Back to jobs
New

Senior Red Team Analyst

Remote

Foundation Risk Partners, one of the fastest growing insurance brokerage and consulting firms in the US, is adding a Senior Red Team Analyst to their team. 

This role is fully remote with travel once a quarter to the office in Longwood, FL. 

Job Summary:

The Red Team Analyst is responsible for conducting adversary simulation and offensive security testing to evaluate the effectiveness of the organization’s people, processes, and technology against real‑world threats. This role emulates advanced threat actors using recognized frameworks such as MITRE ATT&CK, with the goal of identifying control gaps, detection blind spots, and response inefficiencies.

This role works independently from day‑to‑day the Blue Team (Security Operations and Security Engineering) partners closely GRC, and executive leadership to provide objective, evidence‑based assessments that drive continuous improvement in the organization’s security posture.

Essential Functions:

  • Adversary Simulation & Red Team Operations
    •  Design and execute red team exercises, including assumed breach, black box, gray box, and purple team–assisted scenarios.
    • Emulate realistic threat actor behavior across the kill chain, including reconnaissance, initial access, persistence, privilege escalation, lateral movement, command and control, and exfiltration.
    • Develop and maintain custom attack techniques and tooling aligned to evolving threat intelligence and MITRE ATT&CK techniques.
    • Conduct phishing, social engineering, and identity centric attack simulations where authorized. 
  • Detection & Control Validation
    • Test the effectiveness of preventative, detective, and responsive controls across endpoints, identity, email, network, and cloud environments. 
    • Identify detection gaps and false negatives in security tooling, such as SIEM, XDR, EDR, and identity protection platforms.
    • Produce measurable outcomes on time to detect (TTD) and time to respond (TTR) to inform operational maturity. 
  • Purple Team Collaboration
    • Partner with Blue Team to safely validate detections during controlled exercises.
    • Translate offensive findings into actionable defensive improvements, including detection engineering use cases
    • Participate in post exercise debriefs and lessons learned sessions.
  • Reporting & Executive Communication
    • Produce clear, defensible reports detailing attack paths, findings, blast radius, and business impact.
    • Map findings to MITRE ATT&CK, NIST CSF, and internal control frameworks to support audit and risk management activities. 
    • Present results to technical teams and executive leadership in a way that balances realism with risk context. 
  • Continuous Improvement
    • Track remediation progress and validate corrective actions through targeted retesting.
    • Stay current on emerging threats, red team tooling, and adversary tradecraft.
    • Contribute to the organization’s offensive security roadmap and annual testing strategy. 

 Qualifications: 

  • 3–7+ years of experience in offensive security, penetration testing, red teaming, or advanced security engineering.
  • Strong understanding of Windows, Active Directory, Entra ID, Azure, Microsoft 365, and cloud identity attack paths.
  • Hands‑on experience with red team and offensive tools (e.g., C2 frameworks, custom payloads, phishing infrastructure).
  • Deep familiarity with the MITRE ATT&CK framework and threat‑actor–driven testing methodologies.
  • Ability to write clear, high‑quality technical reports suitable for auditors and executives.

Preferred Qualifications:

  • Experience operating in Microsoft Defender, Sentinel, and XDR‑centric environments.
  • Prior experience supporting SOC 2 Type II, ISO 27001, or similar regulatory and audit programs.
  • Red team or offensive security certifications such as: o CRTO / CRTO II o OSCP / OSEP / OSED o GWAPT / GXPN.
  • Background in detection engineering, purple teaming, or incident response.

Key Skills & Competencies:

  • Adversary mindset with strong ethical grounding.
  • Excellent documentation and communication skills.
  • Strong scripting or programming capability (PowerShell, Python, C#, etc.).
  • Ability to work independently with minimal supervision.
  • High degree of professionalism when handling sensitive access and findings.

Disclaimer:

While this job description is intended to be an accurate reflection of the job requirements, management reserves the right to modify, add, or remove duties from particular jobs and to assign other duties as necessary.

Equal Employment Opportunity (EEO):

FRP provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or any other classifications protected by law.

Benefits:

FRP offers a comprehensive range of health-related benefit options including medical, vision, and dental. We offer a 401(k) with company match, company paid life insurance, STD, LTD and a generous PTO policy starting at 18 days per year plus 10 paid holidays & 2 floating holidays!

 

Create a Job Alert

Interested in building your career at Foundation Risk Partners? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Please select all insurance licensures you currently maintain
Select...

If yes, you can always opt-out by replying STOP at any time.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Foundation Risk Partners’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.