Remote opportunity•Posted 9/20/2026, 5:28:44 AM
A
Ardent MC
Adversarial Simulation Lead
Remote•Remote
Full-timeRemoteremotejobsorg
Cyber Securityremotejobs.org
About this role
Ardent is seeking an Adversarial Simulation Lead to join our team. This is a remote position with expected travel to Tallahassee, FL. Position Description: Ardent is seeking a Adversarial Simulation Lead to plan and execute controlled, threat-informed simulations that test whether access controls, monitoring, and detection processes function together under realistic operating conditions. The role performs only explicitly authorized activities within agency-specific, Rules of Engagement and prioritizes safe execution, deconfliction, evidentiary rigor, and operational relevance across a potentially broad multi-agency environment. Responsibilities and Duties:
- Translate approved control objectives into safe adversary-behavior simulations and test cases aligned to selected kill-chain stages and MITRE ATT&CK techniques.
- Develop agency-specific Rules of Engagement inputs covering authorized systems, windows, accounts, techniques, tools, prohibitions, notifications, deconfliction, stop-work conditions, evidence handling, and escalation.
- Execute approved access-control stress tests, privilege-boundary attempts, anomaly generation, endpoint/network activity, vulnerability validation, and related verification techniques.
- Coordinate closely with the Detection & Monitoring Analyst to trace events from activity initiation through telemetry, alerting, triage, escalation, and response.
- Minimize operational risk by confirming preconditions, rollback considerations, safety constraints, communications, and stop conditions before testing.
- Capture reproducible evidence, including command or tool context, screenshots, packet or event data, logs, timestamps, affected assets, observed outcomes, and analytic notes.
- Perform root-cause analysis and develop technically feasible hardening or detection-improvement recommendations, clearly separated from factual AUP reporting.
- Support retesting of approved remediated findings and document whether expected control performance is demonstrated.
- Contribute to workshops and reusable job aids explaining simulation design, evidence, and defensive lessons. Requirements:
Preferred Qualifications
- Experience leading purple-team exercises or adversary campaigns.
- Experience testing Zero Trust or identity-centric controls.
- Cloud, web application, API, Active Directory, firewall, and multi-tenant security operations experience.
- GIAC penetration testing or forensic certifications. Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process. Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.
Posting details
Remote
Yes
Employment type
Full-time
Workplace type
Remote
Source
remotejobsorg
First seen
9/20/2026, 8:10:25 AM
Last seen
9/20/2026, 8:10:25 AM