Job Details
The Director of Red Team is a senior cybersecurity leadership role responsible for directing offensive security operations, managing the internal red team, and overseeing external vendor engagements for advanced adversary simulations and security assessments.
This position sits at the intersection of technical offensive expertise, strategic planning, and operational leadership. The ideal candidate will build, empower, and guide highly skilled offensive security analysts while establishing partnerships across technology and operational business teams to scale testing capabilities and mature security posture across complex enterprise environments.
RESPONSIBILITIES:
- Manage and mature the Red Team strategy, aligning the overall vision and roadmap to business risks and posture.
- Maintain and enforce clear Rules of Engagement, standard operating procedures, and safety controls to ensure adversary simulations test controls effectively without degrading production stability.
- Align testing methodologies with threat intelligence frameworks to emulate threat actors and emerging tactics, techniques, and procedures relevant to business risk profiles.
- Lead, mentor, and mature a team of high-performing red team engineers and offensive security operators, fostering continuous learning and skill development.
- Balance team bandwidth between complex, long-term targeted campaigns, specialized security assessments, and research/tooling development.
- Select and manage third-party offensive security providers for external assessments, scoping complex engagements and statement of work deliverables. Validate that vendor findings maintain high technical standards and actionable quality.
- Integrate third-party findings into internal tracking mechanisms to ensure unified reporting and remediation.
- Partner closely with detection & response operations, threat intelligence, and security engineering to ensure red team findings drive tangible improvements in preventative and detective controls.
- Translate complex exploit chains and tactical findings into clear risk impact narratives for executive leadership and business unit leaders.
EDUCATION & QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience
- 8+ years of progressive experience in cybersecurity, with at least 6 years dedicated to offensive security role in red team, penetration testing, adversary emulation, or exploit development.
- 3+ years leading offensive security teams or programs, with demonstrated success building and maturing the function at enterprise scale.
- Demonstrated experience planning and leading full-scope, objective-based red team operations against mature, monitored environments.
- Strong command of adversary tradecraft and the detection surfaces it creates, including how modern EDR, identity protection, and cloud logging observe attacker activity.
- Practical fluency with MITRE ATT&CK and threat intelligence, and the ability to translate actor behavior into realistic emulation plans.
- Excellent written and verbal communication skills, with proven ability to deliver difficult findings without damaging partnership, and to brief executives credibly.
PREFERRED CERTIFICATIONS:
- OSCP - Offensive Security Certified Professional
- OSEP - Experienced Penetration Tester
- OSED - Exploit Developer
- GIAC GXPN - Exploit Researcher and Advanced Penetration Tester
- GIAC GPEN - Penetration Tester
- GIAC GRTP - Red Team Professional
- GIAC GCPN - Cloud Penetration Tester
- GIAC GWAPT - Web Application Penetration Tester
Bachelor's degree in cyber security, computer science, information technology, information systems, or a related field, or equivalent experience required. Master's degree in cyber security, computer science, information technology, information systems, business administration, or a related field, or equivalent experience preferred. 10+ years of experience in cyber threat intelligence, cyber security, security operations, incident response, threat analysis, or a related field required. 5+ years of experience in a management capacity required. Certified in Certified Information Systems Security Professional (CISSP) or equivalent certification preferred. Certified in Certified Information Security Manager (CISM) or equivalent certification preferred.
What Cencora offers
We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora
Full time
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation
Skills Required
- Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field, or equivalent experience
- 8+ years of progressive cybersecurity experience
- 6+ years in offensive security, red teaming, penetration testing, adversary emulation, or exploit development
- 3+ years leading offensive security teams or programs
- Experience planning and leading full-scope, objective-based red team operations in mature, monitored environments
- Strong command of adversary tradecraft and detection surfaces, including EDR, identity protection, and cloud logging
- Practical fluency with MITRE ATT&CK and threat intelligence
- Excellent written and verbal communication skills with executive briefing experience
- Master's degree in cybersecurity, computer science, information technology, information systems, business administration, or a related field, or equivalent experience
- 10+ years of experience in cyber threat intelligence, cybersecurity, security operations, incident response, threat analysis, or a related field
- 5+ years of experience in a management capacity
- OSCP certification
- OSEP certification
- OSED certification
- GIAC GXPN certification
- GIAC GPEN certification
- GIAC GRTP certification
- GIAC GCPN certification
- GIAC GWAPT certification
- CISSP or equivalent certification
- CISM or equivalent certification
Cencora Compensation & Benefits Highlights
-
Healthcare Strength — Medical, dental, and vision coverage alongside prescription drug and mental/behavioral health resources are described as comprehensive with solid options. Health insurance is considered a standout component among the offerings.
-
Parental & Family Support — Paid parental leave (12 weeks), caregiver leave, fertility and family‑building support, adoption/surrogacy assistance, and backup childcare feature prominently. These programs are viewed as robust and supportive for families.
-
Retirement Support — A 401(k) match of 100% on the first 3% and 50% on the next 2%, plus access to an ESPP, are highlighted benefits. Retirement programs are considered strong and a meaningful part of total compensation.
Cencora Insights
What We Do
Cencora is a leading pharmaceutical solutions organization centered on improving the lives of people and animals everywhere. With 46,000+ global team members, we have the opportunity to make a positive impact on healthcare in communities everywhere. Our team members are empowered to activate their careers through a collective of tools and resources designed to support individual career interests and aspirations. We value our listening culture that actions real outcomes and our team members appreciate and recognize one another for contributions that are making a meaningful global impact. No matter what your role is here, the work we do together has meaning. When you join our team, you become a crucial part of a greater purpose. We’re committed to supporting you personally and professionally, so we can achieve more together at the center of health. Protect yourself from job scams: Recruitment scams are on the rise. To protect yourself, we urge you to be vigilant and follow these guidelines > https://careers.cencora.com/us/en/job-scams
Gallery
Cencora Teams
Cencora Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
















