Staff Security Engineer – Red Team (AI)

Staff Security Engineer – Red Team (AI)

Vollzeit 60000 - 80000 € / Jahr (geschätzt) Homeoffice (teilweise)
GEICO

Auf einen Blick

  • Aufgaben: Leite innovative Red Team-Operationen mit KI und verbessere Sicherheitsprozesse.
  • Unternehmen: GEICO, ein führendes Unternehmen im Bereich Cybersicherheit.
  • Vorteile: Attraktives Gehalt, 401K mit 6% Matching, flexible Arbeitszeiten und umfassende Gesundheitsleistungen.
  • Weitere Informationen: Dynamisches Umfeld mit großartigen Entwicklungsmöglichkeiten und einem Fokus auf Innovation.
  • Warum dieser Job: Gestalte die Zukunft der Cybersicherheit und arbeite an spannenden KI-Projekten.
  • Qualifikationen: Mindestens 8 Jahre Erfahrung in Offensive Security und tiefes Verständnis von KI-Architekturen.

Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.

We are seeking a hands‑on Staff Security Engineer for our Red Team with deep technical expertise in running AI‑driven adversary operations that measurably improve detection and response processes.

You’ll execute at the intersection of offensive security and AI, developing novel Red Team capabilities and running operations against AI‑powered systems.

This role is responsible for working with stakeholders in planning, executing, and delivering Red Team, Purple Team, and other Adversary Emulation operations.

Outcomes will directly inform detection engineering, incident response readiness, and control validation.

You will be responsible for testing/evaluation of AI applications and agents as well as leveraging agentic AI to gain efficiencies for Red Team and penetration testing efforts.

Success in this role means you can champion operations end‑to‑end: shape the scope and objectives, define safety controls and deconfliction, build or tailor emulation plans, execute advanced operator tradecraft in authorized environments, and deliver clear findings mapped to TTPs, telemetry gaps, and detection opportunities.

You are someone with progressive experience on Offensive Security operations who can consistently translate realistic adversary behavior into practical defensive improvements and repeatable emulation capability.

Responsibilities

  • Participate in AI‑focused adversary operations: plan, execute and deliver Red Team, Purple Team, and other Adversary Emulation operations.
  • Scope and design operations: define objectives, target scope, success criteria, safety controls.
  • Develop and run emulations: build, customize, and execute emulation plans using platforms such as MITRE Caldera, or similar products.
  • Execute advanced AI‑leveraged tradecraft across enterprise environments (identity, endpoints, networks, cloud, Saa S) in a controlled, measurable way.
  • Partner with defenders: work directly with Detection Engineering, Threat Intelligence, and Risk Management to validate telemetry coverage, tune detections, improve response playbooks, and close visibility gaps.
  • Champion continuous improvement and innovation in adversary operations techniques, tools, and methodologies.
  • Required Qualifications
  • 8+ years of experience in Offensive Security operations.
  • 5+ years of hands‑on experience running Red Team, Purple Team, and other Adversary operations in enterprise environments.
  • Deep understanding of LLM architecture and familiarity with how models process input, manage context, and generate output.
  • Experience with AI frameworks and tools such as Py Torch, Tensor Flow, Hugging Face, and Lang Chain.
  • Experience with Azure, AWS, GCP or other cloud providers.
  • Strong working knowledge of MITRE ATLAS and ATT&CK, and the ability to translate TTPs into repeatable emulations and measurable detection outcomes.
  • Hands‑on experience with adversary emulation platforms, including building/maintaining emulations and running operations.
  • Demonstrated capability with core operator tradecraft (C2, payload delivery, privilege escalation, lateral movement, persistence, and operational security) appropriate to authorized testing.
  • Extensive use of red team frameworks: Cobalt Strike, Sliver, Metasploit, Empire, Blood Hound.
  • Preferred Qualifications
  • OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certifications.
  • GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) and above.
  • Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programming.
  • Advanced level knowledge of Linux, Mac, and Windows operating systems, AWS/Azure cloud environments and cloud‑native resources (ex. containers, Kubernetes, microservices, serverless functions).
  • Experience with conducting reverse engineering on mobile applications, including applications with anti‑emulator and obfuscation protections.

Education

  • Bachelor’s degree in Cybersecurity, Computer Science or a related field.
  • Annual Salary
  • $110,000.00 - $260,000.00

The above annual salary range is a general guideline.

Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate.

Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.

GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.

Benefits

  • Comprehensive Total Rewards program that offers personalized coverage tailor‑made for you and your family’s overall well‑being.
  • Financial benefits including market‑competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition‑based incentives; and tuition assistance.
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
  • Supports flexibility – We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law.

GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company.

This applies to all applicants and associates.

GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability.

We do not condone or tolerate an atmosphere of intimidation or harassment.

We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

#J-18808-Ljbffr

Staff Security Engineer – Red Team (AI) Arbeitgeber: GEICO

GEICO bietet eine herausragende Arbeitsumgebung für den Director of Associate Experience & Development, indem es eine Kultur der kontinuierlichen Weiterbildung und Entwicklung fördert. Mit einem starken Fokus auf die Entwicklung von Rechtsanwälten und Fachkräften im Bereich Litigation, profitieren Mitarbeiter von maßgeschneiderten Schulungsprogrammen, klaren Karrierepfaden und einer unterstützenden Gemeinschaft, die Vielfalt und Inklusion schätzt. Die Möglichkeit, remote zu arbeiten, kombiniert mit der Präsenz im Büro in Bethesda, Maryland, schafft ein flexibles Arbeitsumfeld, das sowohl persönliche als auch berufliche Bedürfnisse berücksichtigt.

GEICO

Kontaktdaten:

GEICO Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Staff Security Engineer – Red Team (AI) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie GEICO kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von GEICO zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei GEICO.

Wir glauben, dass du diese Fähigkeiten brauchst, um Staff Security Engineer – Red Team (AI) mit Bravour zu bestehen

Offensive Security Operations
Red Team Operations
Purple Team Operations
Adversary Emulation
AI-Driven Adversary Operations
LLM Architektur
AI Frameworks (PyTorch, TensorFlow, Hugging Face, LangChain)

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei GEICO vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei GEICO könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. GEICO sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird GEICO auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!