Hexens

Senior Red Team Operator - Social Engineering Focus

Full TimePosted Jul 21, 2026

Hexens is looking for a Senior Red Team Operator with a strong focus on social engineering to join our team. We deliver full-scope adversary simulations against some of the hardest targets out there, spanning banks, crypto and web3 platforms, and industrial environments. We address complex security challenges, replicating real-world attackers to prove impact against the applications and infrastructures our clients rely on.



Remote Availability: Work from anywhere! This is a fully remote role with no location restrictions.



Responsibilities:

  • Plan and execute red team and adversary simulation engagements across enterprise, cloud, financial, and web3 environments.
  • Run social engineering campaigns as an initial-access vector: phishing, spear phishing, pretexting, and vishing, including executive-level targeting.
  • Carry engagements through post-access: lateral movement, privilege escalation, persistence, and objective completion.
  • Deploy and manage C2 infrastructure and supporting tooling.
  • Perform security control validation and evasion (firewall, proxy, DLP, EDR).
  • Conduct web application and network penetration testing as part of broader engagements.
  • Write clear, client-ready findings and remediation guidance.
  • Lead engagements independently when needed.


Required skillset:

  • Proven red team / adversary simulation experience across multiple sectors.
  • Hands-on social engineering experience with a demonstrable track record (phishing, pretexting, executive-level testing).
  • Strong web application and network penetration testing skills.
  • Comfort with C2 deployment, control bypass, and standard post-exploitation techniques.
  • Ability to run an engagement solo, from scoping through reporting.
  • Clear written and verbal communication for client-facing deliverables.


Big plus if any of the following apply:

  • Experience building phishing simulation and security awareness training programs.
  • Crypto / web3 or smart contract engagement experience.
  • Bug bounty track record (e.g. Bugcrowd, HackerOne).
  • Relevant certifications such as OSCP, CRTO, or OSCE3.
  • Conference talks or published research.

Keep exploring

View all software engineering jobs