Position Summary:
The Human Threats Senior Consultant will serve as a senior technical consultant on the DivisionHex Human Threats team, assessing the security posture and human-centered detection and response capabilities of client organizations. The role will place a strong emphasis on authorized physical security assessments, including facility access controls, perimeter and entry-point security, visitor and badge-management processes, secure-area protections, employee behaviors, and other physical safeguards. The Senior Consultant will also perform and support social engineering activities, including phishing, vishing, pretext development, human risk assessment, and awareness and behavior measurement, to evaluate how physical and digital attack paths can exploit people, processes, and technology.
The ideal candidate will bring expert-level knowledge of physical security assessment methodologies and adversary tradecraft, along with deep experience in one or more social engineering disciplines. They will work with the Managing Principal of Human Threats, Project Managers, Directors, and client Points of Contact to plan and execute engagements, meet project requirements, and provide subject matter expertise across social engineering domains. As a trusted client advisor, the Senior Consultant will use objective testing, onsite assessment activities, social engineering exercises, and clear reporting to help clients identify weaknesses, prioritize remediation, and improve resilience against physical and other human-centric threats.
What You'll Do
- Conduct human threat engagements, including social engineering, phishing, vishing, authorized physical security assessments, and human risk evaluations.
- Plan, scope, and execute physical security assessments across facilities, offices, campuses, and other client locations in accordance with approved rules of engagement.
- Evaluate physical security controls, including perimeter protections, entry points, locks, badges, visitor management, reception procedures, secure areas, employee access practices, and related processes.
- Perform onsite testing and walkthroughs to identify opportunities for unauthorized access, security control bypass, tailgating or piggybacking, weak access governance, and other physical security exposures.
- Develop assessment scenarios, pretexts, and test plans that safely evaluate how physical and social engineering techniques may be combined to gain access to people, facilities, information, or technology.
- Coordinate onsite logistics, client communications, safety considerations, evidence collection, and testing activities while maintaining strict adherence to scope and client authorization.
- Document observations and evidence through accurate notes, timestamps, photographs, interviews, and other appropriate assessment records, while protecting sensitive client information.
- Analyze physical assessment results, assign risk-based findings, and provide practical recommendations that improve facility security, access management, detection, response, and resilience.
- Prepare, review, and approve Human Threat reports to meet quality requirements.
- Deliver timely client briefings and debriefs that clearly communicate physical security gaps, social engineering results, business impact, and prioritized remediation actions.
- Manage priorities and tasks to achieve delivery utilization targets and ensure client deliverables and services are delivered on time.
- Advise clients on testing and assessment activities in a timely and professional manner and establish positive collaborative relationships with clients and stakeholders.
- Maintain current industry certifications and knowledge of emerging physical security, social engineering, and human threat tactics, technologies, and trends.
- Identify up-sell and cross-sell opportunities and escalate them to sales.
- Collaborate with project managers, quality management, sales, and other delivery team members to drive customer satisfaction and meet project deliverables.
- Mentor junior consultants in physical assessment techniques, social engineering tradecraft, client communications, reporting, and engagement execution.
- Contribute to the development and refinement of Human Threat methodologies, tooling, playbooks, and service offerings, with an emphasis on repeatable physical assessment practices.
- Contribute to thought leadership through research, blogs, whitepapers, webinars, and conference presentations on physical security, human threat, and related security topics.
- Support the development of the Human Threat practice through original research, service innovation, and externally facing industry content.
- Represent Coalfire at industry events, client briefings, and conferences as a subject matter expert.
- Contribute to other offensive security engagements, as needed, based on business demand, skillset alignment, and delivery priorities when not assigned to Human Threat assessments.
- Perform other responsibilities as needed in support of client delivery, practice development, and team success.
What You'll Bring
- 5 - 8 years client-facing consulting experience with 3 - 5 years experience in social engineering, red team, insider risk, physical security
- Demonstrated expertise of:
- Social engineering principles and techniques
- Phishing, vishing, smishing, and other communication-based attack methods
- Pretext development and adversary emulation against human targets
- Human risk assessments and behavior-based security evaluations
- Report writing and client presentation delivery
- Demonstrated knowledge of:
- Current threat actor tactics, techniques, and procedures involving human targets
- Physical security concepts and badge/access control weaknesses
- Email security controls, identity-based attacks, and user-targeted attack paths
- Security awareness, culture, and behavior change principles
- Ability to travel up to 75%
- Strong writing skills, personal accountability, and the ability to complete work to established standards without direct supervision.
- Demonstrated experience planning and conducting authorized physical security assessments, facility walkthroughs, access control reviews, and onsite testing.
- Working knowledge of physical security principles and controls, including perimeter security, entry points, locks, badges, visitor management, reception procedures, secure areas, and employee access practices.
- Ability to develop assessment plans, scenarios, pretexts, rules of engagement, and safety procedures for physical and social engineering activities.
- Strong situational awareness, sound judgment, discretion, and professionalism when conducting onsite assessments and interacting with employees, visitors, and client stakeholders.
- Ability to identify, document, risk-rate, and communicate physical and human-centered security vulnerabilities with clear, practical remediation recommendations.
- Demonstrated ability to communicate complex security concepts through written content, client presentations, executive briefings, and public speaking.
- Excellent communication, collaboration, and presentation skills.
- Strong time management skills and the ability to manage multiple priorities, engagements, deadlines, and onsite requirements.
- Ability to protect sensitive client information and maintain accurate assessment evidence and engagement records.
- Working knowledge of social engineering tactics, phishing, vishing, pretext development, human risk, and related human threat disciplines.
- Willingness and ability to travel to client sites and participate in onsite assessments as required.
Bonus Points
- ASIS Certified Protection Professional certification or a comparable physical security credential.
- Knowledge of physical red team tactics and techniques.
- Executive protection or executive-targeted social engineering scenarios.
- Behavioral science, psychology, or influence-based training.
- Threat intelligence related to social engineering campaigns and threat actor tradecraft.
- Insider risk program development.
- Training content development and workshop facilitation.
- Hardware, badge, or access-control related social engineering experience.
- Published research, blogs, whitepapers, or conference presentations related to social engineering, human threat, or offensive security.
Similar Jobs
What you need to know about the Los Angeles Tech Scene
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering



