Overview
Senior Staff Engineer, Offensive Security (REMOTE) at GEICO. This role focuses on penetration testing, adversary simulation, and building a secure, compliant security program across the organization.
Responsibilities
- Strategic and tactical leadership for penetration testing (red teaming) and collaboration with defensive security teams (purple teaming).
- Conduct practical security assessments of applications (web, mobile, APIs, AI products) against OWASP Top 10; work with the Application Security team to improve automated capabilities.
- Design and execute advanced threat emulation scenarios, including physical, social, and digital attack vectors.
- Ensure penetration testing activities meet security, business, and compliance objectives.
- Guide risk assessment, prioritization, reporting, and remediation of vulnerabilities through automation.
- Collaborate with Blue Teams, Threat Intelligence, and Risk Management to ensure comprehensive attack coverage.
- Ensure operations align with industry regulations and standards (e.g., NIST, PCI DSS, NYDFS).
- Champion continuous improvement in penetration testing, adversary simulation techniques, tools, and methodologies.
- Represent Offensive Security in senior leadership and audit discussions as a subject matter expert.
- Provide technical leadership for 3rd party penetration testing programs, overseeing vendor testing activities.
Required Qualifications
Mastery of vulnerability discovery and exploitation across applications, networks, and cloud using tools (e.g., Burp Suite, Metasploit) and custom scripts (Python, PowerShell).Advanced understanding of OWASP, MITRE ATT&CK, SDLC, threat modeling, red / purple teaming, and attack path development.Hands-on experience with tools like Cobalt Strike, Mythic, BloodHound, AutoSploit.Relevant professional security certifications (e.g., GIAC or equivalent).Proven ability to deliver results through automation and best practices.Experience delivering business outcomes for regulatory and compliance obligations.Ability to coach and mentor offensive security engineers across functions (penetration testing, red team, purple team).Preferred Qualifications
OSCP, OSCE, CRTO, CISSP, or relevant Red Team / offensive security certifications.GIAC Penetration Testing and Red Team certifications (GCTI, GPEN, GXPN) a plus.Broad knowledge of security across OSI layers, networking, firewalls, databases, forensics, scripting, and programming.Advanced knowledge of Linux / Mac / Windows, AWS / Azure, cloud-native resources (containers, Kubernetes, microservices, serverless).Experience reversing mobile applications, including anti-emulation and obfuscation protections.Required Experience
10+ years in an engineering-focused role; 8+ years in offensive security (penetration testing, red team, purple team).5+ years hands-on experience in penetration testing, red teaming, and purple teaming activities.4+ years of experience with Azure, AWS, GCP or other clouds.Senior-level influence on security direction; experience applying security controls to meet third-party attestations (PCI, NYDFS, SOX, etc.).Education
Bachelor’s degree in Cybersecurity, Computer Science or a related field.Annual Salary
$120,000.00 - $260,000.00
The above range is a general guideline. The final offer will consider experience, scope, location, and market factors. GEICO does not sponsor new employment authorization for this position at this time.
The GEICO Pledge
Great Company : GEICO helps customers through life’s twists and turns with a mission to protect people when they need it most, and we stay ahead through ongoing innovation.
Great Careers : Opportunities for learning, growth, and development, with mentorship and coaching from leaders at all levels.
Great Culture : An inclusive culture rooted in integrity, action, and a shared purpose, with recognition programs and a focus on belonging.
Great Rewards : Comprehensive benefits and compensation designed to support well-being and financial security, with flexible work options.
Comprehensive Total Rewards tailored to you and your family.Competitive compensation, 401K with 6% match, incentives, and tuition assistance.Mental health support, fertility and adoption assistance.GEICO Flex program allowing up to four weeks of remote work per year.Equal Employment Opportunity
GEICO provides fair and equal employment opportunity for all associates and applicants regardless of race, color, religious creed, national origin, age, gender, pregnancy, sexual orientation, gender identity, marital status, disability or genetic information, in compliance with law. We hire based on qualifications and provide reasonable accommodations where needed.
Seniority level : Mid-Senior level
Employment type : Full-time
Job functions : Finance and Sales; Industries : Insurance
#J-18808-Ljbffr