Senior Offensive Security Engineer (Red Team)
$96k - $181kKeybank, National Association
Senior Offensive Security Engineer
Location: 4910 Tiedeman Road, Brooklyn Ohio
Serves as the senior process owner for vulnerability management and incident response activities for the entire organization. All associated efforts are to promote and advance an information security processes, culture and must reflect compliance with best practices, applicable federal and industry regulations, as well as company information security policies and standards.
Position Summary
Our Cyber Adversary and Exposure Mgmt. team rolls up into Key's broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat centric defense.
Key Responsibilities
- Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.
- Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.
- Conduct physical, external/internal, and wireless network assessments, as well as web and mobile application testing.
- Perform security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS) and embedded systems.
- Develop and test threat actor emulation tools, tactics, and procedures for the Red Team to employ on-demand in assessments of application, system, and network security controls.
- Employ these tools and techniques in the KeyBank environment with minimal supervision.
- Partner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape.
- Consult with cross-functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats.
- Coordinate and monitor third-party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting.
- Generate and publish Red Team metrics and reporting to track program effectiveness and stakeholder visibility.
- Lead efforts to track remediation of findings to completion through coordination with application and technology system owners.
- Expand the team's capabilities through: - Creation of custom tools and automation frameworks. - Research and development of novel offensive techniques and tradecraft. - Incorporation of threat actor intelligence into emulation scenarios. - Delivery of internal presentations and knowledge-sharing sessions.
- Collaborate with the Cyber Threat Intelligence team to translate real-world TTPs into emulation plans.
- Evaluate the effectiveness of detection and response capabilities across SOC, EDR, SIEM, and other security layers.
- Provide detailed post-mortem reports and executive briefings with prioritized recommendations.
- Mentor junior team members and contribute to the development of adversarial tradecraft within the team.
- Partner with blue teams to conduct purple team exercises and improve detection engineering.
- Contribute to the continuous improvement of adversarial emulation methodologies, tooling, and documentation.
Required Qualifications
- Bachelor's degree or equivalent work experience.
- 8+ years of experience in Red Team or Penetration Testing roles.
- Proficiency with Red Team tools and Command & Control (C2) frameworks.
- Strong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang or similar languages.
- Deep understanding of Windows, Linux, Kali Linux, and macOS operating systems.
- Hands-on experience with one or more of the following:
- Google Cloud, Microsoft Azure, and AWS platforms.
- Advanced networking knowledge and experience with attack simulation.
- Familiarity with the MITRE ATT&CK framework and adversary TTPs.
- Deep understanding of one or more Penetration Testing Methodologies such as PTES, ISECOM, ISSAF, and OSSTMM
- Strong research and reporting skills.
- Willingness to travel for on-site assessments.
Preferred Certifications
- Offensive Security Certified Professional (OSCP)
- Offensive Security Certified Expert (OSCE)
- Offensive Security Experienced Penetration Tester (OSEP)
- Certified Red Team Professional (CRTP)
- GIAC Penetration Tester (GPEN)
- GIAC Web Application Penetration Tester (GWAPT)
- CREST Registered Penetration Tester / CBEST Qualifications
Work Location Category
- Hybrid (2+ days)
Compensation and Benefits
This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.
Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.
Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing View email address on click.appcast.io.
$86.5k - $166k
PwC South Africa is looking for a professional specializing in Offensive Security for a role centered on enhancing resilience against cyber threats. The position entails conducting assessments through Red Team operations, identifying areas for improvement, and fostering...Senior$86.5k - $166k
Overview At PwC, our people in Offensive Security focus on improving the organization’s resilience... ...remediate cyber threats. Those in the Red Team at PwC will focus on simulating... ...the principles of information security engineering, architecture, and application security...Senior- ...2 days on campus and 3 days WFH OverDrive is hiring a Security Engineer to help build, tune, and respond to SIEM detections for our... ...Collaboration, metrics, and enablement Collaborate with red-team members in the creation of behavior-based signatures in...SeniorWork from home
- ...Senior Security Engineer We're standing up a dedicated vulnerability management practice at one of the largest banks in the US, automating what two vendor teams currently do by hand, and building the AI layer that takes it further. The work is hands-on, the impact is...SeniorPermanent employmentLocal area
$57.1k - $154.3k
...Senior Security Engineer Category: Cyber Security Main location: United States, Pennsylvania, Various Alternate Location(s): United... ...of the largest banks in the US, automating what two vendor teams currently do by hand, and building the AI layer that takes...SeniorPermanent employmentFull timeLocal areaImmediate start$107k - $214.5k
...are currently looking for team members to join our Security, Privacy, and Risk... ...penetration testing, social engineering campaigns (email, web, phone... ...and verbal) findings to senior management and clients... ...Penetration Tester (GPEN); Offensive Security Certified Professional...Work experience placementLocal area$77.5k - $140.9k
Ernst & Young Oman is looking for an Application Security Engineer to manage development platforms and enhance application security. You will... ...within CI/CD pipelines and work with cross-functional teams. Extensive experience in application security tools and cloud...Senior- ...A typical day of a Security Engineer revolves around system changes, lifecycle of firewalls, and the user VPN environment. It is the responsibility of this individual for device monitoring and response, proactive fault management, vendor engagement, vulnerabilities, and...SeniorLong term contractContract workLocal areaRemote workNight shiftWeekend work
$76.4k - $138.6k
...connected powerhouse of diverse teams and take your career wherever... ...everyone in EY Information Security has a critical role to play. Join... ...The opportunity As an Offensive Security Analyst on the Vulnerability... ...in vulnerability management, red team, or purple team...Summer holidayLocal areaFlexible hours$95.86k - $208.27k
...adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people... .... KPMG is currently seeking a Senior Specialist, MAST Application Penetration... ...), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive...SeniorH1bLocal area$60 per hour
...Description Our client is looking to add a Sr. Network Security Engineers to their Network Security Engineering team. team responsible for securing, governing, and... ...cyber defense efforts and maintain awareness of red team / purple team / blue team functions Contribute...Contract workTemporary workWeekend work- A leading digital content provider in Cleveland, OH, is looking for a Security Engineer to enhance SIEM detection and response. Responsibilities include investigating alerts, leading incident response, and building SIEM dashboards. Candidates should have over 5 years of...SeniorRemote work
- A leading technology solutions provider is looking for a Mid-Senior level Scrum Master to guide multiple Agile teams in delivering innovative AI-based products. The successful candidate will lead Scrum ceremonies, coach teams on Agile principles, and facilitate continuous...Senior
- A leading architecture firm in Cleveland is seeking a Senior Architect to manage projects and mentor a team. The ideal candidate will have over 10 years of architecture experience, strong project management skills, and knowledge of local building codes. Responsibilities...SeniorLocal area
- ...seeking a Housekeeping Department Head in Cleveland to manage daily hotel housekeeping operations. This full-time role involves leading a team of over 100 employees while upholding cleanliness and safety standards. Candidates must have five years of housekeeping management...SeniorFull time
$124k - $280k
...identify vulnerabilities, develop secure systems, and provide... ...performing, diverse, and inclusive teams, and your commitment to... ...part of the Cyber Defense and Engineering team, you will lead large-scale... ...security transformation. As a Senior Manager, you will serve as a...SeniorFull timeH1b- Golden Reserve, located in Independence, Ohio, is seeking an experienced paraplanner and client services team manager to lead its growing paraplanner team. This full-time role requires 50% leadership management alongside paraplanning duties. Candidates must have extensive...SeniorFull time
$77k - $202k
...identify vulnerabilities, develop secure systems, and provide... ...anticipate the needs of your teams and clients, and to deliver quality... ..., and cyber resilience. As a Senior Associate, you will analyze... ...Computer Science, Electrical Engineering, Industrial Engineering, Industrial...SeniorFull timeH1b- A global professional services firm is looking for a Cloud Security Consultant based in Cleveland, Ohio. The role involves guiding the... ...hybrid work model, promoting collaboration with various project teams. Comprehensive benefits and competitive compensation are offered...Senior
$170.6k - $390k
...globally connected powerhouse of diverse teams and take your career wherever you... ...grow your career in information security! The opportunity The Senior Network Security Architect is a... ...a Senior Manager in Cybersecurity Engineering, where you will play a pivotal...SeniorSummer holidayRemote workFlexible hours$77.5k - $140.9k
...help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application...SeniorSummer holidayFlexible hours- Senior Cloud Security Architect- Cleveland, OH, Austin, TX or Atlanta, GA Cleveland, OH, USA Job Description... ...architecture. Partners with cloud engineering, platform engineering, DevOps, Risk & Compliance, and product teams to build secure‑by‑default patterns, guardrails...SeniorRemote workHome office
- Arganteal Corporation is hiring a Senior Branch Physical Security Architect for a full-time remote position based in Cleveland, OH. In this role, you will lead architectural direction for physical security technologies across a banking retail branch network, ensuring compliance...SeniorRemote jobFull timeImmediate start
- ...Engineer Join CBX Solutions, the nation's leading provider of architectural doors, frames... ..., specialty products, and complete security integration services. At CBX Solutions, trust... ...service, you'll thrive here. Be part of a team that invests in your future, celebrates your...For contractorsWork at office
- ...world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications,...
- DGL Consulting Engineers is seeking a Professional Surveyor in Independence, Ohio. This role involves providing land surveying expertise, mentoring junior staff, and managing survey projects. Candidates must have at least 10 years of experience in surveying and a valid...Senior
- BCG Attorney Search is seeking a highly experienced Commercial Trial Litigation Partner in Cleveland, OH, to lead complex litigation cases. The ideal candidate will manage high-stakes trials, mentor junior attorneys, and contribute to the firm's strategic growth. With a...Senior
- A hospitality company is seeking a Sous Chef to oversee specific kitchen operations at Hyatt Regency Cleveland. Key responsibilities include managing daily kitchen tasks, developing new menu items, and providing leadership to kitchen staff. The ideal candidate will possess...Senior
- CLE Consulting Firm is seeking a Senior Accountant in Cleveland, Ohio, responsible for client accounting and bookkeeping for various projects. The role involves leadership and expertise in delivering high-quality financial services. The ideal candidate will have a CPA...Senior
- A prominent wealth management firm in Beachwood, Ohio, seeks an experienced Wealth Advisor to serve high net-worth clients. Responsibilities include managing client engagements, executing investment strategies, and developing financial plans. Ideal candidates will have ...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Offensive Security Engineer (Red Team). Be the first to apply!
- sr information security engineer Cleveland, OH
- senior application security engineer Cleveland, OH
- aws cloud security engineer Cleveland, OH
- sr security engineer Cleveland, OH
- senior cloud security engineer Cleveland, OH
- IT security engineer Cleveland, OH
- information technology security engineer Cleveland, OH
- network security engineer Cleveland, OH
- security engineer Cleveland, OH
- senior security operations engineer Cleveland, OH

