Haystack
← Back to Jobs
Remote
Technology
IN

Red Team Operator/Consultant

InterSec Inc.United States🇺🇸United StatesPosted Sep 23, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
19 hours ago
MFAHelp DeskLESSPenetration Testing

Job Description

Red Team / Social Engineering Operator (Freelance, Remote)

Client: InterSec, Inc., subcontract support for a government cybersecurity assessment program

Engagement type: Project based freelance, 1099 or corp to corp

Location: Fully remote, U.S. based required

Assignments: Two Atlanta jurisdiction engagements (Jurisdiction A and Jurisdiction B), additional assignments possible

 

The Work

InterSec holds a multi jurisdictional penetration testing contract with a regional government authority in the Atlanta, Georgia area. We need an experienced social engineering operator to execute authorized Red Team engagements against two jurisdictions under signed Rules of Engagement.

This is adversarial emulation of real attacker tradecraft, specifically the help desk account takeover pattern used by threat actors like Scattered Spider, the group behind the MGM Resorts and Caesars Entertainment intrusions. It targets a government workforce's identity verification and account recovery controls. All work stops at proof of compromise. No credential obtained is ever used, and no account or system is accessed once control is demonstrated.

 

Scope of Work

   OSINT reconnaissance. Build target profiles for named employees and departments from public sources, without privileged access.

   Phishing and spear phishing (email). Credential harvesting campaigns against named roles, using benign landing pages that log outcomes only. No live malware.

   Vishing (voice). Pretext calls against IT help desk functions to test password reset, MFA enrollment, and account recovery verification. Primary technique across both assignments.

   Whaling and spear phishing against executive leadership, tuned from OSINT, where authorized.

   Smishing (SMS), where authorized, to test MFA fatigue and reset flow susceptibility.

   Map every technique to its MITRE ATT&CK identifier (for example T1566, T1598, T1621, T1556, T1078) for the final report.

   Operate under a named client control group for continuous deconfliction. Pause immediately on request.

   Document findings with severity, evidence, and remediation guidance in a report for technical and executive audiences.

Note: the two assignments differ. Jurisdiction A is vishing only. Jurisdiction B covers phishing and vishing, with spear phishing, whaling, and smishing authorized under contract but not currently active. Comfort working within a tightly bounded, written scope is essential.

 

Required Qualifications

   5+ years of hands on red team, social engineering, or offensive security experience. A strong documented portfolio, CTF results, published case studies, lab work, will be considered in place of formal years.

   Demonstrated experience planning and executing vishing campaigns against a corporate or institutional target, specifically help desk pretexting.

   Working knowledge of MITRE ATT&CK and the ability to map executed techniques accurately.

   Strong written English. Deliverables are formal reports read by government client leadership.

   Comfortable working to a signed, bounded Rules of Engagement with hard constraints (approved hours, prohibited pretexts, named exclusions) and immediate stand down authority.

   Legally authorized to work in the U.S. and able to pass a basic background check.

 

Certifications

Minimum one required, or clearly equivalent demonstrated skill:

   OSCP (Offensive Security Certified Professional)

   GPEN (GIAC Penetration Tester)

   CRTO (Certified Red Team Operator, Zero Point Security)

   PNPT (Practical Network Penetration Tester, TCM Security)

A named certification matters less than a track record of real vishing and pretexting work.

 

Logistics

   Remote, U.S. hours, Eastern Time preferred. Engagement dates set per assignment; Jurisdiction A runs weekdays, business hours only.

   Paid per engagement, rate discussed based on scope and experience. All work performed under InterSec's signed Rules of Engagement, no activity outside the authorized scope, target list, or window, under any circumstance.

Similar jobs