AYN

Red Team Operator, Operational Technology (OT)

Armadin · Remote · remote

About Us

At Armadin, we're a group of engineers, researchers, and security researchers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on.

We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite security practioners into purpose-built security models and agents that discover risk and remediate it before organizations are breached.

Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, Georgia Tech, Waterloo, Berkeley, and MIT to reinvent security for an adversary that never sleeps.

Role OverviewAs an Operational Technology (OT) Red Team Operator, you will conduct adversary-focused offensive operations in highly sensitive Operational Technology (OT), Critical Infrastructure, and converged enterprise environments where the margin for error is zero. Modern OT environments do not exist in isolation; they are deeply interconnected with corporate networks, Active Directory, cloud systems, and specialized web/thick-client software management layers. These engagements are designed to simulate complex, multi-stage real-world attacks spanning the entire attack surface—from enterprise network perimeters down to cyber-physical and industrial control systems.

This role requires far more than executing automated scanners—you will analyze environments holistically, discover complex attack paths across network boundaries and applications, and operate with discipline, creativity, and intent. You will emulate motivated threat actors by chaining application vulnerabilities, Active Directory misconfigurations, network trust relationships, and protocol weaknesses to achieve operational objectives while minimizing detection and ensuring process safety.

Beyond direct engagement work, you will partner closely with internal engineers and researchers to help define, build, and test adversarial evaluations that model real attacker behavior across OT, network, and application domains. You will translate engagement outcomes—such as complex kill chains, privilege escalation techniques, and custom operational tradecraft—into structured inputs that support the training and validation of AI systems intended to learn how to plan, execute, and reason about offensive operations at scale. This role plays a direct part in shaping how cross-domain offensive expertise is captured, operationalized, and automated.

What You'll Do- Execute Cyber-Physical & Converged Penetration Tests: Plan and execute semi-automated and manual red team operations across sensitive OT environments (e.g., ICS, SCADA, DCS, BMS, IIoT, Embedded Systems) where testing requires human expertise and judgement to maintain safety, process integrity, and uptime.

- Exploit Multi-Domain Attack Surfaces: Identify and exploit weaknesses across converged IT, network, application, and OT layers including:

- OT services and industrial protocols (e.g., Modbus, DNP3, EtherNet/IP, Profinet).

- Active Directory attacks (Kerberoasting, pass-the-hash, BloodHound enumeration, domain trust abuse) to pivot laterally from corporate networks into OT control zones.

- OT software applications, engineering workstations, embedded web applications, and management APIs (OWASP Top 10, logic flaws, insecure authentication).

- Container technologies, virtualization, and edge computing layers supporting modern industrial architectures.

- Certificate services, PKI infrastructure abuse, and network perimeter controls (firewalls, VPNs, jump boxes).

- Adversary Emulation & Post-Exploitation: Conduct stealthy lateral movement, privilege escalation, and persistence activities while evading EDR, SIEM, and network monitoring solutions across segmented network zones.

- Maintain Operational Security & Infrastructure: Deploy and operate covert command-and-control (C2) infrastructure (Cobalt Strike, Sliver, Mythic, custom frameworks) while practicing strict attribution management, infrastructure isolation, and network OPSEC.

- Custom Tooling & Exploit Development: Develop scripts, proof-of-concept exploits, and custom plugins (Python, PowerShell, Go, C/C++) to manipulate proprietary network protocols, reverse engineer thick clients, or bypass specialized safety/security controls.

- Operational Discipline: Demonstrate meticulous operational discipline, including rigid scope adherence, cleanup, evidence handling, and time management across concurrent engagements.

- Reporting & Stakeholder Communication: Produce actionable, technical reports and present findings to plant managers, engineering teams, CISOs, and executive leadership, clearly articulating exploitable risk vs. theoretical risk.

- AI Safety & Guidance: Define the reasoning paths, protocol logic, and strict "No-Go" parameters that our AI models use to navigate sensitive industrial networks, serving as the ultimate safety guardrail for autonomous operations.

What You'll Bring- Hands-on experience in offensive security with a primary focus on OT/ICS/SCADA, combined with strong competency in network or application penetration testing. Including technical knowledge of industrial protocols (Modbus, DNP3, EtherNet/IP, Profinet, OPC UA) and the ability to perform manual packet manipulation, traffic analysis, and firmware/embedded software assessments.

- Additionally, you bring hands-on experience in at least one of the following areas:

- Network & Active Directory Security: Proven experience with enterprise network exploitation, including Active Directory kill chains (Kerberoasting, BloodHound, delegation abuse, forest trusts), network device manipulation (routers, firewalls, VPNs), and covert communication channels across segmented environments (Purdue Model).

- Application Security: Proven experience with web application security testing methodologies (OWASP Top 10, business logic flaws, authentication/authorization bypass, injection attacks, API security).

- Systems & Automation: Strong operating system fundamentals (Linux, Windows) and proficiency in scripting/programming in at least one language (Python, Go, PowerShell, Bash, or C/C++) to modify or extend offensive tooling.

- Risk Contextualization: Ability to quantify exploitability and impact in a way that balances cyber risk with operational safety and uptime requirements.

- Communication: Exceptional technical writing and verbal skills to communicate with both plant engineers and C-level executives.

- Work Authorization: Must be eligible to work in the United States without sponsorship.

Even Better With- OT/ICS Certifications: GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), GCIP (GIAC Critical Infrastructure Protection), or equivalent.

- Specialized Experience: On one or more of the following: Mobile application testing, source code reviews, reverse engineering, embedded device testing, encryption/decryption, packet analysis, and covert communication channels

- Network & Offensive Security Certifications: OSCP, OSEP, CRTO/CRTE (Certified Red Team Operator/Expert), CPTS, or PNPT.

- AppSec Certifications: GWAPT, eWPTXv2, OSWE, CWES, or TCM Practical Web/Mobile Pentest.

- Tooling & AI Focus: Experience developing custom C2 modules/extensions, or interest/experience in how LLMs and agentic AI workflows apply to offensive security operations.

- Background: Prior experience within specialized government offensive units, top-tier offensive security consultancies, or Fortune 500 red teams with operational technology scope.

Location

Remote within the United States

Benefits & Perks | FTE

🏥 Full Health, Dental, & Vision Coverage

📈 Meaningful Equity Ownership

🥙 In-Office Meals

✂️ Haircuts at the Office

🎉 Company S

Apply on the employer’s site