Red Team Security Consultant, Mandiant, Google Cloud

Posted today

compliancepointLos Angeles (CA)

SENIORITY

Senior

SALARY

$112,000 - $161,000 per year

Apply

About the role

Mandiant Red Team Consulting Team MemberAs a Mandiant Red Team Consulting team member, you will be responsible for assessing and advising clients on both technical and process-based controls for all manner of environments. You will perform Red and Purple Team assessments, including adversarial emulation of cyber attacks against customer organizations, and other technical cyber assessments including external pen testing, web application, mobile, and wireless security testing. You will expand the team's capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations, and knowledge sharing. Mandiant's Red Team delivers intelligence-driven adversarial emulation that mirrors real-world cyber threats. Operating covertly and with zero prior knowledge of an environment, our experts simulate the full lifecycle of a targeted attack. From initial social engineering and perimeter breaches to stealthy lateral movement, objective hunting, and data exfiltration, we challenge security teams to detect and neutralize a sophisticated adversary before an actual breach occurs. Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone. Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $112000 - $161000 (USD) + 15% bonus target + equity + benefits.
Responsibilities: Perform red and purple team assessments, assumed breach assessments (e.g., red team engagements with a pre-deployed implant), ransomware readiness reviews (e.g., assessing susceptibility to modern ransomware threats), threat analysis, and social engineering assessments. Conduct external and internal wireless assessments, web and mobile applications testing, and embedded system assessments. Recognize and safely utilize attacker tools, tactics, and procedures. The application window will be open until at least September 23, 2026. This opportunity will remain online based on business needs which may be before or after the specified date. This role may also be located in our Playa Vista, CA campus. San Francisco/Los Angeles applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the San Francisco/Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Los Angeles, CA, USA; Boulder, CO, USA; San Francisco, CA, USA.
Minimum qualifications: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.3 years of experience with pen testing and red teaming functions, including network, web application, mobile, cloud, social engineering, scripting, or tool development. Experience with tools used for wireless, web application, and network security testing. Ability to travel up to 30% of the time.
Preferred qualifications: Certifications related to offensive security including OSCE, OSEP, OSEE, OSCP, CCSAS, CCT, INF, or relevant SANS courses. Experience implementing or assessing information security implementation or assessment of security controls. Experience working collaboratively with Blue Teams, SOCs, or utilizing SIEM/EDR technologies. Proficiency in Python, Go, C#, C++, or C for tool development and automation.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this