Senior Red Team Security Engineer
WellSky · Overland Park
Job description
About the role
We are looking for a Senior Red Team Security Engineer to lead offensive security engagements at WellSky. The role combines hands‑on red‑team operations, security architecture, and mentorship to strengthen our enterprise, cloud, and application defenses.
Key responsibilities
- Design, scope, and execute red‑team engagements and adversary‑emulation exercises across on‑premise systems, cloud environments (AWS, Azure, GCP), and applications, collaborating with detection engineering to remediate gaps.
- Lead the implementation and enhancement of security controls, system hardening, monitoring, vulnerability assessment, incident response, and disaster‑recovery processes while enforcing a secure software development lifecycle.
- Develop and enforce security controls in colocation and cloud environments in alignment with WellSky policies.
- Analyze technical requirements, recommend solutions, and ensure compliance with industry standards and regulatory frameworks.
- Provide technical guidance to development and IT teams to foster secure software design and deployment.
- Participate in security incident response activities, including detection, containment, resolution, and escalation.
- Serve as subject‑matter expert for security tools such as SIEM, DLP, EDR, SAST, and SCA, optimizing configurations and workflows.
- Leverage AI tools and platforms to improve decision‑making, streamline workflows, and drive data‑informed outcomes.
- Perform other duties as assigned.
Required profile
- Bachelor’s degree in a related field or equivalent work experience.
- 4–6 years of relevant experience, including at least 2 years in an offensive security role (penetration testing, red teaming, adversary emulation, or purple teaming).
- Hands‑on experience executing the full attack lifecycle – reconnaissance, initial access, privilege escalation, lateral movement, persistence, and data exfiltration – against enterprise networks, cloud platforms, and web applications.
- Working knowledge of the MITRE ATT&CK framework for planning engagements and mapping findings.
- Proven ability to communicate technical findings and business risk to engineering teams and executive leadership.
Required skills
- Offensive tools: Burp Suite, Nmap, Metasploit, BloodHound, Impacket.
- Command‑and‑control frameworks: Cobalt Strike, Sliver, Mythic.
- Cloud attack and defense experience in AWS, Azure, and GCP (IAM abuse, misconfiguration exploitation, cloud‑native logging and controls).
- Security platforms: SIEM, DLP, EDR, SAST, SCA.
- MITRE ATT&CK framework.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 7 hours ago
Expires 1 month from now
2 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
WellSky
Overland Park
Related job offers
-
Full Stack Java Developer – Overland Park, KS
Infosys Overland Park -
Full Stack Java Developer
Infosys Overland Park -
Project Manager – LATAM Nearshore (English Required)
DaCodes. Uruguay -
Technology Support Specialist I
MANTECA UNIFIED SCHOOL DISTRICT School -
DevOps Engineer – Alpharetta, GA
Infosys Alpharetta