Logo
GEICO

Senior Staff Engineer, Offensive Security (REMOTE)

GEICO, WorkFromHome

Save Job

Overview

Join to apply for the Senior Staff Engineer, Offensive Security (REMOTE) role at GEICO .

As a Senior Staff Engineer of Offensive Security, you'll be at the forefront of our cybersecurity strategy for penetration testing, advanced attack simulations, and enabling organization to prevent, detect, and respond to cyber threats. Your role is pivotal in shaping our security posture, collaborating closely with senior leadership to influence risk decisions and ensure regulatory readiness.

Base pay range

$120,000.00/yr - $260,000.00/yr

Responsibilities

  • Strategic and tactical leadership for highly effective penetration testing, simulating real-world cyber-attacks (red teaming), and collaborating with defensive security teams (purple teaming).
  • Conduct tactical security penetration test assessments to validate the security of company applications (web, mobile, APIs, and AI products) against OWASP Top 10 threats and work with the Application Security team to provide feedback and recommendations to increase automated capabilities.
  • Design and execute advanced threat emulation scenarios, including physical, social, and digital attack vectors.
  • Ensure penetration testing activities are meeting security, business, and compliance objectives and outcomes.
  • Guide the team on risk assessment, prioritization, reporting, and remediation of vulnerabilities through automation.
  • Collaborate with Blue Teams, Threat Intelligence, and Risk Management to ensure comprehensive attack coverage and feedback loops.
  • Ensure operations align with industry regulations and compliance standards such as NIST, PCI DSS, and NYDFS.
  • Champion continuous improvement and innovation in penetration testing, adversary simulation techniques, tools, and methodologies.
  • Represent the Offensive Security functions in senior leadership and audit discussions as a subject matter expert.
  • Offer technical leadership for 3rd party penetration testing programs by setting a high bar and overseeing vendor testing activities.

Required Qualifications

  • Mastery of vulnerability discovery and exploitation across applications, networks, and cloud using tools (e.g., Burp Suite, Metasploit), and custom scripts (Python, PowerShell).
  • Advanced understanding of OWASP, MITRE ATT&CK framework, software development lifecycle (SDLC), threat modeling, red/purple teaming, and attack path development.
  • Hands-on experience with tools like Cobalt Strike, Mythic, BloodHound, and AutoSploit.
  • Relevant professional security certifications (e.g. from GIAC or others).
  • Proven experience in achieving results efficiently through automation and establishing best practices.
  • Proven track record to deliver business outcomes for meeting regulatory and compliance obligations.
  • Ability to force multiply through coaching and mentorship to offensive security engineers across all functions (penetration testing, red teaming, purple teaming).

Preferred Qualifications

  • OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs.
  • GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus.
  • Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programming.
  • Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions).
  • Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections.

Required Experience

  • 10+ years in engineering focused role, preferably in the tech industry.
  • 8+ years of experience in offensive security (penetrating testing, red team, and purple team).
  • 5+ years of hands-on experience performing penetration-testing, red teaming, and purple teaming activities.
  • 4+ years of experience with Azure, AWS, GCP or other cloud providers.
  • Senior role influencing company direction on security.
  • Experience applying security controls to exceed third party attestation requirements (PCI, NYDFS, SOX …).

Education

  • Bachelor’s degree in Cybersecurity, Computer Science or a related field

Notes

The GEICO Pledge describes our approach to compensation, benefits and workplace culture, including protection against discrimination and commitments to accessibility and inclusion. GEICO hires and promotes individuals solely on the basis of qualifications for the job. GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and perform the essential functions of the job.

Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Finance and Sales

Industries

Insurance

At this time, GEICO will not sponsor a new applicant for employment authorization for this position.

#J-18808-Ljbffr