Full-Time

Operational Technology Red Team Operator

Updated on 8/1/2026

Armadin

Armadin

51-200 employees

AI-native platform for proactive cyber defense

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
LLM
PowerShell
Bash
Python
LDAP
Network Monitoring
Computer Networking
Operating Systems
Go
Penetration Testing
C/C++
Linux/Unix

Get referred to Armadin

See people who can refer or advise you

Requirements
  • Ability to clearly communicate with Operational Technology stakeholders in a manner that builds relationships and trust.
  • Demonstrated experience in offensive security with a focus on Operational Technology, Industrial Control Systems, Supervisory Control and Data Acquisition, and Embedded Systems, including familiarity with automation and control systems and a Linux terminal.
  • Deep technical knowledge of industrial protocols including Modbus, DNP3, Ethernet/IP, and Profinet, with the ability to perform manual packet manipulation.
  • Deep understanding of networking and operating system fundamentals.
  • Strong knowledge of enterprise protocols and services including SMB, LDAP, Kerberos, DNS, and HTTP.
  • Scripting or programming experience in at least one language such as Python, Go, PowerShell, Bash, C, or C++.
  • Ability to quantify exploitable risk versus theoretical vulnerability for plant managers and Chief Information Security Officers.
  • Ability to analyze attack paths and chain multiple weaknesses into meaningful outcomes.
  • Strong technical writing and communication skills.
  • Eligibility to work in the United States without sponsorship.
Responsibilities
  • Execute semi-automated and manual red team and penetration testing on sensitive Operational Technology environments, including Industrial Control Systems, Supervisory Control and Data Acquisition, Distributed Control Systems, Building Management Systems, Industrial Internet of Things, and Embedded Systems, with expert human oversight for safety and uptime.
  • Identify and exploit weaknesses across diverse attack surfaces, including Operational Technology services and protocols, Active Directory, control systems, embedded devices, container technologies, certificate services, Public Key Infrastructure, and forest trust relationships.
  • Conduct privilege escalation, lateral movement, and post-exploitation activities.
  • Customize public offensive tooling or develop custom internal tooling.
  • Deploy and operate command-and-control infrastructure using Cobalt Strike, Sliver, Mythic, and custom frameworks.
  • Implement evasion techniques against Endpoint Detection and Response, Security Information and Event Management, and network monitoring.
  • Practice operational security, including infrastructure isolation and attribution management.
  • Maintain operational discipline through scope control, cleanup, and evidence handling.
  • Develop proof-of-concept exploits and tooling as needed to achieve objectives.
  • Produce clear, actionable reports communicating risk and business impact.
  • Present findings to technical teams and executive stakeholders.
  • Contribute to internal research, tooling, playbooks, and knowledge sharing.
  • Define the reasoning paths, safety guardrails, and protocol-specific logic used by artificial intelligence systems to navigate industrial networks.
  • Define the no-go parameters for autonomous agents in volatile manufacturing or utility environments.
  • Work with client engineers and internal artificial intelligence teams to translate validated Operational Technology kill chains into autonomous defensive postures.
Desired Qualifications
  • Experience modifying or developing offensive tooling.
  • Familiarity with detection evasion concepts and operational tradecraft.
  • Experience working with mature defensive teams and security operations centers.
  • Experience or interest in applying large language models and agentic workflows to offensive security.
  • Relevant certifications such as GICSP, GRID, GCIP, OSCP, or OSEP, or equivalent demonstrated capability.
  • Experience at world-class consulting firms, Fortune 100 red teams, or specialized government offensive units.

Armadin provides an AI-native cybersecurity platform that helps large enterprises prepare for AI-driven cyber threats. Its system uses a swarm of specialized AI agents that simulate attacker behavior to continuously reason, plan, and adapt, seeking exploitable vulnerabilities and kill chains across an organization’s attack surface. Unlike traditional scanners, Armadin’s agents return proof of what can be exploited, enabling proactive remediation and a reduction in testing time from days to minutes. The company differentiates itself through autonomous, attack-minded AI that operates at machine speed, combining red-teaming expertise with AI research to detect and validate risks across multi-modal, rapid campaigns (hyperattacks). The goal is to shift security from reactive checks to proactive, continuous testing that keeps pace with AI-enabled threats, serving Fortune 100 enterprises on a subscription basis.

Company Size

51-200

Company Stage

Series A

Total Funding

$214M

Headquarters

Redwood City, California

Founded

2025

Get referred to Armadin

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Palo Alto Networks partnership can accelerate enterprise distribution through Unit 42.
  • Decision-grade exploit proof matches buyers demanding validated, remediation-ready risk evidence.
  • Record early-stage funding supports rapid hiring, product expansion, and category creation.

What critics are saying

  • Crowded security platforms can bundle autonomous validation and commoditize Armadin’s core feature.
  • Enterprises can distrust hyperattack framing if real-world urgency remains unproven.
  • One missed exploit or false result can damage CISO trust quickly.

What makes Armadin unique

  • Kevin Mandia and Travis Lanham bring Mandiant-grade offensive security credibility.
  • Armadin uses autonomous AI agents to validate real kill chains, not listings.
  • The platform targets AI-driven hyperattacks across the entire attack surface.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Company Equity

Remote Work Options

Conference Attendance Budget

Meal Benefits

Health Savings Account/Flexible Spending Account