Red Team Project

Red Team Phishing Simulation Resume Project Example

An authorized red team phishing simulation that cloned internal login flows with GoPhish, measured click and credential submission rates, delivered awareness metrics to leadership, and documented social engineering tradecraft within strict ROE.

GoPhishSocial EngineeringRed TeamPhishing

Free to start · No credit card required

ELENA ROSSI

Penetration Tester

95% ATS matchATS

Project

Phishing sim

ROE-bound
GoPhishSocial EngineeringEmail AnalysisReportingAwareness Metrics
  • Ran authorized phishing simulation with GoPhish.
  • Measured click-through and submission rates by department.
  • Reported social engineering risk with remediation training plan.

Why this project is valuable

Red team signal

Phishing simulations show social engineering methodology and metrics delivery—not SOC phishing triage playbooks alone.

Good ATS coverage

Supports red team, phishing simulation, social engineering, GoPhish, and security awareness keywords.

Leadership-ready metrics

Click and submission rates by department drive training investment decisions.

Good interview depth

Discuss ROE, pretext crafting, landing page safety, and measurement ethics.

Project overview

A red team phishing simulation is credible penetration tester resume material because human-layer testing complements technical pentests and demonstrates controlled social engineering delivery.

GoPhish sent themed pretext emails to a segmented test group; landing pages mirrored internal SSO styling without capturing real passwords in production—submissions logged to an isolated collector; metrics compared departments and repeat clickers for targeted awareness follow-up.

On a resume, that gives you ways to describe campaign approval workflows, domain allowlisting, safe credential handling, executive briefing decks, and coordination with IT to avoid incident response false alarms.

Architecture overview

Project flow
1Approve

ROE and approval

Legal and IT signed scope defining targets, timing, and data handling before send.

2Pretext

Pretext development

Email templates mirror realistic internal scenarios without deceptive malware attachments.

3Launch

GoPhish campaign

Tracking links and landing pages hosted on authorized infrastructure with TLS.

4Measure

Metric collection

Open, click, and submission rates aggregated by department and role.

5Safety

Safe handling

Submitted credentials routed to isolated test storage with immediate purge policy.

6Report

Leadership report

Executive deck covers results, repeat offenders, and training recommendations.

What this project includes

  • Signed rules of engagement for phishing
  • GoPhish campaign with tracking metrics
  • Realistic pretext and landing page design
  • Department-level click and submission rates
  • Safe credential handling and purge policy
  • Executive awareness report with training plan

Tech stack

Phishing simulation stacks on GoPhish and reporting—not SIEM detection rule authoring.

GoPhishSocial EngineeringEmail AnalysisTLS CertificatesReporting DashboardAwareness Training

GoPhish

Orchestrates email campaigns, landing pages, and engagement metrics.

Social Engineering

Frames pretext realism and human-layer attack methodology.

Email Analysis

Reviews header and link patterns to improve future pretext quality.

TLS Certificates

Serves landing pages over HTTPS on authorized simulation domains.

Reporting Dashboard

Exports metrics for leadership and awareness team consumption.

Awareness Training

Connects simulation results to targeted follow-up curricula.

Features implemented

Authorized scope

Signed ROE prevents accidental production impact or legal exposure.

Department metrics

Segmented results identify where training investment helps most.

Realistic pretexts

Internal-themed scenarios measure actual susceptibility.

Safe credential flow

Isolated collectors and purge policies protect participant data.

IR coordination

IT aware of simulation reduces false-positive escalation.

Repeat clicker tracking

Follow-up targets users who fail multiple simulations.

Resume bullet examples

These bullets present phishing work as authorized red team delivery.

  • Designed and executed authorized red team phishing simulation with GoPhish, achieving measurable click and credential submission rates segmented by department for leadership review.
  • Crafted realistic internal-themed pretext emails and landing pages within signed ROE, coordinating with IT to prevent false-positive incident response escalations.
  • Delivered executive report with susceptibility metrics, repeat-offender identification, and targeted security awareness training recommendations.
  • Implemented safe credential collection with isolated storage and immediate purge policy aligned to legal and privacy requirements.
Generate bullets from your project

Skills demonstrated

This project demonstrates social engineering simulation, GoPhish, and red team reporting.

Red Team

phishing simulationGoPhishsocial engineeringpretext design

Governance

rules of engagementIR coordinationsafe data handlinglegal approval

Reporting

awareness metricsexecutive briefingtraining plansdepartment analysis

ATS keywords extracted from this project

Use red team and phishing keywords—not SOC triage or detection engineering terms.

red teamphishing simulationGoPhishsocial engineeringsecurity awarenesspenetration testingpretextphishing assessmentpenetration testerhuman layer testingcampaign metrics

Interview questions based on this project

Phishing simulations invite ROE and ethics questions.

How did you keep the simulation ethical?

Signed ROE defined recipients, timing, and data handling; IT knew the window; credentials went to isolated test storage with immediate purge.

What metrics mattered most?

Submission rate by department and repeat clickers—opens alone are weak signals of real risk.

How did you avoid IR chaos?

Pre-campaign briefing with SOC and helpdesk included campaign indicators and sender domains.

How would you improve it?

Follow with vishing or physical tailgating modules in a broader red team program.

Common mistakes

SOC phishing triage framing

Describe offensive simulation delivery—not inbound email analysis playbooks.

No ROE mention

Authorization and safe handling prove professional red team discipline.

Malware attachment focus

Modern sims often measure credential submission; clarify your pretext type.

Missing metrics

Department rates and leadership reporting show business value.

FAQ

Is a phishing simulation a good pentest resume project?

Yes. Social engineering is a standard red team and penetration testing competency.

Can I run GoPhish locally?

Yes. Lab campaigns with synthetic users demonstrate tooling and reporting skill.

Should I mention coordination with IT?

Yes. It shows operational maturity and reduces concern about reckless testing.

How many bullets should I use?

Two to four bullets on campaign design, metrics, ROE, and reporting.

Turn project details into resume evidence

Use this phishing simulation to strengthen your penetration tester resume

Present GoPhish campaigns, social engineering metrics, and recruiter-friendly red team reporting with stronger keyword alignment.

Free to start · No credit card required