Resource Management Concepts
Posted 3d ago

Security Engineer - Red Team (Offensive Security)

Resource Management Concepts
Quantico, Virginia, United States
$150k-$165k/yrOnsiteFull Time
Responsibilities
  • executing operations
  • exploiting vulnerabilities
  • producing findings
Requirements
  • Requires 5 years of cybersecurity experience
  • TS/SCI eligibility
  • DoD 8570 IAT III
  • CSSP Auditor, and DCWF 541 certifications
  • Plus Windows, Linux
  • Networking, and enterprise services knowledge
Technical tools mentioned
WindowsLinuxActive DirectoryAWSAzureGCPCC++Industrial Control Systems (ICS)Internet of Things (IoT)

Job description

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.

We are seeking a highly skilled Cyber Security Engineer – Red Team (Offensive Security) – to join our Cyber Defense Team in Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security. You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.

The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.

Requirements

Responsibilities

● Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.

● Identify and exploit network, host, and application-level vulnerabilities.

● Develop and refine proof-of-concept exploits and techniques to test defensive measures.

● Produce detailed technical findings and recommendations for remediation.

● Collaborate with defensive and engineering teams to improve detection and response.

● Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.

● Participate in after-action reviews and contribute to policy and playbook updates.

● Prepare, update, document, and present course materials that cover TTPs.

● Provide support required to maintain the customer’s Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.

● Considerable travel.

Minimum Qualifications

● TS/SCI eligibility

● 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).

● Possess and maintain a DoD 8570 IAT Level III certification: SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP.

● Possess and maintain a DoD 8570 CSSP Auditor certification: CySA+, CEH, CISA, GSNA, CFR, PenTest.

● Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements: CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA.

● Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active Directory).

● Once placed in this role, candidates must pass the customer's Red Team Operations Course (RTOC) at the Red Team Certified Professional (RTCP) level. Upon the first attempt of the RTOC, the placed candidate must achieve the initial minimum requirement of Red Team Associate (RTA). Achieving a minimum RTA qualification will afford the placed candidate a second attempt at the RTOC to achieve the RTCP certification.

Preferred Qualifications

● Experience with any of the following:

  • AV/EDR evasion and detection-bypass techniques.
  • Custom tooling, payload or, command-and-control (C2) development.
  • Software development in C, C++, or a similar language.
  • Malware analysis and reverse engineering.
  • Cloud platforms and services (AWS, Azure, GCP).
  • Physical security assessments or red-team intrusion exercises.
  • Industrial control systems (ICS) and Internet of Things (IoT) environments.

● Offensive-security certifications such as OSCP, OSEP, OSCE, CRTO. CRTL, GXPN.

Benefits

At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.

RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.

Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $150,000 to $165,000 (annually).

#LI-LL1

About Resource Management Concepts

Delivering Mission-Focused IT & Cybersecurity Solutions

Similar jobs

Security Engineer roles near Quantico, Virginia
1d
Save
Mark Applied
Hide
Sr. Security Engineer
Washington, District of Columbia, United States
$120k-$150k/yr OnsiteFull Time
Halvik
Halvik: Technology services modernizing and securing mission-critical systems for U.S. federal agencies.
8+ YOEBachelor's degree in a related field, 8+ years of cybersecurity experience, Azure security expertise, CISSP or equivalent certification, cloud certification, and active Secret clearance.
Microsoft Azure, Azure Kubernetes Service (AKS), Azure Policy, Azure Active Directory (Azure AD), Entra, Conditional Access, Role-Based Access Control (RBAC), Zero Trust, NIST, FISMA, FedRAMP, NIST SP 800-53
1d
Save
Mark Applied
Hide
Senior Security Engineer
Washington, District of Columbia, United States
$102k-$132k/yr OnsiteFull Time
Diné Development Corporation
Diné Development Corporation: Navajo Nation-owned government contractor providing IT, engineering, professional, and environmental services to public-sector agencies.
8+ YOERequires 8+ years of cybersecurity experience, a bachelor's degree in a technical field, Secret clearance, Security+ or CISSP, cloud certification, and experience securing Azure services and Zero Trust controls.
Microsoft Azure, NIST, FISMA, FedRAMP, AKS, Azure Policy, Azure AD/Entra, Conditional Access, RBAC, Zero Trust
1d
Save
Mark Applied
Hide
Sr Security Engineer, Supply Chain, Leo Security
Arlington or Herndon or Bellevue or Seattle
$178k-$227k/yr FieldFull Time
Kuiper Systems
Kuiper SystemsNasdaq Global Select Market: AMZN: Developing a low Earth orbit satellite network to deliver high-speed, low-latency broadband internet connectivity.
5+ YOERequires 5+ years in security engineering, assessments, or operations; experience identifying risks, developing mitigations, conducting cybersecurity and physical security assessments, and applying security frameworks.
NIST 800-53, NIST 800-161, ISO 27001, NIST 800-171, NISTIR 8276, FAR/DFARS, CMMC, ITAR/EAR, OT/ICS
2d
Save
Mark Applied
Hide
Lead Security Engineer, GRC
Boston or Costa Mesa or Seattle or Washington
$166k-$253k/yr OnsiteFull Time
Anduril Industries
Anduril Industries: Defense technology developing AI-powered autonomous military systems.
6+ YOE6+ years in security engineering or GRC, programming and automation experience, compliance framework expertise, cloud and SaaS integrations, infrastructure as code, technical leadership, and eligibility for a U.S. Secret clearance.
Go, Python, Rust, Terraform, AWS CDK, Vanta, Drata, Hyperproof, OneTrust, Kubernetes
2d
Save
Mark Applied
Hide
Security Engineer (Active Top Secret Clearance Required)
Washington, District of Columbia, United States
HybridFull Time
Clear Creek Federal
Clear Creek Federal: A federal government contracting business serving civilian, defense, and intelligence community customers.
Requires U.S. citizenship, active Top Secret clearance, cybersecurity expertise, RMF, SCM, IDS/IPS, firewall, vulnerability assessment, Windows AD, encryption, and security assessment experience.
Risk Management Framework (RMF), Tripwire, CyberArk, Security Configuration Management (SCM), Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Windows, Active Directory (AD), Network Access Control (NAC)
3d
Save
Mark Applied
Hide
ConMon Security Engineer
Tysons, Virginia, United States
$135k-$155k/yr OnsiteFull Time
Telos Corporation
Telos CorporationNasdaq: TLS: Public U.S. cybersecurity providing cyber-risk, cloud, identity, biometric, and secure-network solutions to government and commercial customers.
Bachelor's degree or equivalent experience, 5+ years in IT, US citizenship, active Top Secret clearance, DoD 8140 compliance, ConMon and eMass expertise, cloud security, automation, and stakeholder management skills.
eMass, Tenable, Qualys, Python, SQL, NIST SP 800-53 Rev 5
4d
Save
Mark Applied
Hide
Senior Security Engineer
Washington, District of Columbia, United States
$160k-$190k/yr OnsiteFull Time
Evolver
Evolver: Cybersecurity and digital transformation serving federal agencies and commercial enterprises with IT, AI, and technology services.
10+ YOERequires a bachelor's degree or equivalent experience, 10 years of enterprise IT experience including 5 years on large government contracts, CISSP with ISSEP, ITIL 4 Foundation, and U.S. citizenship.
AWS GovCloud, Azure Government, SIEM, SOAR, EDR, Splunk, Elastic, Cortex XSOAR, CrowdStrike, Microsoft Defender, AWS, Azure, GCP, Kubernetes, Docker, RMF, NIST 800-series, TIC 3.0, DevSecOps, CI/CD, PKI, FISMA, OMB A-130, CDM
4d
Save
Mark Applied
Hide
Senior Security Engineer
Reston, Virginia, United States
$110k-$150k/yr OnsiteFull Time
Chickasaw Nation Industries
Chickasaw Nation Industries: Federally chartered, Chickasaw Nation-owned holding providing federal contracting, manufacturing, and technology services.
Bachelor’s degree and 4 years of relevant experience or equivalent; NIST RMF expertise, technical security assessment skills, documentation proficiency, and ability to obtain and maintain required customer clearance.
NIST, Risk Assessment and Management, Vulnerability Analysis, Configuration Management, Security Assessment Report, POA&M, Continuous Monitoring