Adversarial Simulation Lead
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 3h ago
The date the source published, not the day we noticed it (2026-09-17). Last seen at its source just now.
Is it remote?
Remote
That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.
Who may apply?
Not stated
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 1h ago · last seen just now
The listing
Ardent is seeking an Adversarial Simulation Lead to join our team.
This is a remote position with expected travel to Tallahassee, FL.
Position Description:
Ardent is seeking a Adversarial Simulation Lead to plan and execute controlled, threat-informed simulations that test whether access controls, monitoring, and detection processes function together under realistic operating conditions. The role performs only explicitly authorized activities within agency-specific, Rules of Engagement and prioritizes safe execution, deconfliction, evidentiary rigor, and operational relevance across a potentially broad multi-agency environment.
Responsibilities and Duties:
- Translate approved control objectives into safe adversary-behavior simulations and test cases aligned to selected kill-chain stages and MITRE ATT&CK techniques.
- Develop agency-specific Rules of Engagement inputs covering authorized systems, windows, accounts, techniques, tools, prohibitions, notifications, deconfliction, stop-work conditions, evidence handling, and escalation.
- Execute approved access-control stress tests, privilege-boundary attempts, anomaly generation, endpoint/network activity, vulnerability validation, and related verification techniques.
- Coordinate closely with the Detection & Monitoring Analyst to trace events from activity initiation through telemetry, alerting, triage, escalation, and response.
- Minimize operational risk by confirming preconditions, rollback considerations, safety constraints, communications, and stop conditions before testing.
- Capture reproducible evidence, including command or tool context, screenshots, packet or event data, logs, timestamps, affected assets, observed outcomes, and analytic notes.
- Perform root-cause analysis and develop technically feasible hardening or detection-improvement recommendations, clearly separated from factual AUP reporting.
- Support retesting of approved remediated findings and document whether expected control performance is demonstrated.
- Contribute to workshops and reusable job aids explaining simulation design, evidence, and defensive lessons.
Requirements:
- Bachelor’s degree in cybersecurity, digital forensics, information technology, computer science, or related field.
- Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 7 years in adversary simulation, penetration testing, threat hunting, digital forensics, incident response, vulnerability assessment, or security engineering.
- Demonstrated ability to conduct controlled testing in production-sensitive or regulated environments under formal authorization.
- Hands-on knowledge of MITRE ATT&CK, identity and access control, endpoint and network telemetry, SIEM/EDR/XDR, vulnerability tools, cloud security, and evidence preservation.
- Ability to explain operational consequences and mitigation options to technical and executive audiences.
Preferred Qualifications:
- Experience leading purple-team exercises or adversary campaigns.
- Experience testing Zero Trust or identity-centric controls.
- Cloud, web application, API, Active Directory, firewall, and multi-tenant security operations experience.
- GIAC penetration testing or forensic certifications.
Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.
Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.