azure, or Google Cloud.
  • Experience testing containerized environments, Kubernetes, CI/CD pipelines, and infrastructure as code.
  • Experience with web and API penetration testing.
  • Experience with mobile, wireless, or physical security assessments.
  • Background in threat intelligence or intelligence-led red teaming.
  • Experience performing purple team exercises and detection validation.
  • Familiarity with security platforms such as Microsoft Sentinel, Splunk, CrowdStrike, Microsoft Defender, Palo Alto Cortex, or similar technologies.
  • Experience developing custom tooling, implants, payloads, or C2 extensions.
  • Knowledge of malware analysis, reverse engineering, exploit development, or vulnerability research.
  • Experience integrating offensive-security testing into DevSecOps and security-development lifecycles.
  • Active security certification such as OSCP, OSEP, OSCE3, CRTO, GXPN, GPEN, PenTest+, or equivalent practical experience.

Hands-On Technical Expectations

The successful candidate should be able to independently:

  • Build and operate a controlled red team infrastructure.
  • Conduct an external attack simulation against approved targets.
  • Perform internal network reconnaissance and Active Directory attack-path analysis.
  • Identify and exploit privilege-escalation opportunities.
  • Execute controlled phishing simulations and assess email-security controls.
  • Demonstrate lateral movement and credential-abuse techniques.
  • Test endpoint, identity, network, and cloud detection capabilities.
  • Use breach and attack simulation tools to validate defensive controls.
  • Develop scripts and tooling to automate reconnaissance, testing, and reporting.
  • Explain the attack path, security impact, detection opportunities, and remediation steps to both technical and executive audiences.

Key Performance Indicators

  • Quality and realism of red team and adversary-emulation exercises.
  • Number and severity of validated security weaknesses identified.
  • Coverage of critical MITRE ATT&CK techniques.
  • Effectiveness of breach and attack simulation activities.
  • Quality and clarity of technical reporting.
  • Improvement in detection and response capabilities.
  • Successful collaboration with blue team, SOC, infrastructure, and DevSecOps teams.
  • Timely completion of remediation validation and retesting.

Education and Certifications

A degree in cybersecurity, computer science, information technology, or a related field is preferred but not required.

Relevant certifications are valued, but practical hands-on capability is more important than certifications. Suitable certifications include:

  • OSCP / OSCP+
  • OSEP
  • OSCE3
  • CRTO / CRTP
  • GXPN
  • GPEN
  • PNPT
  • CISSP, for candidates with relevant practical experience

Important Candidate Profile

The ideal candidate is not limited to running automated vulnerability scanners or producing checklist-based penetration-test reports. They must be capable of thinking and operating like a real-world threat actor while maintaining disciplined authorization, safety, and documentation throughout the engagement.

They should demonstrate practical experience with network attacks, phishing operations, Active Directory, credential abuse, privilege escalation, lateral movement, command-and-control infrastructure, breach and attack simulation, and security-control validation.

SolarWinds is an Equal Employment Opportunity Employer. SolarWinds will consider all qualified applicants for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, marital status, disability, veteran status or any other characteristic protected by law.

All applications are treated in accordance with the SolarWinds Privacy Notice: https://www.solarwinds.com/applicant-privacy-notice

Apply for this role