This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers. As a Staff Engineer of Offensive Security, you'll be at the forefront of our cybersecurity strategy for penetration testing, advanced attack simulations, and enabling organization to prevent, detect, and respond to cyber threats. Your role is pivotal in shaping our security posture, collaborating closely with senior leadership to influence risk decisions and ensure regulatory readiness. We seek a hands-on offensive security engineer with deep technical expertise in penetration testing, real-world adversary tactics, and risk frameworks, capable of driving measurable improvements in our cyber resilience. Candidates are expected to have hands-on penetration testing experience while driving security and compliance initiatives to perform overall offensive security functions including red and purple teaming. The ideal candidate must possess a highly technical skillset and the ability to collaborate with stakeholders across the company to integrate penetration testing and other offensive security functions within company processes. You'll challenge the status quo, identifying opportunities to elevate our security engineering excellence through automation and innovative approaches. Your ability to think big, anticipate and adapt change, and address root causes will be key to delivering greater business value while proactively examining actions and refining approaches. In this high-stakes environment, you'll ensure implementation of industry best practices and execution of offensive security functions while meeting regulatory compliance requirements. This role offers a unique opportunity to expand your influence, forge critical alliances, and lead the evolution of offensive security in a fast-paced environment. Your impact will be felt across the organization as you strengthen our defenses against ever-evolving cyber threats through simulation of real-world cyberattacks and attempts to breach the organization's defenses.
Job Responsibility:
Lead highly effective large-scale penetration testing initiatives
Participate in simulating real-world cyber-attacks (red teaming), and collaborating with defensive security teams (purple teaming)
Conduct tactical security penetration test assessments to validate the security of company applications (web, mobile, APIs, and AI products) against OWASP Top 10 threats and work with the Application Security team to provide feedback and recommendations to increase automated capabilities
Ensure penetration testing activities are meeting security, business, and compliance objectives and outcomes
Design and execute advanced threat emulation scenarios, including physical, social, and digital attack vectors
Collaborate with Blue Teams, Threat Intelligence, and Risk Management to ensure comprehensive attack coverage and feedback loops
Ensure operations align with industry regulations and compliance standards such as NIST, PCI DSS, and NYDFS
Champion continuous improvement and innovation in penetration testing, adversary simulation techniques, tools, and methodologies
Requirements:
Mastery of vulnerability discovery and exploitation across applications, networks, and cloud using tools (e.g., Burp Suite, Metasploit), and custom scripts (Python, PowerShell)
Advanced understanding of OWASP, MITRE ATT&CK framework, software development lifecycle (SDLC), threat modeling, red/purple teaming, and attack path development
Hands-on experience with tools like Cobalt Strike, Mythic, BloodHound, and AutoSploit
Relevant professional security certifications (e.g. from GIAC or others)
Proven experience in achieving results efficiently through automation and establishing best practices
Proven track record to deliver business outcomes for meeting regulatory and compliance obligations
Ability to force multiply through coaching and mentorship to offensive security engineers across all functions (penetration testing, red teaming, purple teaming)
8+ years in engineering focused role, preferably in the tech industry
5+ years of experience in offensive security (penetrating testing, red team, and purple team)
5+ years of hands-on experience performing penetration-testing, red teaming, and purple teaming activities
4+ years of experience with Azure, AWS, GCP or other cloud providers
Senior role influencing team’s direction on security
Experience applying security controls to exceed third party attestation requirements (PCI, NYDFS, SOX …)
Bachelor’s degree in Cybersecurity, Computer Science or a related field
Nice to have:
OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs
GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus
Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing
Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)
Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections
What we offer:
Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being
Financial benefits including market-competitive compensation
a 401K savings plan vested from day one that offers a 6% match
performance and recognition-based incentives
and tuition assistance
Access to additional benefits like mental healthcare as well as fertility and adoption assistance
Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year