Senior Offensive Security Engineer (Red Team)
Key · Ohio
📍 Brooklyn, OHvia workdayFirst listed here 2026-09-24
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Key.
Location:
4910 Tiedeman Road, Brooklyn Ohio
Position Summary Our Cyber Adversary and Exposure Management team rolls up into Key’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense.
The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense Red Team and is responsible for guiding team execution, capability development, operational maturity, and offensive security strategy. The role is responsible for advancing the maturity, consistency, and effectiveness of adversarial simulation, red team, and penetration testing capabilities while providing day-to-day leadership for team execution. The role establishes testing strategy and standards, guides engagement planning and quality, coordinates priorities and resources, mentors team members, and drives measurable improvement across the offensive security program. The role also supports Continuous Threat Exposure Management (CTEM) objectives by validating prioritized exposures, assessing attack paths, and measuring the effectiveness of remediation activities against realistic adversary scenarios.
The role also simulates advanced cyber adversaries and emulates real-world adversaries to assess and improve KeyBank’s detection, response, and resilience capabilities. This work goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes.
The ideal candidate will bring significant experience directing adversary emulation, red team engagements, and offensive security operations across enterprise on-premises and cloud environments, with experience leading or participating in physical security assessments. The role demands exceptional technical proficiency, strategic leadership, operational discipline, and the ability to clearly articulate complex security findings and risk implications to audiences ranging from engineers to senior executives.
Key Responsibilities Team Leadership & Operational Management Provide day-to-day technical and operational team leadership for the Red Team, reporting to the CAEM manager, including work prioritization, engagement assignments, execution oversight, issue escalation, and coordination of team deliverables.
Coach and mentor team members, facilitate knowledge sharing, identify capability gaps, and support development of technical depth and leadership readiness across the team.
Provide third-party vendor support, dependencies, and stakeholder communications to keep engagements on track and ensure risks, blockers, and decisions are elevated promptly.
Provide hands-on technical guidance during complex engagements and reinforce safe, responsible, and repeatable adversarial tradecraft.
Partner with Detection Engineering, Security Operations, Threat Intelligence, and Incident Response teams to conduct purple team exercises that validate control effectiveness, detection coverage, and response capabilities against real-world adversary behaviors.
Red Team Strategy, Governance & Program Maturity Lead the development and execution of a maturity roadmap for adversarial simulation, red team, and penetration testing capabilities, including repeatable methodologies, standards, tooling, automation, and quality assurance practices.
Establish and maintain a risk-based testing strategy and engagement pipeline aligned with enterprise threats, critical assets, regulatory expectations, and stakeholder priorities.
Define and report program metrics that demonstrate coverage, execution quality, remediation outcomes, control validation, and progress against the offensive security maturity roadmap.
Use program metrics and engagement outcomes to identify trends, communicate risk, and prioritize improvements to testing coverage and team capabilities.
Drive continuous improvement of adversarial emulation methodologies, tooling, documentation, and operating practices.
Present offensive security program metrics, engagement outcomes, risk themes, and strategic recommendations to cybersecurity leadership, governance forums, and executive stakeholders.
Align adversarial testing activities with exposure management priorities by validating remediation efforts, identifying exploitable attack paths, and measuring reductions in organizational exposure.
Adversarial Simulation & Red Team Operations Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.
Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.
Conduct physical, external/internal, wireless network, web application, and mobile application security assessments.
Lead security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS), identity infrastructure, privileged access management solutions, hybrid enterprise environments, and embedded systems.
Develop and operationalize Red Team tooling, automation, and adversary emulation capabilities that replicate real-world threat actor behaviors and enable repeatable assessment of application, cloud, infrastructure, and network security controls.
Employ these tools and techniques within the environment with minimal supervision while mentoring team members in their safe and responsible use.
Lead adversarial testing of AI-enabled applications, machine learning systems, generative AI technologies, large language models, and autonomous agents to identify exploitable weaknesses, misuse scenarios, and gaps in preventive, detective, and responsive security controls.
Engagement Oversight & Stakeholder Management Review engagement plans, rules of engagement, testing evidence, findings, and reports to p
More Ohio jobs
Ohio jobs · Browse all locations