Skip to main content
RoleCybersecurity

Red Teamer

Long campaigns, adversary emulation, AD chains, evasion against modern EDR.

POST verdict

Tiny market, brutal bar, mythologised everywhere. A real seat if you've already done the years, a fantasy if you're aiming at it as a first security job.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You've got serious pentest, malware or detection-engineering background already
  • You think in objectives and TTPs, not vulnerabilities and CVSS scores
  • You can write tooling that survives contact with a competent blue team
  • You're comfortable working alone for weeks before you have anything to show
Skip this if
  • You haven't yet done two years of pentest or equivalent offensive work
  • You want fast feedback loops, red-team engagements move in months
  • You'd struggle with operating quietly and never getting public credit
  • You build, lose, and rebuild infrastructure without breaking stride
  • Your TTPs evolve with the target, you don't run the same playbook twice
  • Blue teams find your work hard to detect even when they're warned in advance
  • You can defend every operational decision in a post-engagement debrief
The bit you're probably underestimating

The job is mostly preparation and patience. For every week of exciting operational work there are six weeks of infrastructure prep, recon, tooling, scoping and reporting. Most people who chase the role bounce off the prep, not the ops. Pay is good but not extraordinary outside FAANG and elite consultancies, and the career ceiling inside red team itself is low. Plan an exit into adversary simulation leadership, research, or detection before you take the seat.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

High at senior IC; small market, mostly large enterprises and gov.

  • +Pentester
  • +Malware analyst
  • +Offensive consultant
  • That it's the natural next step from pentest, different skillset entirely.
  • Adversary Emulation
  • Tooling / C2 dev
  • Detection (purple)

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.