Red Team Phishing Simulation Resume Project Example
An authorized red team phishing simulation that cloned internal login flows with GoPhish, measured click and credential submission rates, delivered awareness metrics to leadership, and documented social engineering tradecraft within strict ROE.
Free to start · No credit card required
ELENA ROSSI
Penetration Tester
Project
Phishing sim
ROE-bound- Ran authorized phishing simulation with GoPhish.
- Measured click-through and submission rates by department.
- Reported social engineering risk with remediation training plan.
Why this project is valuable
Red team signal
Phishing simulations show social engineering methodology and metrics delivery—not SOC phishing triage playbooks alone.
Good ATS coverage
Supports red team, phishing simulation, social engineering, GoPhish, and security awareness keywords.
Leadership-ready metrics
Click and submission rates by department drive training investment decisions.
Good interview depth
Discuss ROE, pretext crafting, landing page safety, and measurement ethics.
Project overview
A red team phishing simulation is credible penetration tester resume material because human-layer testing complements technical pentests and demonstrates controlled social engineering delivery.
GoPhish sent themed pretext emails to a segmented test group; landing pages mirrored internal SSO styling without capturing real passwords in production—submissions logged to an isolated collector; metrics compared departments and repeat clickers for targeted awareness follow-up.
On a resume, that gives you ways to describe campaign approval workflows, domain allowlisting, safe credential handling, executive briefing decks, and coordination with IT to avoid incident response false alarms.
Architecture overview
Project flowROE and approval
Legal and IT signed scope defining targets, timing, and data handling before send.
Pretext development
Email templates mirror realistic internal scenarios without deceptive malware attachments.
GoPhish campaign
Tracking links and landing pages hosted on authorized infrastructure with TLS.
Metric collection
Open, click, and submission rates aggregated by department and role.
Safe handling
Submitted credentials routed to isolated test storage with immediate purge policy.
Leadership report
Executive deck covers results, repeat offenders, and training recommendations.
What this project includes
- Signed rules of engagement for phishing
- GoPhish campaign with tracking metrics
- Realistic pretext and landing page design
- Department-level click and submission rates
- Safe credential handling and purge policy
- Executive awareness report with training plan
Tech stack
Phishing simulation stacks on GoPhish and reporting—not SIEM detection rule authoring.
GoPhish
Orchestrates email campaigns, landing pages, and engagement metrics.
Social Engineering
Frames pretext realism and human-layer attack methodology.
Email Analysis
Reviews header and link patterns to improve future pretext quality.
TLS Certificates
Serves landing pages over HTTPS on authorized simulation domains.
Reporting Dashboard
Exports metrics for leadership and awareness team consumption.
Awareness Training
Connects simulation results to targeted follow-up curricula.
Features implemented
Authorized scope
Signed ROE prevents accidental production impact or legal exposure.
Department metrics
Segmented results identify where training investment helps most.
Realistic pretexts
Internal-themed scenarios measure actual susceptibility.
Safe credential flow
Isolated collectors and purge policies protect participant data.
IR coordination
IT aware of simulation reduces false-positive escalation.
Repeat clicker tracking
Follow-up targets users who fail multiple simulations.
Resume bullet examples
These bullets present phishing work as authorized red team delivery.
- Designed and executed authorized red team phishing simulation with GoPhish, achieving measurable click and credential submission rates segmented by department for leadership review.
- Crafted realistic internal-themed pretext emails and landing pages within signed ROE, coordinating with IT to prevent false-positive incident response escalations.
- Delivered executive report with susceptibility metrics, repeat-offender identification, and targeted security awareness training recommendations.
- Implemented safe credential collection with isolated storage and immediate purge policy aligned to legal and privacy requirements.
Skills demonstrated
This project demonstrates social engineering simulation, GoPhish, and red team reporting.
Red Team
Governance
Reporting
ATS keywords extracted from this project
Use red team and phishing keywords—not SOC triage or detection engineering terms.
Interview questions based on this project
Phishing simulations invite ROE and ethics questions.
How did you keep the simulation ethical?
Signed ROE defined recipients, timing, and data handling; IT knew the window; credentials went to isolated test storage with immediate purge.
What metrics mattered most?
Submission rate by department and repeat clickers—opens alone are weak signals of real risk.
How did you avoid IR chaos?
Pre-campaign briefing with SOC and helpdesk included campaign indicators and sender domains.
How would you improve it?
Follow with vishing or physical tailgating modules in a broader red team program.
Common mistakes
Describe offensive simulation delivery—not inbound email analysis playbooks.
Authorization and safe handling prove professional red team discipline.
Modern sims often measure credential submission; clarify your pretext type.
Department rates and leadership reporting show business value.
FAQ
Is a phishing simulation a good pentest resume project?
Yes. Social engineering is a standard red team and penetration testing competency.
Can I run GoPhish locally?
Yes. Lab campaigns with synthetic users demonstrate tooling and reporting skill.
Should I mention coordination with IT?
Yes. It shows operational maturity and reduces concern about reckless testing.
How many bullets should I use?
Two to four bullets on campaign design, metrics, ROE, and reporting.
Turn project details into resume evidence
Use this phishing simulation to strengthen your penetration tester resume
Present GoPhish campaigns, social engineering metrics, and recruiter-friendly red team reporting with stronger keyword alignment.
Free to start · No credit card required
