Logo
GEICO

Senior Manager, Offensive Security

GEICO, Chevy Chase, Maryland, United States, 20815

Save Job

GEICO .

For more information, please .**At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.****Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose.****When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.**As a Senior Manager of Offensive Security, you'll be at the forefront of our cybersecurity strategy, leading a skilled team in penetration testing and advanced attack simulations. Your role is pivotal in shaping our security posture, collaborating closely with senior leadership to influence risk decisions and ensure regulatory readiness.We seek a hands-on leader with deep technical expertise in penetration testing, real-world adversary tactics, and risk frameworks, capable of driving measurable improvements in our cyber resilience. Candidates are expected to have hands-on penetration testing experience while leading the team to perform overall offensive security functions. The ideal candidate must possess a highly technical skillset and the ability to collaborate with stakeholders across the company to integrate penetration testing and other offensive security functions within company processes.Your strategic vision will be crucial in crafting and executing a 3-year plan that delivers incremental business outcomes through data-driven decisions. You'll challenge the status quo, identifying opportunities to elevate our security engineering excellence through automation and innovative approaches. Your ability to think big, anticipate and adapt change, and address root causes will be key to delivering greater business value while proactively examining actions and refining approaches.In this high-stakes environment, you'll develop talent, refine attack methodologies, and ensure efficient execution of offensive security functions while meeting compliance requirements. This role offers a unique opportunity to expand your executive influence, forge critical alliances, and lead the evolution of offensive security in a fast-paced, dynamic setting. Your impact will be felt across the organization as you strengthen our defenses against ever-evolving cyber threats.**Responsibilities**:* Lead, mentor, and grow a high-performing offensive security team focused on highly effective penetration testing, simulating real-world cyber-attacks (red teaming), and collaborating with defensive security teams (purple teaming).* Conduct tactical security penetration test assessments to validate the security of company applications (web, mobile, and APIs) against OWASP Top 10 threats and work with the Application Security team to provide feedback and recommendations to increase automated capabilities.* Design and execute advanced threat emulation scenarios, including physical, social, and digital attack vectors.* Establish business outcome-oriented penetration testing roadmap, lead the scoping and execution of program improvement initiatives, and regularly review roadmap and communicate status to leadership.* Ensure penetration testing activities are meeting security and business objectives and outcomes by establishing metrics & key performance indicators (KPIs) while delivering results on time.* Oversee the communication and develop automated reporting/tracking of findings identified during testing activities, following up with remediation teams to determine status, escalating findings as needed to senior leadership to deliver timely results.* Collaborate with Blue Teams, Threat Intelligence, and Risk Management to ensure comprehensive attack coverage and feedback loops.* Ensure operations align with industry regulations and compliance standards such as NIST, PCI DSS, and NYDFS.* Champion continuous improvement and innovation in penetration testing, adversary simulation techniques, tools, and methodologies.* Represent the Offensive Security functions in senior leadership and audit discussions as a subject matter expert.* Manage the 3rd party penetration testing program by identifying vendors, overseeing vendor testing activities and working with Sourcing to develop statement of work documentation and procure such services.**Required Qualifications:*** Mastery of vulnerability discovery and exploitation across applications, networks, and cloud using tools (e.g., Burp Suite, Metasploit), and custom scripts (e.g. Python, Shell).* Advanced understanding of OWASP, MITRE ATT&CK framework, software development lifecycle (SDLC), threat modeling, red/purple teaming, and attack path development.* Hands-on experience with tools like Cobalt Strike, Mythic, BloodHound, and AutoSploit.* Relevant professional security certifications.* Proven experience building and guiding high performing offensive security teams, achieving results efficiently through automation, and establishing best practices (scoping, ROE, deconfliction).* Proven track record to deliver business outcomes for meeting regulatory and compliance obligations.* Ability to hire talent who have right mix of offensive security functions (penetration testing, red teaming, purple teaming) and align their skills to evolving business priorities.**Preferred** **Qualifications****:*** OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs.* GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus.* Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.* Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)* Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections.**Required Experience:*** 10+ years of building, leading, and managing security or software engineering teams.* 8+ years of experience leading offensive security teams (penetrating testing, red team, and purple team).* 5+ years of hands-on experience performing penetration-testing, red teaming, and purple teaming activities.* 4+ years of experience with Azure, AWS, GCP or other cloud providers.* Senior role influencing company direction on security.* Experience applying security controls to exceed third party attestation requirements (PCI, NYDFS, SOX …).**Education:*** Bachelor’s degree in Cybersecurity, Computer Science or a related field.**Annual Salary**$150,000.00 - $300,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.**The GEICO Pledge:****Great Company:** At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs.We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives.**Great Careers:** We offer a career where you can learn, grow, #J-18808-Ljbffr