Full-Time

Operational Technology Red Team Operator

Operational Technology, Operational Technology

Armadin

Armadin

51-200 employees

AI-native platform for proactive cyber defense

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Remote within the United States; must be authorized to work in the United States without sponsorship.

Category
IT & Security (1)
Required Skills
PowerShell
Bash
Kubernetes
Python
LDAP
Computer Networking
Docker
Go
C/C++
Linux/Unix

Get referred to Armadin

Find people who can refer or advise you

Requirements
  • Ability to clearly communicate with OT stakeholders in a manner that builds relationships and trust.
  • Demonstrated experience in offensive security with a focus on OT/ICS/SCADA/Embedded Systems.
  • Knowledge of automation and control systems and a Linux terminal.
  • Deep technical knowledge of industrial protocols (Modbus, DNP3, Ethernet/IP, Profinet) and the ability to perform manual packet manipulation.
  • Deep understanding of networking and operating system fundamentals
  • Strong knowledge of common enterprise protocols and services (e.g., SMB, LDAP, Kerberos, DNS, HTTP)
  • Scripting or programming experience in at least one language (e.g., Python, Go, PowerShell, Bash, C/C++)
  • Ability to quantify "exploitable risk" vs. "theoretical vulnerability" in a way that resonates with both plant managers and CISOs.
  • Ability to analyze attack paths and chain multiple weaknesses into meaningful outcomes
  • Strong technical writing and communication skills
  • Eligibility to work in the United States without sponsorship.
Responsibilities
  • Execute semi-automated and manual red team and penetration testing on sensitive OT environments (e.g., ICS, SCADA, DCS, BMS, IIoT, Embedded Systems) where autonomous testing requires expert human oversight to maintain safety and uptime.
  • Identify and exploit weaknesses across diverse attack surfaces: Understanding of OT services and protocols; Understanding and able to execute common Active Directory attacks that would allow lateral movement and privilege escalation; Ability to target controls systems and embedded devices for attack activities and abuse opportunities; Moderate understanding of container technologies and attack techniques to abuse these technologies; Certificate services and PKI infrastructure abuse; Knowledge of trust relationship attacks forest trusts.
  • Conduct privilege escalation, lateral movement, and post-exploitation activities.
  • Ability to customize public offensive tooling or develop custom internal tooling.
  • Maintain operational security throughout engagements: Deploy and operate command-and-control infrastructure (Cobalt Strike, Sliver, Mythic, custom frameworks); Implement evasion techniques against EDR, SIEM, and network monitoring; Practice proper OPSEC including infrastructure isolation and attribution management; Demonstrate operational discipline, including scope control, cleanup, and evidence handling.
  • Develop proof-of-concept exploits and tooling as needed to achieve objectives
  • Produce clear, actionable reports that communicate risk and business impact
  • Present findings to technical teams and executive stakeholders
  • Contribute to internal research, tooling, playbooks, and knowledge sharing
  • Define the reasoning paths, safety guardrails, and protocol-specific logic our AI uses to navigate industrial networks.
  • Act as the ultimate safety valve, defining the "No-Go" parameters for autonomous agents in volatile manufacturing or utility environments.
  • Work with client engineers and our internal AI teams to translate validated OT kill chains into autonomous defensive postures.
Desired Qualifications
  • Experience modifying or developing offensive tooling
  • Familiarity with detection evasion concepts and operational tradecraft
  • Experience working with mature defensive teams and security operations centers
  • Experience or interest in how LLMs and agentic workflows can be applied to offensive security.
  • Relevant certifications (e.g., GICSP, GRID, GCIP, or OSCP/OSEP) or equivalent demonstrated capability
  • Experience at world class consulting firms, fortune 100 Red Teams, or within specialized government offensive units

Armadin provides an AI-native cybersecurity platform that helps large enterprises prepare for AI-driven cyber threats. Its system uses a swarm of specialized AI agents that simulate attacker behavior to continuously reason, plan, and adapt, seeking exploitable vulnerabilities and kill chains across an organization’s attack surface. Unlike traditional scanners, Armadin’s agents return proof of what can be exploited, enabling proactive remediation and a reduction in testing time from days to minutes. The company differentiates itself through autonomous, attack-minded AI that operates at machine speed, combining red-teaming expertise with AI research to detect and validate risks across multi-modal, rapid campaigns (hyperattacks). The goal is to shift security from reactive checks to proactive, continuous testing that keeps pace with AI-enabled threats, serving Fortune 100 enterprises on a subscription basis.

Company Size

51-200

Company Stage

Series A

Total Funding

$214M

Headquarters

Redwood City, California

Founded

2025

Get referred to Armadin

Find people who can refer or advise you

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Company Equity

Remote Work Options

Conference Attendance Budget

Meal Benefits

Health Savings Account/Flexible Spending Account