Managing Principal, Red Team Operator

Armadin
  • Palo Alto, California
    11 days ago

    Job Description

    About Us

    At Armadin, we're a group of engineers, researchers, and hackers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on.

    We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite red teamers into purpose-built security models and agents that discover risk and remediate it before organizations are breached.

    Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, and MIT to reinvent security for an adversary that never sleeps.

    Role Overview

    The Managing Principal Red Team Operator is a senior technical leadership role for an experienced offensive security professional who combines deep expertise across application and network security with the ability to mentor, influence, and shape Armadin's technical strategy. This is not a team-building role — you will manage a small number of existing red team operators, providing mentorship and strategic direction while maintaining your own high-impact delivery across complex, multi-disciplinary engagements.

    You will be a thought leader within Armadin and across the industry, driving innovation in adversarial methodology, tool development, and the integration of AI into red team operations. Beyond leading engagements, you will work closely with product engineering teams — both remotely and onsite — to ensure Armadin's platform and capabilities incorporate the full spectrum of red team tradecraft and real-world adversarial complexity.

    This role requires the ability to think strategically about offensive security across multiple attack surfaces (application, network, infrastructure, cloud, identity), execute at the highest technical level, articulate complex concepts to leadership and product teams, and elevate the skill and impact of your peers.

    What You’ll Do

    Technical Leadership & Delivery

    • Lead and execute sophisticated multi-disciplinary red team engagements spanning application security, network penetration testing, cloud infrastructure, and identity systems — combining expertise across attack vectors into cohesive, high-impact campaigns.

    • Identify novel attack chains and weaknesses that transcend traditional security boundaries, conducting source code review, network analysis, binary reverse engineering, and infrastructure assessment in concert to uncover business-critical security gaps.

    • Develop comprehensive, technically rigorous reports and executive briefings that translate complex offensive findings into clear remediation roadmaps and risk narratives for both technical and non-technical stakeholders.

    • Conduct advanced threat analysis and intelligence gathering to understand the full attack landscape of enterprise environments, including adversarial TTPs, business risk, and compliance implications.

    Team Leadership & Mentorship

    • Mentor and manage a small team of red team operators, providing technical guidance, code reviews, methodology coaching, and career development while maintaining high standards of operational security and impact.

    • Share tradecraft, tool development insights, and lessons learned from complex engagements to elevate team capability and establish Armadin as a center of offensive security excellence.

    • Conduct capability assessments, skill development planning, and strategic feedback with team members to ensure continuous improvement and clear growth trajectories.

    Strategic Innovation & Product Collaboration

    • Work closely with product engineering and AI teams — including onsite collaboration — to translate red team needs, methodologies, and adversarial insights into platform capabilities, tool integrations, and AI-driven attack simulations.

    • Serve as the voice of offensive security tradecraft in product strategy discussions, ensuring platform development prioritizes real-world attack complexity and operator efficiency.

    • Lead research initiatives into emerging attack vectors, exploitation techniques, AI-augmented adversarial methodologies, and novel tools to maintain Armadin's position at the forefront of offensive security.

    • Develop and contribute to open-source tooling, proprietary frameworks, and methodologies that enhance Armadin's capabilities and influence the broader security community.

    Industry & Internal Leadership

    • Represent Armadin as a thought leader in offensive security through conference talks, published research, security community engagement, and technical leadership.

    • Interface directly with executive leadership and client C-suite to communicate strategic security findings, risk narratives, and business-level implications.

    • Contribute to hiring, interviewing, and technical assessment of prospective red team operators to build world-class offensive security talent.

    What You’ll Bring

    Experience & Expertise

    12+ years of hands-on offensive security experience, including extensive depth in multiple disciplines:

    • Advanced web application penetration testing and secure code review (OWASP Top 10, business logic flaws, authentication/authorization bypass, API security, control flow analysis)

    • Network penetration testing, Active Directory attacks, lateral movement, privilege escalation, and persistence operations across enterprise infrastructure

    • Mobile application security assessments, thick/thin client reverse engineering, and binary analysis across platforms (iOS, Android, Windows, macOS, Linux)

    • Cloud infrastructure security, identity systems (Kerberos, SAML, OAuth), and multi-cloud red team operations

    • Demonstrated ability to integrate findings across multiple attack surfaces into comprehensive, strategic offensive campaigns

    Technical Proficiency

    • Expert-level proficiency with offensive security tools across multiple domains (Burp Suite, OWASP ZAP, Caido, Nmap, Metasploit, Cobalt Strike, Impacket, BloodHound, Responder, CrackMapExec, Frida, Ghidra, IDA Pro, etc.)

    • Advanced scripting and tool development in Python, Bash, PowerShell, or compiled languages; ability to extend C2 frameworks, develop custom exploits, and create application-specific tooling

    • Deep understanding of network protocols, packet-level analysis, cryptography, system architecture (Windows, Unix/Linux, cloud platforms), and application design patterns

    • Proficiency in multiple operating systems and platforms (Windows, Linux, macOS), container technologies, and cloud environments (AWS, Azure, GCP)

    Leadership & Communication

    • Proven ability to mentor, lead, and develop technical talent; demonstrated impact on team capability and organizational growth

    • Exceptional written and verbal communication skills — capable of translating complex technical concepts for executive leadership, product teams, and diverse client audiences

    • Strategic thinking and the ability to align technical initiatives with business objectives; experience influencing product roadmaps or organizational strategy

    • Independent judgment, intellectual curiosity, and the ability to rapidly assimilate new information to make time-sensitive decisions in ambiguous situations

    Requirements

    • Must be eligible to work in the United States without sponsorship

    • Willingness to work onsite in our Palo Alto, CA office to collaborate with product engineering teams, support complex engagements, and participate in strategic initiatives

    Even Better With

    • Prior experience working alongside AI/ML models, automated offensive security frameworks, or building AI-augmented attack tools

    • Published research, conference speaking, or significant open-source contributions in offensive security

    • Experience in startup or high-growth environments; demonstrated ability to wear multiple hats and drive initiatives with minimal bureaucracy

    • Advanced certifications: OSCP, OSCE, CRTE, CRTO, or equivalent elite-level credentials

    • Track record of building offensive security tools or frameworks adopted by the community

    • Experience leading or mentoring red team programs within large enterprises

    Location

    Onsite in Palo Alto, CA

    Benefits & Perks

    Full Health, Dental, & Vision Coverage

    Meaningful Equity Ownership

    In-Office Meals

    ️ Haircuts at the Office
    Company Sponsored Conferences & Events

    401(k), HSA, and FSA Plans

    Flexible PTO

     

    Numbers & Facts

    LocationPalo Alto, California
    Websitehttps://www.armadin.com/careers

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Androidunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Bash Scriptingunmatched
    • Business Strategyunmatched
    • Campaignsunmatched
    • Career Counselingunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Compiled Programming Languagesunmatched
    • Computer Hackingunmatched
    • Conferencesunmatched
    • Continuous Improvementunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Design Patterns Programming Methodologiesunmatched
    • Develop Methodologiesunmatched
    • Establish Prioritiesunmatched
    • GCP (Good Clinical Practices)unmatched
    • IDA Prounmatched
    • Intelligence Gatheringunmatched
    • Kerberosunmatched
    • Leadershipunmatched
    • Linux Operating Systemunmatched
    • Mac Operating Systemunmatched
    • Machine Toolunmatched
    • Mentoringunmatched
    • Metasploitunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Mobile Applicationsunmatched
    • Multiplatform/Cross-Platformunmatched
    • NMapunmatched
    • Network Performance/Analysisunmatched
    • Network Protocolsunmatched
    • Network Securityunmatched
    • Network Testingunmatched
    • OAuthunmatched
    • Open Sourceunmatched
    • Operating Systemsunmatched
    • Operations Security (OPSEC)unmatched
    • Penetration Testingunmatched
    • Presentation/Verbal Skillsunmatched
    • Product Engineeringunmatched
    • Product Planningunmatched
    • Product Strategyunmatched
    • Python Programming/Scripting Languageunmatched
    • Reverse Engineeringunmatched
    • Riskunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Assertion Markup Language (SAML)unmatched
    • Security Attacksunmatched
    • Software Designunmatched
    • Startupunmatched
    • Strategic Planningunmatched
    • System Architectureunmatched
    • Talent Managementunmatched
    • Team Lead/Managerunmatched
    • Technical Analysisunmatched
    • Technical Deliveryunmatched
    • Technical Leadershipunmatched
    • Technical Strategyunmatched
    • Thick Clientunmatched
    • Thin Clientsunmatched
    • Thought Leadershipunmatched
    • Truck Driverunmatched
    • Unix Operating Systemsunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched
    • iOSunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder