Kroll
Red Team Operator
Remote, United States· REMOTE
About the role
You plan and execute multi-week engagements that emulate how a real attacker would operate against the organisation, working towards defined objectives rather than a checklist. The defensive team is actively monitoring, so a significant part of the work is maintaining access and progressing quietly once they begin investigating. Every engagement ends with a joint debrief covering what was achieved and what was detected.
What you will do
- Plan operations against defined objectives, not a checklist
- Build and maintain the tooling the operation needs
- Debrief the defenders honestly, including what they caught
What they ask for
- Several years of offensive work with references
- Comfortable writing your own tooling rather than running someone else's
- Understands modern detection well enough to plan around it
Nice to have
- OSEP or CRTO
- Published tooling
- Physical or social assessment experience
What applying with Rooted means
This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.
Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.
You can read this role without an account. To apply you need a Rooted credential.
This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is Kroll. Confirm the final details with the original source or during the application process.
Posted 2026-08-13