
Job Description
About GhostEye
Most security programs answer whether a company appears compliant. GhostEye answers a harder question: could a real attacker get in today?
Our founder previously led red-team operations at BlackRock and conducted offensive cyber operations at MITRE. Through that work, he saw how quickly adversaries adapt and how often traditional security programs fail to test the complete attack chain, particularly when the initial access vector is a person.
GhostEye was built to close that gap. We are building the always-on red team for modern enterprises. Our platform emulates the attacks adversaries use today, including help-desk vishing, deepfaked executives, MFA fatigue, identity compromise, and the technical payloads that follow.
We identify what is actually exploitable, help customers close the gaps, and retest until the fixes hold. Our team brings together offensive-security research, AI, and engineering to turn real attacker tradecraft into repeatable security validation.
About the role
GhostEye’s product is only as good as the attacks it can emulate.
As our Lead Security Researcher, you will study how real adversaries move from human manipulation to technical compromise. Your research will span phishing, vishing, smishing, pretexting, deepfakes, penetration testing, identity attacks, endpoint tradecraft, and EDR evasion.
You will spearhead GhostEye’s attack-simulation platform and lead the engineers responsible for turning offensive research into product capabilities. This is a hands-on, player-coach role. You will set technical direction, conduct research, build tooling, review implementation, and remain accountable for what the team ships.
You will translate attacker tactics, techniques, and procedures into safe, repeatable simulations that test whether an organization’s people and security controls can withstand a real attack. This includes understanding what happens after someone clicks, shares credentials, approves an MFA request, or grants an attacker access to an endpoint.
All research and testing is conducted in authorized environments for defensive purposes.
What you’ll own
- Research the complete attack chain. Study how real adversaries combine OSINT, social engineering, identity attacks, endpoint execution, defense evasion, credential access, lateral movement, and command and control.
- Build realistic attack simulations. Design safe, repeatable simulations spanning phishing, vishing, smishing, deepfakes, pretexting, penetration testing, and post-compromise activity.
- Lead the attack-simulation engineering team. Set technical direction, translate research into engineering priorities, review implementation, mentor engineers, and work alongside the team to ship scalable product capabilities.
- Advance endpoint and EDR validation. Research endpoint tradecraft and EDR evasion in controlled environments, identify detection and telemetry gaps, and turn validated techniques into repeatable control tests.
- Translate research into customer impact. Analyze simulations, identify weaknesses across people, identity, endpoints, and security processes, and produce remediation guidance customers can act on.
- Build GhostEye’s research program. Own the research roadmap, track emerging attacker tradecraft, and publish selected findings through technical write-ups, open-source tools, conference talks, and responsible disclosure.
What success looks like
By day 30:
- Develop a strong understanding of GhostEye’s platform, research environment, attack library, and safety requirements.
- Take ownership of the attack-simulation research roadmap and establish priorities with the engineering team.
- Deconstruct a recent deepfake-based vishing campaign and map its attack path and telemetry across a representative EDR deployment.
- Identify the first research capability to move into production.
By day 60:
- Lead the team in shipping a safe, repeatable simulation that connects human initial access to identity or endpoint-control validation.
- Establish a reliable process for moving research from hypothesis through validation and product implementation.
- Document the relevant attacker behavior, expected security telemetry, detection opportunities, and remediation guidance.
By day 90:
- Deliver a measurable improvement to the GhostEye platform or a customer assessment.
- Have the engineering team executing against a clear research and product roadmap.
- Produce a customer-facing or public research deliverable that demonstrates GhostEye’s technical depth.
- Become the internal authority on how emerging attacker tradecraft should shape the platform.
What we’re looking for
- A demonstrated history of building offensive-security tools, attack simulations, adversary-emulation capabilities, or penetration-testing infrastructure.
- Hands-on understanding of how attackers move from social engineering and initial access into endpoint execution and post-compromise activity.
- Experience researching endpoint tradecraft, EDR behavior, defensive telemetry, or security-control effectiveness.
- Strong programming and automation ability in Python, PowerShell, C, C++, C#, Go, Rust, or another relevant language.
- Familiarity with MITRE ATT&CK, OSINT, adversary-emulation methodologies, and common offensive-security tooling.
- Evidence of technical leadership through setting direction, leading projects, reviewing technical work, or mentoring engineers and researchers.
- The ability to design controlled experiments, validate findings, distinguish real results from testing artifacts, and produce reproducible documentation.
- Strong written and verbal communication. You can explain a sophisticated attack to both a security engineer and a non-technical executive.
- Excellent ethics and judgment regarding authorization, customer safety, responsible disclosure, and offensive capabilities.
We care more about demonstrated technical ability than credentials or a specific number of years. Strong evidence can come from professional work, independent research, open-source tooling, lab projects, technical write-ups, CTFs, CVEs, or responsible disclosures.
Public research is not required when professional work provides strong evidence of technical depth. We understand that offensive-security work is often confidential.
Nice to have
- Knowledge of Windows internals, Active Directory, cloud identity, or enterprise endpoint environments.
- Experience with reverse engineering, malware analysis, payload development, or command-and-control infrastructure.
- Experience applying AI or machine learning to security, including generative voice, text, video, or deepfake systems.
- Background in enterprise red-team operations or building offensive-security products.
- Published research, open-source tooling, conference presentations, CVEs, or responsible disclosures.
- Relevant certifications such as OSCP, OSEP, CRTO, GPEN, or GXPN. Certifications are helpful signals, not requirements.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Security
- Employment Type
- Full Time
- Location
- New York, NY
- Posted
- Compensation
- $150,000 - $250,000 per year
About GhostEye
AI-powered social engineering platform that executes real attacks to test enterprise human security vulnerabilities
More Roles at GhostEye
Similar Security Roles



Found this role interesting?