Adversarial Simulation Lead
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Ardent is seeking a Adversarial Simulation Lead to plan and execute controlled, threat-informed simulations that test whether access controls, monitoring, and detection processes function together under realistic operating conditions. The role performs only explicitly authorized activities within agency-specific Rules of Engagement and prioritizes safe execution, deconfliction, evidentiary rigor, and operational relevance across a potentially broad multi-agency environment.
Responsibilities and Duties:
- Translate approved control objectives into safe adversary-behavior simulations and test cases aligned to selected kill-chain stages and MITRE ATT&CK techniques.
- Develop agency-specific Rules of Engagement inputs covering authorized systems, windows, accounts, techniques, tools, prohibitions, notifications, deconfliction, stop-work conditions, evidence handling, and escalation.
- Execute approved access-control stress tests, privilege-boundary attempts, anomaly generation, endpoint/network activity, vulnerability validation, and related verification techniques.
- Coordinate closely with the Detection & Monitoring Analyst to trace events from activity initiation through telemetry, alerting, triage, escalation, and response.
- Minimize operational risk by confirming preconditions, rollback considerations, safety constraints, communications, and stop conditions before testing.
- Capture reproducible evidence, including command or tool context, screenshots, packet or event data, logs, timestamps, affected assets, observed outcomes, and analytic notes.
- Perform root-cause analysis and develop technically feasible hardening or detection-improvement recommendations, clearly separated from factual AUP reporting.
- Support retesting of approved remediated findings and document whether expected control performance is demonstrated.
- Contribute to workshops and reusable job aids explaining simulation design, evidence, and defensive lessons.
Requirements:
- A Bachelor’s degree in cybersecurity, digital forensics, information technology, computer science, or related field.
- Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 7 years in adversary simulation, penetration testing, threat hunting, digital forensics, incident response, vulnerability assessment, or security engineering.
- Demonstrated ability to conduct controlled testing in production-sensitive or regulated environments under formal authorization.
- Hands-on knowledge of MITRE ATT&CK, identity and access control, endpoint and network telemetry, SIEM/EDR/XDR, vulnerability tools, cloud security, and evidence preservation.
- Ability to explain operational consequences and mitigation options to technical and executive audiences.
Preferred Qualifications:
- Experience leading purple-team exercises or adversary campaigns.
- Experience testing Zero Trust or identity-centric controls.
- Cloud, web application, API, Active Directory, firewall, and multi-tenant security operations experience.
- GIAC penetration testing or forensic certifications.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at ArdentMC
Explore Top Companies in this Space
Trace3
Information Technology & Services / Cybersecurity / Cloud Computing / AI & Data Solutions
Atmosera
Information Technology & Services / Systems and Information Management / Cloud Computing / Enterprise Software
The Looma Project
Media and Information Services / Digital Advertising / Retail Technology / B2B Software
Antenna
Media / Technology / Information Services
ArdentMC
View Company ProfileArdentMC (operating at ardentmc.com) is a specialized technology firm focused on geospatial and IT solutions for the public sector. Founded in 2006 and headquartered in Vienna, Virginia, ArdentMC bridges critical gaps in government and defense operations by delivering high-end geospatial mobile and web-based applications. Unlike traditional IT providers, ArdentMC tailors its solutions to address complex challenges in national security, disaster response, and infrastructure management. Under the hood, the company leverages advanced geospatial information systems (GIS) and IT program management to create scalable, mission-critical platforms. This empowers federal, state, and local agencies to enhance situational awareness, streamline operations, and mitigate risks—whether combating cyber threats or natural disasters. With a revenue footprint of approximately $21 million, ArdentMC operates as a privately held subsidiary, focusing on delivering measurable impact rather than rapid growth.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
