Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you.
As a Red Team Operator, you will join a team that emulates real-world threats using threat actor tactics, techniques, and procedures (TTPs). Your primary goal will be to train defenders and measure how well our people, processes, and technology protect our environment. You will execute engagements alongside senior operators, support multiple engagements at once, and grow your tradecraft in areas such as tool development, EDR evasion, and cloud attack paths.
As part of the Global Security organization within Cyber Operations, you will build strong partnerships across Global Security and Technology teams to successfully execute the Red Team mission.
- This position is based out of our Alpharetta, Georgia office.
- We believe great things happen when teams connect. Our schedule is built around 4 days of high-impact, in-office collaboration (Monday–Thursday), paired with Friday Flexibility to wrap up your week remotely.
- This position does not offer immigration sponsorship (current or future) including F-1 STEM OPT extension support.
- This position is not open to third-party vendors or C2C.
- In person interviews are required.
What you will do
- Execute threat actor emulation engagements using real-world TTPs, and contribute to engagement planning alongside senior operators.
- Support multiple concurrent engagements while following rules of engagement, OPSEC standards, and deconfliction processes.
- Collaborate on building and maintaining secure Red Team command and control (C2) infrastructure.
- Document and communicate findings in clear technical reports, and partner with Cyber Detection and Response teams in purple team exercises to develop and validate new detections.
- Contribute to tool development, including beacon object files (BOFs), C2 extensions, EDR evasion techniques, and stealthy C2 channels, under the guidance of senior team members.
- Apply AI tools to speed up threat emulation, CVE analysis, and malware analysis, and to support AI-augmented testing.
- Handle sensitive data and systems responsibly, in line with the legal and regulatory requirements of a global financial data company.
What experience you need
- 2+ years of experience in cybersecurity, including hands-on offensive work (penetration testing, red teaming, offensive security research, or CTFs and lab projects).
- 1+ years of experience writing code in at least one language such as C, C#, Go, Python, or PowerShell.
- Working knowledge of Windows and Linux operating system internals, Active Directory, and networking fundamentals (e.g., IP, TCP, UDP, DNS, HTTP/S).
- Working knowledge of the MITRE ATT&CK framework.
- Experience using AI/LLM tools in technical or security workflows.
What could set you apart
- Industry certifications such as OSCP, OSEP, CRTO, CRTP, or similar.
- Hands-on experience deploying and using C2 frameworks such as Cobalt Strike, Sliver, or Mythic, including building customizations or extensions.
- Experience with Google Cloud Platform (GCP) or Amazon Web Services (AWS), including IAM, service accounts, and automating via API calls.
- Experience building MCP integrations or AI agents.
- A public portfolio such as GitHub projects, blog posts, CVEs, or write-ups on complex security lab environments.
- Experience in financial services or another regulated industry.
#LI-Hybrid
#LI-KD1
We offer comprehensive compensation and healthcare packages, 401k matching, paid time off, and organizational growth potential through our online learning platform with guided career tracks.
Are you ready to power your possible? Apply today, and get started on a path toward an exciting new career at Equifax, where you can make a difference!


