Senior Red Team Engineer
Indexed description
Journey with us! Combine your career goals and sense of adventure by joining our exciting team of employees. Royal Caribbean Group is pleased to offer a competitive compensation and benefits package, and excellent career development opportunities, each offering unique ways to explore the world.
We are proud to be the vacation-industry leader with global brands — including Royal Caribbean International, Celebrity Cruises and Silversea Cruises — the most innovative fleet and private destinations, and the best people. Together, we are dedicated to turning the vacation of a lifetime into a lifetime of vacations for our guests.
Position Summary
The Senior Red Team Engineer will serve as a technical authority within the Cyber Security Counter Threat Management function, leading advanced red team and adversary emulation engagements that stress-test the organization's defenses against sophisticated attack scenarios. This role requires deep offensive security expertise across cloud, identity, network, and endpoint environments, leveraging advanced tradecraft to identify security gaps and drive meaningful risk reduction. As a senior member of the Cyber Security Counter Threat Management team, this individual will partner closely with cybersecurity and technology teams to enhance detection capabilities, strengthen defensive strategies, and improve the organization's overall cyber resilience. The ideal candidate combines hands-on offensive security expertise with the ability to mentor others, influence security strategy, and communicate effectively with both technical and executive stakeholders.
Senior Red Team Engineer
(Posted as Senior Engineer, Cyber Security Counter Threat Management at rcgcareers.com)
- The position is onsite and based in Miramar, Florida.
- The position is also not eligible for work authorization sponsorship.
Essential Duties and Responsibilities
- Lead advanced red team operations and adversary emulation exercises designed to assess and challenge the organization's security posture.
- Simulate real-world attack scenarios across cloud, identity, endpoint, network, and application environments.
- Conduct threat-led security assessments using current intelligence, attacker tactics, techniques, and procedures (TTPs).
- Develop custom tools, payloads, and automation to support offensive security operations and security validation activities.
- Assess the effectiveness of security controls, detection mechanisms, and response capabilities across enterprise systems.
- Partner with Detection Engineering, SOC, Incident Response, and Infrastructure teams to improve visibility, monitoring, and response effectiveness.
- Facilitate purple team engagements to validate detections and continuously enhance defensive capabilities.
- Perform phishing, credential attack, and social engineering simulations to evaluate organizational readiness.
- Research emerging threats, attack methodologies, and vulnerabilities to ensure testing methodologies remain current and effective.
- Translate technical findings into actionable recommendations for both technical stakeholders and executive leadership.
- Establish operational standards, methodologies, and best practices for offensive security engagements.
- Mentor team members and provide technical leadership on red team methodologies, tooling, and adversary simulation strategies.
Qualifications, Knowledge and Skills
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline; equivalent experience considered.
- 7+ years of cybersecurity experience with significant expertise in red teaming, adversary emulation, penetration testing, or offensive security operations.
- Demonstrated experience leading large-scale offensive security engagements in complex enterprise environments.
- Expert understanding of the MITRE ATT&CK framework, adversary behaviors, and modern attack methodologies.
- Strong experience conducting assessments across Microsoft Azure, AWS, Active Directory, Entra ID, Windows, Linux, and hybrid environments.
- Hands-on expertise with offensive security tooling such as Cobalt Strike, Mythic, Sliver, BloodHound, Impacket, Burp Suite, and similar platforms.
- Advanced scripting and development skills using Python, PowerShell, C#, Go, or comparable languages.
- Strong understanding of security monitoring technologies, EDR/XDR platforms, and techniques used to evaluate detection effectiveness.
- Experience with phishing campaigns, social engineering assessments, and initial-access attack simulations.
- Ability to communicate highly technical concepts to both technical and non-technical audiences.
- Excellent analytical, problem-solving, and risk assessment skills.
- Experience mentoring security professionals and driving technical excellence within a team environment.
- Preferred certifications include OSEP, OSCE3, CRTO, CRTL, GXPN, GPEN, or OSCP.
Agency and Third-Party Submissions: Please note this is a direct search by the Company, and applications through agencies and other third parties will not be accepted, nor will fees be paid for unsolicited resumes. Any unsolicited resumes will be considered the Company's property.
We know there's a lot to consider. As you go through the application process, our recruiters will be glad to provide guidance, and more relevant details to answer any additional questions. Thank you again for your interest in Royal Caribbean Group. We'll hope to see you onboard soon!
It is the policy of the Company to ensure equal employment and promotion opportunity to qualified candidates without discrimination or harassment on the basis of race, color, religion, sex, age, national origin, disability, sexual orientation, sexuality, gender identity or expression, marital status, or any other characteristic protected by law. Royal Caribbean Group and each of its subsidiaries prohibit and will not tolerate discrimination or harassment.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search