Talent.com
Senior Staff Engineer, Offensive Security (REMOTE)

Senior Staff Engineer, Offensive Security (REMOTE)

GEICOBoston, MA, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
  • serp_jobs.filters.remote
job_description.job_card.job_description

Overview

Senior Staff Engineer, Offensive Security (REMOTE)

3 days ago Be among the first 25 applicants

This range is provided by GEICO. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$120,000.00 / yr - $260,000.00 / yr

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose.

When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge : Great Company, Great Culture, Great Rewards and Great Careers.

As a Senior Staff Engineer of Offensive Security, you'll be at the forefront of our cybersecurity strategy for penetration testing, advanced attack simulations, and enabling organization to prevent, detect, and respond to cyber threats. Your role is pivotal in shaping our security posture, collaborating closely with senior leadership to influence risk decisions and ensure regulatory readiness.

We seek a hands-on engineer with deep technical expertise in penetration testing, real-world adversary tactics, and risk frameworks, capable of driving measurable improvements in our cyber resilience. Candidates are expected to have hands-on penetration testing experience while leading the team to perform overall offensive security functions including red and purple teaming. The ideal candidate must possess a highly technical skillset and the ability to collaborate with stakeholders across the company to integrate penetration testing and other offensive security functions within company processes.

You'll challenge the status quo, identifying opportunities to elevate our security engineering excellence through automation and innovative approaches. Your ability to think big, anticipate and adapt change, and address root causes will be key to delivering greater business value while proactively examining actions and refining approaches.

In this high-stakes environment, you'll ensure implementation of industry best practices and execution of offensive security functions while meeting regulatory compliance requirements. This role offers a unique opportunity to expand your influence, forge critical alliances, and lead the evolution of offensive security in a fast-paced environment. Your impact will be felt across the organization as you strengthen our defenses against ever-evolving cyber threats through simulation of real-world cyberattacks and attempts to breach the organization's defenses.

Responsibilities

  • Strategic and tactical leadership for highly effective penetration testing, simulating real-world cyber-attacks (red teaming), and collaborating with defensive security teams (purple teaming).
  • Conduct tactical security penetration test assessments to validate the security of company applications (web, mobile, APIs, and AI products) against OWASP Top 10 threats and work with the Application Security team to provide feedback and recommendations to increase automated capabilities.
  • Design and execute advanced threat emulation scenarios, including physical, social, and digital attack vectors.
  • Ensure penetration testing activities are meeting security, business, and compliance objectives and outcomes.
  • Guide the team on risk assessment, prioritization, reporting, and remediation of vulnerabilities through automation.
  • Collaborate with Blue Teams, Threat Intelligence, and Risk Management to ensure comprehensive attack coverage and feedback loops.
  • Ensure operations align with industry regulations and compliance standards such as NIST, PCI DSS, and NYDFS.
  • Champion continuous improvement and innovation in penetration testing, adversary simulation techniques, tools, and methodologies.
  • Represent the Offensive Security functions in senior leadership and audit discussions as a subject matter expert.
  • Offer technical leadership for 3rd party penetration testing programs by setting a high bar and overseeing vendor testing activities.

Required Qualifications

  • Mastery of vulnerability discovery and exploitation across applications, networks, and cloud using tools (e.g., Burp Suite, Metasploit), and custom scripts (Python, PowerShell).
  • Advanced understanding of OWASP, MITRE ATT&CK framework, software development lifecycle (SDLC), threat modeling, red / purple teaming, and attack path development.
  • Hands-on experience with tools like Cobalt Strike, Mythic, BloodHound, and AutoSploit.
  • Relevant professional security certifications (e.g. from GIAC or others).
  • Proven experience in achieving results efficiently through automation and establishing best practices.
  • Proven track record to deliver business outcomes for meeting regulatory and compliance obligations.
  • Ability to force multiply through coaching and mentorship to offensive security engineers across all functions (penetration testing, red teaming, purple teaming).
  • Preferred Qualifications

  • OSCP, OSCE, CRTO, CISSP, or relevant Red Team / offensive security certs.
  • GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus.
  • Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programming.
  • Advanced level knowledge of Linux / Mac / Windows operating systems, AWS / Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)
  • Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections.
  • Required Experience

  • 10+ years in engineering focused role, preferably in the tech industry.
  • 8+ years of experience in offensive security (penetrating testing, red team, and purple team).
  • 5+ years of hands-on experience performing penetration-testing, red teaming, and purple teaming activities.
  • 4+ years of experience with Azure, AWS, GCP or other cloud providers.
  • Senior role influencing company direction on security.
  • Experience applying security controls to exceed third party attestation requirements (PCI, NYDFS, SOX …).
  • Education

  • Bachelor’s degree in Cybersecurity, Computer Science or a related field
  • Annual Salary

    $120,000.00 - $260,000.00

    The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate / annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.

    At this time, GEICO will not sponsor a new applicant for employment authorization for this position.

    The GEICO Pledge

    Great Company : At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs.

    We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives.

    Great Careers : We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career – and your potential – in mind. You’ll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels.

    Great Culture : We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose. As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers.

    Great Rewards : We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future.

  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being.
  • Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance.
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.
  • The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

    GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and / or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

    Seniority level

  • Mid-Senior level
  • Employment type

  • Full-time
  • Job function

  • Finance and Sales
  • Industries
  • Insurance
  • Referrals increase your chances of interviewing at GEICO by 2x

    Get notified about new Senior Financial Engineer jobs in Boston, MA.

    Staff Engineer - Finance Data Specialist (Remote)

    Boston, MA $115,000.00-$260,000.00 1 hour ago

    We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

    #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Staff Security Engineer • Boston, MA, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityBoston, MA, United States
    serp_jobs.job_card.full_time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Principal Cyber Security Engineer

    Principal Cyber Security Engineer

    RaftHanscom Air Force Base, MA, United States
    serp_jobs.job_card.full_time
    All of the programs we support require.All work must be conducted within the continental U.Distributed Data Systems, Platforms at Scale, and Complex Application Development, with headquarters in Mc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    LearnLuxBoston, MA, US
    serp_jobs.job_card.full_time
    LearnLux is the leading provider of workplace financial wellbeing that blends fiduciary digital planning with access to one-on-one guidance from Certified Financial Planner™️ professionals.Le...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Engineer, Reliability Engineering

    Senior Engineer, Reliability Engineering

    RaytheonTewksbury, MA, United States
    serp_jobs.job_card.full_time
    MA134 : Innovation Dr Tewks Bdg 400 836 North Street Building 400, Tewksbury, MA, 01876 USA.Person, or Immigration Status Requirements : . At Raytheon, the foundation of everything we do is rooted in o...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,455 per week in Gloucester, MA

    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,455 per week in Gloucester, MA

    TravelNurseSourceGloucester, MA, US
    serp_jobs.job_card.full_time
    TravelNurseSource is working with CrossMed Healthcare to find a qualified ER / Trauma RN in Gloucester, Massachusetts, 01930!. At CrossMed Healthcare Staffing, we aim to create lasting impressions whe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,577 per week in Gloucester, MA

    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,577 per week in Gloucester, MA

    TravelNurseSourceGloucester, MA, US
    serp_jobs.job_card.full_time +1
    TravelNurseSource is working with AHS Staffing to find a qualified ER / Trauma RN in Gloucester, Massachusetts, 01930!.AHS Staffing is looking for a Emergency Room Registered Nurse in Gloucester, MA ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    GCP Security Engineer

    GCP Security Engineer

    Publicis SapientBoston, MA, United States
    serp_jobs.job_card.full_time
    Seeking an experienced Google Cloud Security Engineer to design, implement, and manage enterprise-grade security solutions within Google Cloud Platform (GCP). The ideal candidate holds a GCP Profess...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,345 per week in Gloucester, MA

    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,345 per week in Gloucester, MA

    TravelNurseSourceGloucester, MA, US
    serp_jobs.job_card.full_time
    TravelNurseSource is working with Triage Staffing to find a qualified ER / Trauma RN in Gloucester, Massachusetts, 01930!. Travel Nursing : Emergency Department Gloucester.Shift Details : 12H Nights (...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityBoston, MA, United States
    serp_jobs.job_card.full_time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Security Engineer

    Security Engineer

    Lever Demo - IS OpportunitiesBoston, Massachusetts, United States, 02108
    serp_jobs.job_card.full_time
    PLEASE READ : these jobs are testing jobs of Lever's testing environment - please do not apply for this job.Lever was founded ten years ago to tackle the most strategic challenge that companies face...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Manager

    Senior Security Manager

    SanofiCambridge, MA, US
    serp_jobs.job_card.full_time
    Ready to push the limits of what's possible? Join Sanofi in one of our corporate functions and you can play a vital part in the performance of our entire business while helping to make an impact on...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,869 to $2,937 per week in Essex, MA

    Travel Nurse RN - Emergency Room (ER) / Trauma - $2,869 to $2,937 per week in Essex, MA

    TravelNurseSourceEssex, MA, US
    serp_jobs.job_card.full_time
    TravelNurseSource is working with MUVE Healthcare LLC to find a qualified ER / Trauma RN in Essex, Massachusetts, 01915!. Join our team for an exciting travel nursing opportunity!.As a member of the i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    System Security Engineer

    System Security Engineer

    Draper LabsCambridge, MA, United States
    serp_jobs.job_card.full_time
    Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    Mastech DigitalSomerville, MA, US
    serp_jobs.job_card.full_time
    The Information Security Engineer II – Cloud Incident Responder tackles moderately complex security engineering challenges within their domain. They maintain and enhance existing security cont...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Information Security Engineer (Somerville)

    Information Security Engineer (Somerville)

    Mastech DigitalSomerville, MA, US
    serp_jobs.job_card.part_time
    The Information Security Engineer II Cloud Incident Responder tackles moderately complex security engineering challenges within their domain. They maintain and enhance existing security controls wh...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Engineer, Corporate Services Security

    Security Engineer, Corporate Services Security

    AmazonBoston, MA, United States
    serp_jobs.job_card.full_time
    Security Engineer, Corporate Services Security — Job ID : 3098656 | Amazon.Location : Boston, MA, USA (open to candidates to work out of one of the following locations). Corporate Services Security (C...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior System Security Engineer

    Senior System Security Engineer

    Draper LabsCambridge, MA, United States
    serp_jobs.job_card.full_time
    Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Systems Engineer - MA Onsite

    Senior Systems Engineer - MA Onsite

    RaytheonAndover, MA, United States
    serp_jobs.job_card.full_time
    MA101 : Andover MA 350 Lowell St Essex 350 Lowell Street Essex, Andover, MA, 01810 USA.Person, or Immigration Status Requirements : . At Raytheon, the foundation of everything we do is rooted in our va...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours