Senior Offensive Security Engineer (Red Team)
KeyCorp
Senior Offensive Security Engineer Our Cyber Adversary and Exposure Management team rolls up into Key's broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense. The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense Red Team and is responsible for guiding team execution, capability development, operational maturity, and offensive security strategy. The role is responsible for advancing the maturity, consistency, and effectiveness of adversarial simulation, red team, and penetration testing capabilities while providing day-to-day leadership for team execution. The role establishes testing strategy and standards, guides engagement planning and quality, coordinates priorities and resources, mentors team members, and drives measurable improvement across the offensive security program. The role also supports Continuous Threat Exposure Management (CTEM) objectives by validating prioritized exposures, assessing attack paths, and measuring the effectiveness of remediation activities against realistic adversary scenarios. The role also simulates advanced cyber adversaries and emulates real-world adversaries to assess and improve KeyBank's detection, response, and resilience capabilities. This work goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes. The ideal candidate will bring significant experience directing adversary emulation, red team engagements, and offensive security operations across enterprise on-premises and cloud environments, with experience leading or participating in physical security assessments. The role demands exceptional technical proficiency, strategic leadership, operational discipline, and the ability to clearly articulate complex security findings and risk implications to audiences ranging from engineers to senior executives. Team Leadership & Operational Management Provide day-to-day technical and operational team leadership for the Red Team, including work prioritization, engagement assignments, execution oversight, issue escalation, and coordination of team deliverables. Coach and mentor team members, facilitate knowledge sharing, identify capability gaps, and support development of technical depth and leadership readiness across the team. Provide third-party vendor support, dependencies, and stakeholder communications to keep engagements on track and ensure risks, blockers, and decisions are elevated promptly. Provide hands-on technical guidance during complex engagements and reinforce safe, responsible, and repeatable adversarial tradecraft. Partner with Detection Engineering, Security Operations, Threat Intelligence, and Incident Response teams to conduct purple team exercises that validate control effectiveness, detection coverage, and response capabilities against real-world adversary behaviors. Red Team Strategy, Governance & Program Maturity Lead the development and execution of a maturity roadmap for adversarial simulation, red team, and penetration testing capabilities, including repeatable methodologies, standards, tooling, automation, and quality assurance practices. Establish and maintain a risk-based testing strategy and engagement pipeline aligned with enterprise threats, critical assets, regulatory expectations, and stakeholder priorities. Define and report program metrics that demonstrate coverage, execution quality, remediation outcomes, control validation, and progress against the offensive security maturity roadmap. Use program metrics and engagement outcomes to identify trends, communicate risk, and prioritize improvements to testing coverage and team capabilities. Drive continuous improvement of adversarial emulation methodologies, tooling, documentation, and operating practices. Present offensive security program metrics, engagement outcomes, risk themes, and strategic recommendations to cybersecurity leadership, governance forums, and executive stakeholders. Align adversarial testing activities with exposure management priorities by validating remediation efforts, identifying exploitable attack paths, and measuring reductions in organizational exposure. Adversarial Simulation & Red Team Operations Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK. Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation. Conduct physical, external/internal, wireless network, web application, and mobile application security assessments. Lead security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS), identity infrastructure, privileged access management solutions, hybrid enterprise environments, and embedded systems. Develop and operationalize Red Team tooling, automation, and adversary emulation capabilities that replicate real-world threat actor behaviors and enable repeatable assessment of application, cloud, infrastructure, and network security controls. Employ these tools and techniques within the environment with minimal supervision while mentoring team members in their safe and responsible use. Lead adversarial testing of AI-enabled applications, machine learning systems, generative AI technologies, large language models, and autonomous agents to identify exploitable weaknesses, misuse scenarios, and gaps in preventive, detective, and responsive security controls. Engagement Oversight & Stakeholder Management Review engagement plans, rules of engagement, testing evidence, findings, and reports to promote consistent quality, accuracy, safety, and actionable outcomes. Lead cross-functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats. Coordinate and monitor third-party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting. Provide detailed post-mortem reports and executive briefings with prioritized recommendations. Present engagement outcomes, risk themes, maturity assessments, and strategic recommendations to senior leadership, governance committees, and cybersecurity stakeholders. Threat Intelligence, Detection Validation & Purple Teaming Partner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape and that real-world tactics, techniques, and procedures (TTPs) are translated into emulation plans. Evaluate the effectiveness of detection and response capabilities across SOC, EDR/XDR, SIEM, and other security layers. Build collaborative relationships with blue teams to conduct purple team exercises and improve detection engineering. Findings Management & Risk Reduction Lead efforts to track remediation of findings to completion through coordination with application and technology system owners. Validate the effectiveness of remediation actions through retesting, attack path analysis, and other exposure validation activities. Support Continuous Threat Exposure Management (CTEM) initiatives by validating prioritized exposure reductions and measuring security improvements resulting from remediation activities. Research, Innovation & Capability Development Expand team capabilities through: Development of custom offensive security tools and automation capabilities to support adversary emulation and security testing. Incorporation of artificial intelligence, automation, and emerging technologies to improve offensive security testing efficiency, scalability, and effectiveness. Research and development of novel offensive techniques and tradecraft. Incorporation of threat actor intelligence into emulation scenarios. Delivery of internal presentations and knowledge-sharing sessions. Required Qualifications Education & Experience Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent professional experience. 12+ years of experience in Red Team or Penetration Testing roles. Demonstrated experience leading complex offensive security engagements and coordinating the work of technical teams. Experience building or maturing a Red Team, adversarial simulation, or penetration testing program, including methodologies, quality standards, metrics, and multi-year capability planning. Offensive Security & Adversary Emulation Expertise Proficiency with Red Team tools and Command-and-Control (C2) frameworks. Advanced networking knowledge and experience with attack simulation. Deep understanding of the MITRE ATT&CK framework and adversary TTPs. Deep understanding of one or more penetration testing methodologies, such as PTES, ISECOM, ISSAF, or OSSTMM. Demonstrated knowledge of AI security risks and adversarial testing techniques, including experience evaluating generative AI applications, model and agent integrations, data exposure, prompt-based attacks, excessive agency, and other emerging AI threat scenarios. Technical & Platform Knowledge Strong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang, or similar languages. Deep understanding of Windows, Linux, Kali Linux, and macOS operating systems. Direct experience with one or more cloud platforms: KeyCorp
- Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it is...Senior
$180k - $230k
Senior Security Engineer, Threat & Offensive Security Valon is building the AI-native operating system for regulated... ...ultimate mission of Valon's Security team to ensure we have sound programs, processes... ...experience in security engineering, red team, or threat management role,...SeniorRemote workFlexible hours$224k - $356.5k
Senior Offensive Security Engineer NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to push the frontier... ...Join us! What you'll be doing: Crafting and building new red team agents: autonomous and semi-autonomous LLM agents that perform...Senior$187k - $220k
Senior Offensive Security Engineer Join us in building the future of finance. Our mission is to democratize finance... ...shift, keep reading. About the Team + Role We are building an elite team,... ...and ethics in everything we build! The Red Team's mission is to identify and...SeniorWork at officeShift work3 days per week- Seeking a full-time Senior Offensive Security Engineer focused on enhancing AI-driven offensive security, this remote position will manage the development of autonomous red team agents, improve existing agent capabilities, and mentor team members in advanced offensive tooling...SeniorFull timeRemote work
- ...powerful AI platform for SAP teams. SAP is the heart of the... ...About this role We're hiring Senior Security Engineers to design, harden, and continuously... ...safely. Lead our internal red team. You'll lead and extend... .... Push the frontier on offensive and defensive AI for SAP. AI...Senior
- Staff Offensive Security Engineer Cloaked is a consumer privacy and identity platform on a mission to give people back control of their personal... ...review, and audit support. One day you might be red-teaming a physical system, and the next you are tearing apart our...
- ...Job Description Job Description Senior Security Engineer Full Time Opportunity 5 days on site... ...our infrastructure and development teams to produce innovative and secure solutions... ...of automation Conduct lightweight offensive/discovery operations on your own or...SeniorFull time
- ...portal, an in-house marketing team that helps them grow, a... ...The Role We are seeking a Senior Application Security Engineer to join Savvy Wealth at our... ...services environment experience Offensive security background (pentesting, bug bounty, red team) that informs how you defend...SeniorWork at office
$163.94k - $215.18k
Hi, we're Oscar. We're hiring a Senior Security AI Engineer 1 to join our Security Engineering team.Oscar is the first health insurance company built around a full stack... ...Initiatives & Threat Modeling: Lead proactive AI red-teaming exercises and map adversarial tactics...SeniorFull timeWork at officeFlexible hours- ...Position As our first dedicated Senior Security Engineer, you will join a remote, global health‑tech team that works at the intersection... ...candidates with real-world offensive experience, not just institutional... ..., responsible disclosure, or red team operations is a strong...SeniorRemote work
$126k - $188k
...themselves. We're looking to grow our teams with more people who share our... ...and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical... ...Security, Cryptography, IAM, or Red Teams) and proficient in...SeniorWork experience placementLocal areaRemote work$200k - $280k
...Responsibilities Partner with engineering teams to incorporate secure design principles into technical designs. Review security-critical code and... ...management tooling. Discover vulnerabilities through red team exercises and participate in security incident response...SeniorFull timeWork experience placementFlexible hours- ...stock. We are a highly collaborative team of builders and operators who invent new... ...innovation. Join us!We are hiring a Senior AI Security Engineer II to lead the security, governance, and... ...across the AI lifecycle, lead red-teaming and adversarial testing of AI...Senior
$160k - $200k
Senior Application Security Engineer New York, New York, United States The Senior Application Security Engineer... ...Cloud Infrastructure, and Security teams to shape secure coding practices,... ...workflows. Hands-on penetration testing / offensive security experience across web...Senior$167.5k - $226.3k
...company values, which are reflected in our product and in our team.Our ValuesIf this sounds like you, you’ll fit right in.Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s AI...SeniorCasual workWork at officeLocal area- ...financial services environment. Enhance security maturity and operational effectiveness through... .... Collaborate with cross-functional teams to strengthen security posture.Job DescriptionSenior Security Engineer OverviewThe Senior Security Engineer will lead cybersecurity...Senior
$134.6k - $194.48k
Sr AI Security Engineer The Sr AI Security Engineer continuously monitors the... ...and AI engineering teams to design and implement practical... ...engineering, cloud security, offensive security, or a related technical... ...with AI/LLM security testing or red teaming. Familiarity with...SeniorTemporary workWork experience placement- ▶︎ Job Details ・ Job Title: Senior Security Engineer / Advanced Security Engineer ・ Client: Japanese IT Company ・ Working Location: New York... ..., coordinating with vendors, subcontractors, and internal teams Conduct security assessments and design tailored...SeniorFull timeFor subcontractorVisa sponsorshipShift work
$190k - $237k
...market solution for revenue teams, trusted by over 500,000... ...members. Role Overview The Senior Application Security Engineer is a senior individual... ...Perform hands-on validation and offensive security testing of... ...adversarial thinking, and focused red-team-style exercises, to...SeniorWorldwideFlexible hours- ...are reflected in our product and in our team.Our ValuesIf this sounds like you, you’ll... ...is looking for an experienced security engineer skilled in detection and response, who can... ...enhance and mature Justworks’ Security. As a Senior Detection Engineer, you’ll design, build...SeniorCasual workLocal area
$128.9k - $180k
...empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can't wait to meet you. WHAT YOU'LL DO As a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees...SeniorWork at officeLocal areaFlexible hours- ...Description Job Description J ob Title: Sr. Security Engineer Duration: 6 months Contract To Hire... ...Position Client X is seeking an exceptional Senior Security Engineer to join its IT Security Team in our New York office. This person will join a...SeniorContract workWork at officeRemote work
$10k
...building the smart infrastructure for finance teams, embedded in the transaction flow of... ...'ll be the architect of our endpoint security posture across the full fleet — macOS, Windows... .... You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and...SeniorFull timeWork at officeRemote workHome officeFlexible hours- Senior Cloud Security Engineer The Senior Cloud Security Engineer will design, implement, and maintain security... ..., application development, and DevOps teams to embed security into every stage of... ...handling PHI at scale Experience with red teaming or adversarial testing of AI...SeniorWork at officeLocal area
$175k - $220k
...in officeAbout the RoleWe are looking for a highly technical Senior Security Engineer who thrives on building security capabilities from the... ...area. You will join a highly technical Security Engineering team that values innovation, ownership, and building scalable security...SeniorFull timeWork at office- Senior Security Engineer - AI We are seeking a Senior Security Engineer to join our team, focusing on defining security workflows and incident response (IR) strategies. Our AI Security Engineers are at the forefront of the Agentic Security revolution, working directly...Senior
$180k - $240k
...rooted in connection—between clients and clinicians, care teams, loved ones, and the communities that support them. By... ...they deserve, we'd love to meet you. About the Role The Senior Corporate Security Engineer role is responsible for designing, building and operating...SeniorFull timeWork at officeLocal areaRemote work$142.32k - $213.48k
...career with us means joining a team of more than 230,000... ...institutional blockchain adoption — and security is its foundation. As... ...can trust.We are seeking a Senior Security Engineer (VP) to join our New York-based... ...in penetration testing, red team exercises, or formal security...SeniorFull timeContract workWorldwide- Job Title: Senior Security Engineer Location: REMOTE - Cincinnati, Charlotte, Boca, Portland, San Jose, Chicago TOP SKILLS: Top 3 Required Skills... ...and security controls in MS O365 (SharePoint, OneDrive, Teams) Hands-on experience configuring Data Classification...SeniorFor contractorsRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Offensive Security Engineer (Red Team). Be the first to apply!
- security engineering manager New York, NY
- physical security engineer New York, NY
- senior security operations engineer New York, NY
- staff security engineer New York, NY
- offensive security engineer New York, NY
- security software engineer New York, NY
- entry level security engineer New York, NY
- network security engineer New York, NY
- sr information security engineer New York, NY
- lead security engineer New York, NY

