Senior Offensive Security Engineer (Red Team)
$96k - $181kKeyCorp
Location: 4910 Tiedeman Road, Brooklyn Ohio
Position Summary
Our Cyber Adversary and Exposure Management team rolls up into Key’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense. The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense Red Team and is responsible for guiding team execution, capability development, operational maturity, and offensive security strategy. The role is responsible for advancing the maturity, consistency, and effectiveness of adversarial simulation, red team, and penetration testing capabilities while providing day-to-day leadership for team execution. The role establishes testing strategy and standards, guides engagement planning and quality, coordinates priorities and resources, mentors team members, and drives measurable improvement across the offensive security program. The role also supports Continuous Threat Exposure Management (CTEM) objectives by validating prioritized exposures, assessing attack paths, and measuring the effectiveness of remediation activities against realistic adversary scenarios. The role also simulates advanced cyber adversaries and emulates real-world adversaries to assess and improve KeyBank’s detection, response, and resilience capabilities. This work goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes. The ideal candidate will bring significant experience directing adversary emulation, red team engagements, and offensive security operations across enterprise on-premises and cloud environments, with experience leading or participating in physical security assessments. The role demands exceptional technical proficiency, strategic leadership, operational discipline, and the ability to clearly articulate complex security findings and risk implications to audiences ranging from engineers to senior executives.
Key Responsibilities
Team Leadership & Operational Management
Provide day-to-day technical and operational team leadership for the Red Team, reporting to the CAEM manager, including work prioritization, engagement assignments, execution oversight, issue escalation, and coordination of team deliverables. Coach and mentor team members, facilitate knowledge sharing, identify capability gaps, and support development of technical depth and leadership readiness across the team. Provide third-party vendor support, dependencies, and stakeholder communications to keep engagements on track and ensure risks, blockers, and decisions are elevated promptly. Provide hands‑on technical guidance during complex engagements and reinforce safe, responsible, and repeatable adversarial tradecraft. Partner with Detection Engineering, Security Operations, Threat Intelligence, and Incident Response teams to conduct purple team exercises that validate control effectiveness, detection coverage, and response capabilities against real-world adversary behaviors.
Red Team Strategy, Governance & Program Maturity
Lead the development and execution of a maturity roadmap for adversarial simulation, red team, and penetration testing capabilities, including repeatable methodologies, standards, tooling, automation, and quality assurance practices. Establish and maintain a risk‑based testing strategy and engagement pipeline aligned with enterprise threats, critical assets, regulatory expectations, and stakeholder priorities. Define and report program metrics that demonstrate coverage, execution quality, remediation outcomes, control validation, and progress against the offensive security maturity roadmap. Use program metrics and engagement outcomes to identify trends, communicate risk, and prioritize improvements to testing coverage and team capabilities. Drive continuous improvement of adversarial emulation methodologies, tooling, documentation, and operating practices. Present offensive security program metrics, engagement outcomes, risk themes, and strategic recommendations to cybersecurity leadership, governance forums, and executive stakeholders. Align adversarial testing activities with exposure management priorities by validating remediation efforts, identifying exploitable attack paths, and measuring reductions in organizational exposure.
Adversarial Simulation & Red Team Operations
Lead and execute adversary emulation engagements using intelligence‑driven threat scenarios aligned with frameworks such as MITRE ATT&CK. Design and conduct full‑scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation. Conduct physical, external/internal, wireless network, web application, and mobile application security assessments. Lead security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS), identity infrastructure, privileged access management solutions, hybrid enterprise environments, and embedded systems. Develop and operationalize Red Team tooling, automation, and adversary emulation capabilities that replicate real‑world threat actor behaviors and enable repeatable assessment of application, cloud, infrastructure, and network security controls. Employ these tools and techniques within the environment with minimal supervision while mentoring team members in their safe and responsible use. Lead adversarial testing of AI‑enabled applications, machine learning systems, generative AI technologies, large language models, and autonomous agents to identify exploitable weaknesses, misuse scenarios, and gaps in preventive, detective, and responsive security controls.
Engagement Oversight & Stakeholder Management
Review engagement plans, rules of engagement, testing evidence, findings, and reports to promote consistent quality, accuracy, safety, and actionable outcomes. Lead cross‑functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats. Coordinate and monitor third‑party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting. Provide detailed post‑mortem reports and executive briefings with prioritized recommendations. Present engagement outcomes, risk themes, maturity assessments, and strategic recommendations to senior leadership, governance committees, and cybersecurity stakeholders.
Threat Intelligence, Detection Validation & Purple Teaming
Partner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape and that real‑world tactics, techniques, and procedures (TTPs) are translated into emulation plans. Evaluate the effectiveness of detection and response capabilities across SOC, EDR/XDR, SIEM, and other security layers. Build collaborative relationships with blue teams to conduct purple team exercises and improve detection engineering.
Findings Management & Risk Reduction
Lead efforts to track remediation of findings to completion through coordination with application and technology system owners. Validate the effectiveness of remediation actions through retesting, attack path analysis, and other exposure validation activities. Support Continuous Threat Exposure Management (CTEM) initiatives by validating prioritized exposure reductions and measuring security improvements resulting from remediation activities.
Research, Innovation & Capability Development
Expand team capabilities through: Development of custom offensive security tools and automation capabilities to support adversary emulation and security testing. Incorporation of artificial intelligence, automation, and emerging technologies to improve offensive security testing efficiency, scalability, and effectiveness. Research and development of novel offensive techniques and tradecraft. Incorporation of threat actor intelligence into emulation scenarios. Delivery of internal presentations and knowledge‑sharing sessions.
Required Qualifications
Education & Experience
Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent professional experience. 12+ years of experience in Red Team or Penetration Testing roles. Demonstrated experience leading complex offensive security engagements and coordinating the work of technical teams. Experience building or maturing a Red Team, adversarial simulation, or penetration testing program, including methodologies, quality standards, metrics, and multi‑year capability planning.
Offensive Security & Adversary Emulation Expertise
Proficiency with Red Team tools and Command‑and‑Control (C2) frameworks. Advanced networking knowledge and experience with attack simulation. Deep understanding of the MITRE ATT&CK framework and adversary TTPs. Deep understanding of one or more penetration testing methodologies, such as PTES, ISECOM, ISSAF, or OSSTMM. Demonstrated knowledge of AI security risks and adversarial testing techniques, including experience evaluating generative AI applications, model and agent integrations, data exposure, prompt‑based attacks, excessive agency, and other emerging AI threat scenarios.
Technical & Platform Knowledge
Strong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang, or similar languages. Deep understanding of Windows, Linux, Kali Linux, and macOS operating systems. Direct experience with one or more cloud platforms: Microsoft Azure AWS Google Cloud Platform (GCP).
Research, Analysis & Communication
Strong research and reporting skills. Ability to translate technical findings into actionable recommendations for technical and executive audiences.
Leadership & Program Management
Strong team leadership, coaching, prioritization, stakeholder management, and executive communication skills. Experience presenting offensive security findings, program metrics, and strategic recommendations to executive leadership, governance committees, audit stakeholders, and technical teams. Experience defining strategy, establishing standards, measuring performance, and driving continuous improvement of offensive security capabilities. Ability and willingness to travel for on‑site assessments.
Preferred Qualifications
Experience leading purple team engagements.
Preferred Certifications
Offensive Security Certified Professional (OSCP) Offensive Security Certified Expert (OSCE) Offensive Security Experienced Penetration Tester (OSEP) Certified Red Team Professional (CRTP) Certified Red Team Operator (CRTO) Certified Red Team Operator II (CRTO II) GIAC Penetration Tester (GPEN) GIAC Web Application Penetration Tester (GWAPT) GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) CREST Registered Penetration Tester / CBEST Qualifications Certified Azure Red Team Professional (CARTP) Certified Azure Red Team Expert (CARTE) COMPENSATION AND BENEFITS
Compensation and Benefits
This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives. Key has implemented an approach to employee workspaces which prioritizes in‑office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Company Culture
KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law. Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing View email address on click.appcast.io. KeyBank is an organization collectively committed to helping you unlock your potential and discover what truly drives you. Working here means sharing our purpose to help our clients, colleagues, and communities thrive. You’ll find genuinely supportive teammates, a flexible, inclusive work environment, challenging projects, accessible leaders, and opportunities to grow in your position and your career. For 200 years, Key has opened doors in our communities. Let us open one for you.
#J-18808-Ljbffr- ...Advantage, Medicare Supplement, and individual plans. The Senior Security Engineer is a hands-on technical role responsible for implementing,... ...escalation. Responsibilities: Works with various teams and individuals to design streamlined data work flows in regard...SeniorCasual workWork at officeRemote work
- ...accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast... ...business and on-call availabilityThe Senior Product Security Engineer is a deeply technical, hands-on... ...AI engineers on model risk management, red-teaming, and adversarial testing.Stay...Senior
$96k - $181k
...Tiedeman Road, Brooklyn Ohio Senior Cyber Threat... ...Cyber Threat Management team is part of Key's broader... ...Corporate Information Security. Cyber Defense's mission... ..., exercises (tabletop, red / blue / purple), and risk... ...Defense, Security Engineering, Fraud, Third-Party Risk...SeniorWork at officeRemote workFlexible hours- ...assessments, and decision support for senior leaders Support briefings for... ...gap assessments against security controls, risk treatments,... ...with Cyber Defense, Security Engineering, Fraud, Third-Party Risk... ...Technology, Legal, and other teams Provide mentorship and technical...Senior
- ...Senior Security Engineer At Flynn Group, we believe in the power of collaboration and value in-person... ...innovation thrives, with office-based teams coming together four days a week to collaborate... ..., penetration testing coordination, red-team/purple-team activities, adversary...SuggestedTemporary workCasual workWork at officeWork from homeFlexible hours
$116k - $216k
...Location: 4910 Tiedeman Road, Brooklyn Ohio API Security Engineer Role Overview We are seeking an experienced API & Application... ..., cloud, network, SOC, middleware, and platform engineering teams to identify security risks, implement protections,...Work at officeRemote workFlexible hours$105.4k - $207.8k
Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business... ...thinking and a creative approach. We collaborate with teams from across our organization in order to bring the full breadth...SeniorWork experience placementLocal areaRemote work- ...KeyBank National Association is seeking an attorney to lead its Commercial Lending team in a senior in-house capacity. The Assistant General Counsel will advise across the full lifecycle of commercial lending products and operations, supporting Small Business, Business...Senior
- ....Accenture SecurityAccenture Security delivers continuous, rapid-fire... ...to grow with confidence. Our team of the security sector’s... ...management and interaction with senior leadership at a client and/or... ...cybersecurity, infrastructure engineering, software development) with a...SeniorFull timeWork experience placementLive inWork at officeLocal area
$105.4k - $207.8k
...Summary Our Deloitte Cyber team understands the evolving... ...will support Next-Generation Security Operations Center (SOC) capabilities... ...doAs a CrowdStrike SecOps, Senior Consultant on the Cyber... ...analysts and threat detection engineers to prioritize, develop, and tune...SeniorWork experience placementLocal areaVisa sponsorship$122k - $240.5k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy... ...implementation, collaborate with product and engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders....SeniorLocal areaVisa sponsorship- OverviewWe are seeking a highly skilled Security Engineer II to join our Information Security team. This role will play a key part in managing, administrating, reporting and identifying enhancements for our security solutions and assisting with implementation across cloud...Full timeFlexible hours
- ...yogurt, added sugar or artificial preservatives are used, giving the purest taste possible to each item. Job Description: Lead the team, In charge of shifts and delegating tasks Show exemplary knowledge of the job and excellent customer service Deal with...SeniorFlexible hoursShift work
$105.4k - $207.8k
Position Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense & Resilience team, you will help clients strengthen physical security, operational... ...relations, intelligence studies, engineering, homeland security, public administration, or...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
...Summary Our Deloitte Cyber team understands the unique... ...confidence, and proactively manage to secure success. Recruiting for this... ...'ll do As a Managed Services Engineer III on the Cyber Operate... ...From entry-level employees to senior leaders, we believe there’s always...SeniorWork at officeLocal areaVisa sponsorshipShift workRotating shift- ...bring a warm personality, strong communication, and creativity for seniors. A high school diploma or equivalent is required; STNA... ...and experience in long-term care or recreation is a plus. Join a team committed to meaningful engagement and resident well-being. #J-1...Senior
$105.4k - $207.8k
...Summary Our Deloitte Cyber team understands the unique... ...confidence, and proactively manage to secure success. Recruiting for this... ...'ll do As a Managed Services Engineer III on the Cyber Operate... ...From entry-level employees to senior leaders, we believe there’s always...SeniorLocal areaVisa sponsorshipShift workRotating shift$134.5k - $265.1k
...As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...with client engagement teams to design, build, and deliver... ...concepts (e.g., application security, cloud security, identity,... ...From entry-level employees to senior leaders, we believe there’s...SeniorLocal areaVisa sponsorship- ...for clients and end users. Job Description We are seeking a Senior Project Architect who is passionate about design and its... ...world. Candidates should be licensed with proven success leading teams, engaging with project owners and consultants, and delivering exceptional...Senior
$198k - $368k
...Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International.Responsibilities:Own the...H1bLocal area- ...General Responsibilities Provide engineering and consulting services for a broad array of projects... ...and non-technical clients and project teams. Services may be provided for existing... ...project work. Work closely with senior-level project manager to gain project management...SeniorInternship
- About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor... .... Behind the platform is a global team of people who care deeply about the work... ...seeking an experienced Information Security Engineer with a strong background in implementing...Remote work
- ...Job Description: Pay Rate: $65 - $70/hour on W2 Notes: should be local to OH or KY TECHNICAL SKILLS Must Have API security Software Application Security Testing (SAST) Software Composition Analysis (SCA) Javascript/NodeJS Python Terraform...Local areaRemote work
$30 - $38 per hour
...mentor others, Infinity offers stable work, quality jobs, and a team that respects your trade. Why Experienced Installers... ...century, we’ve been at the forefront of designing, building, and engineering premium, award-winning products. Today, Marvin is also proud to...SeniorHourly pay- ...and certified Construction Materials Testing (CMT) Senior Laboratory Technician I to join our Cleveland team. We offer opportunities for growth in this role... ...with the goal to raise the standards of professional engineering consulting. Today, we are a leader in geotechnical...Senior
- ..., supervising personal care staff and coordinating care plans to promote wellbeing. This full-time position entails leading nursing teams and ensuring high-quality care across memory care and assisted living. The director will report to the Executive Director and collaborate...SeniorFull time
$82.6k - $162.8k
...Summary Our Deloitte Cyber team understands the unique... ...confidence, and proactively manage to secure success. Recruiting for this... ...'ll do As a Managed Services Engineer II on the Cyber Operate... ...From entry-level employees to senior leaders, we believe there’s always...Local areaVisa sponsorship- ...Job Description Job Description Description: The Senior Buyer is responsible for managing an assigned group of key commodities and... ...other tasks. The Senior Buyer works closely with the operations team to maintain balance between supply and demand for production and...Senior
$55k - $65k
...alike. Summary/Objective: The Senior Maintenance worker’s job is to perform routine... .... General knowledge of electrical engineering, plumbing, welding, hydraulics,... ...(subject to your location and role) Team Building: Employee engagement and recognition...SeniorFor contractorsLocal areaImmediate startFlexible hours- ...the singular mission of Advancing Communities, our diverse 800+ team of professionals works collaboratively across multiple service... ...multiple states, including planning, landscape architecture, civil engineering, surveying, and construction engineering. We are a team of...SeniorTemporary workLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Offensive Security Engineer (Red Team). Be the first to apply!
- senior application security Brooklyn, OH
- senior manager legal Brooklyn, OH
- senior operations technician Brooklyn, OH
- srs Brooklyn, OH
- senior implementation project manager Brooklyn, OH
- senior financial analyst fp&a Brooklyn, OH
- senior Brooklyn, OH
- senior manager diversity & inclusion Brooklyn, OH
- application security engineer
- principal security engineer






