Senior Consultant, Human Threats

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
146K-180K Annually
Senior level
Cloud • Security • Cybersecurity
The Role
Conduct authorized physical security assessments and social engineering engagements, including phishing, vishing, pretexting, facility walkthroughs, and human risk evaluations. Analyze vulnerabilities, document evidence, prepare reports, brief clients, and recommend remediation. The role also involves onsite testing, client relationship management, mentoring junior consultants, methodology development, thought leadership, and collaboration across delivery and sales teams.
Summary Generated by Built In
About Coalfire

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.

But that’s not who we are – that’s just what we do.
 
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Position Summary:

The Human Threats Senior Consultant will serve as a senior technical consultant on the DivisionHex Human Threats team, assessing the security posture and human-centered detection and response capabilities of client organizations. The role will place a strong emphasis on authorized physical security assessments, including facility access controls, perimeter and entry-point security, visitor and badge-management processes, secure-area protections, employee behaviors, and other physical safeguards. The Senior Consultant will also perform and support social engineering activities, including phishing, vishing, pretext development, human risk assessment, and awareness and behavior measurement, to evaluate how physical and digital attack paths can exploit people, processes, and technology.

 

The ideal candidate will bring expert-level knowledge of physical security assessment methodologies and adversary tradecraft, along with deep experience in one or more social engineering disciplines. They will work with the Managing Principal of Human Threats, Project Managers, Directors, and client Points of Contact to plan and execute engagements, meet project requirements, and provide subject matter expertise across social engineering domains. As a trusted client advisor, the Senior Consultant will use objective testing, onsite assessment activities, social engineering exercises, and clear reporting to help clients identify weaknesses, prioritize remediation, and improve resilience against physical and other human-centric threats.


What You'll Do

  • Conduct human threat engagements, including social engineering, phishing, vishing, physical security assessments, and human risk evaluations.
  • Plan, scope, and execute physical security assessments across facilities, offices, campuses, and other client locations in accordance with approved rules of engagement.
  • Evaluate physical security controls, including perimeter protections, entry points, locks, badges, visitor management, reception procedures, secure areas, employee access practices, and related processes.
  • Develop assessment scenarios, pretexts, and test plans that safely evaluate how physical and social engineering techniques may be combined to gain access to people, facilities, information, or technology.
  • Coordinate onsite logistics, client communications, safety considerations, evidence collection, and testing activities while maintaining strict adherence to scope and client authorization.
  • Document observations and evidence through accurate notes, timestamps, photographs, interviews, and other appropriate assessment records, while protecting sensitive client information.
  • Deliver timely client briefings and debriefs that clearly communicate physical security gaps, social engineering results, business impact, and prioritized remediation actions.
  • Manage priorities and tasks to achieve delivery utilization targets and ensure client deliverables and services are delivered on time.
  • Maintain current industry certifications and knowledge of emerging physical security, social engineering, and human threat tactics, technologies, and trends.
  • Collaborate with project managers, quality management, sales, and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Mentor junior consultants in physical assessment techniques, social engineering tradecraft, client communications, reporting, and engagement execution.
  • Contribute to the development and refinement of Human Threat methodologies, tooling, playbooks, and service offerings, with an emphasis on repeatable physical assessment practices.
  • Contribute to thought leadership through research, blogs, whitepapers, webinars, and conference presentations on physical security, human threat, and related security topics.
  • Contribute to other offensive security engagements, as needed, based on business demand, skillset alignment, and delivery priorities when not assigned to Human Threat assessments.
  • Perform other responsibilities as needed in support of client delivery, practice development, and team success.

What You'll Bring

  • 5 - 8 years client-facing consulting experience with 3 - 5 years experience in social engineering, red team, insider risk, physical security.
  • Demonstrated expertise of:
  • Social engineering principles and techniques
  • Phishing, vishing, smishing, and other communication-based attack methods
  • Pretext development and adversary emulation against human targets
  • Human risk assessments and behavior-based security evaluations
  • Report writing and client presentation delivery
  • Demonstrated knowledge of:
  • Current threat actor tactics, techniques, and procedures involving human targets
  • Physical security concepts and badge/access control weaknesses
  • Email security controls, identity-based attacks, and user-targeted attack paths
  • Security awareness, culture, and behavior change principles
  • Ability to travel up to 75%
  • Strong writing skills, personal accountability, and the ability to complete work to established standards without direct supervision.
  • Demonstrated experience planning and conducting authorized physical security assessments, facility walkthroughs, access control reviews, and onsite testing.
  • Ability to identify, document, risk-rate, and communicate physical and human-centered security vulnerabilities with clear, practical remediation recommendations.
  • Demonstrated ability to communicate complex security concepts through written content, client presentations, executive briefings, and public speaking.
  • Strong time management skills and the ability to manage multiple priorities, engagements, deadlines, and onsite requirements.
  • Ability to protect sensitive client information and maintain accurate assessment evidence and engagement records.
  • Working knowledge of social engineering tactics, phishing, vishing, pretext development, human risk, and related human threat disciplines.
  • Willingness and ability to travel to client sites and participate in onsite assessments as required.

Bonus Points

  • ASIS Certified Protection Professional certification or a comparable physical security credential.
  • Knowledge of physical red team tactics and techniques.
  • Behavioral science, psychology, or influence-based training.
  • Threat intelligence related to social engineering campaigns and threat actor tradecraft.
  • Insider risk program development.
  • Hardware, badge, or access-control related social engineering experience.
  • Published research, blogs, whitepapers, or conference presentations related to social engineering, human threat, or offensive security.

Why You’ll Want to Join Us

At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.

Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at [email protected].

Skills Required

  • 5–8 years of client-facing consulting experience
  • 3–5 years of experience in social engineering, red teaming, insider risk, or physical security
  • Expertise in social engineering principles and techniques
  • Experience with phishing, vishing, smishing, and communication-based attack methods
  • Experience developing pretexts and conducting adversary emulation against human targets
  • Experience conducting human risk assessments and behavior-based security evaluations
  • Strong report writing and client presentation skills
  • Knowledge of threat actor tactics, techniques, and procedures involving human targets
  • Knowledge of physical security concepts, badge systems, access controls, and related weaknesses
  • Knowledge of email security controls, identity-based attacks, and user-targeted attack paths
  • Knowledge of security awareness, organizational culture, and behavior change principles
  • Ability to travel up to 75% and participate in onsite client assessments
  • Experience planning and conducting authorized physical security assessments, facility walkthroughs, access-control reviews, and onsite testing
  • Ability to develop assessment plans, scenarios, pretexts, rules of engagement, and safety procedures
  • Strong situational awareness, judgment, discretion, and professionalism
  • Ability to identify, document, risk-rate, and communicate physical and human-centered security vulnerabilities
  • Ability to communicate complex security concepts through written content, presentations, executive briefings, and public speaking
  • Excellent communication, collaboration, and presentation skills
  • Strong time management and ability to manage multiple priorities, deadlines, and onsite requirements
  • Ability to protect sensitive client information and maintain accurate assessment evidence and records
  • ASIS Certified Protection Professional certification or comparable physical security credential
  • Knowledge of physical red team tactics and techniques
  • Experience with executive protection or executive-targeted social engineering scenarios
  • Behavioral science, psychology, or influence-based training
  • Threat intelligence related to social engineering campaigns and threat actor tradecraft
  • Insider risk program development experience
  • Training content development and workshop facilitation experience
  • Hardware, badge, or access-control-related social engineering experience
  • Published research, blogs, whitepapers, or conference presentations related to social engineering, human threat, or offensive security

Coalfire Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Coalfire and has not been reviewed or approved by Coalfire.

  • Leave & Time Off Breadth Flexible paid time off and paid parental leave are prominently offered, with remote/WFH support enabling time away when workload allows.
  • Healthcare Strength Comprehensive medical, dental, vision, wellness resources, and an EAP are part of the core package. Carrier coverage and plan options are regularly highlighted across employer materials.
  • Retirement Support A company‑matched 401(k) is included alongside other financial and development perks. This retirement benefit is consistently featured across benefits overviews.

Coalfire Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,062 Employees
Year Founded: 2001

What We Do

Coalfire is the cybersecurity advisor that helps private and public sector organizations avert threats, close gaps, and effectively manage risk. By providing independent and tailored advice, assessments, technical testing, and cyber engineering services, we help clients develop scalable programs that improve their security posture, achieve their business objectives, and fuel their continued success. Coalfire has been a cybersecurity thought leader for more than 20 years and has offices throughout the United States and Europe.

Similar Jobs

Cin7 Logo Cin7

Senior Manager, Field & Event Marketing

Cloud • eCommerce • Logistics • Software
Easy Apply
In-Office or Remote
Denver, CO, USA
276 Employees
115K-135K Annually

inKind Logo inKind

Automation Engineer

eCommerce • Fintech • Food • Mobile • Social Impact
Remote or Hybrid
USA
170 Employees
95K-120K Annually

inKind Logo inKind

Platform Engineer

eCommerce • Fintech • Food • Mobile • Social Impact
Remote or Hybrid
USA
170 Employees
150K-170K Annually

BlackLine Logo BlackLine

Strategic Account Manager

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
153K-180K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account