Staff, Security Engineer

Macy's

$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in software engineering, cybersecurity, or AI/ML with production-scale deployments.
  • Preferred PhD or Master's in a technical discipline; AI/Cloud/Cybersecurity certifications are a plus.
  • Strong programming skills in Python, SQL, JavaScript, C/C++, and API development.
  • Expertise in detection engineering, threat hunting, and advanced security analytics.
  • Familiarity with cloud technologies like AWS, Azure, and GCP, including CI/CD practices.

Responsibilities

  • Establish a risk-based approach for evaluating new and emerging threats.
  • Stay updated on technology trends to inform mitigation strategies.
  • Design and lead simulations based on defined threat scenarios.
  • Participate in developing security strategies and best practices.
  • Mentor team members and provide leadership across cross-functional teams.
  • Document findings and recommendations from assessments.
  • Build relationships with leadership and third parties to identify top threats.

Benefits

  • Inclusive and engaging work environment.
  • Competitive pay rooted in principles of equity.
  • Performance incentives and merit annual reviews.
  • Merchandise discounts and health benefits including dental and vision.
  • 401k match and employee assistance for personal matters.
Full Job Description
Job Description

Job Overview

The Staff, Vulnerability Engineer is a specialist in Penetration Testing and Information Security Vulnerability Management. This hands-on role involves conducting penetration tests and vulnerability assessments on complex applications, operating systems, and wired and wireless networks. In response to an ever-changing threat landscape, they establish a proactive program to assess Macy's resilience against real-world tactics, techniques, and procedures (TTPs).

What You Will Do
  • Establish a risk-based approach for evaluating and prioritizing new and emerging threats.
  • Stay current on emerging technology trends and the threat landscape, providing subject matter knowledge on specific adversarial threats and risks to assist with mitigation strategies.
  • Design, coordinate, and lead simulations based on organizationally defined threat scenarios.
  • Participate in reviewing and developing security strategies, best practices, policies, and procedures.
  • Provide leadership, share knowledge, and mentor team members.
  • Build working relationships with Macy's TMRC, leadership, and third parties to identify top threats.
  • Develop standard Rules of Engagement for real-time testing.
  • Document detailed findings, analysis, and recommendations.

Skills You Will Need

AI & Machine Learning: Expertise in Generative AI, LLMs, RAG, AI Agents, Prompt Engineering, LangChain/LangGraph, anomaly detection, NLP, transformers, and security-focused ML solutions.

Security Engineering: Strong experience in detection engineering, threat hunting, SIEM/XDR/EDR, MITRE ATT&CK, Sigma, OCSF, threat intelligence, and enterprise security operations.

Cloud & Infrastructure: Advanced knowledge of AWS, Azure, GCP, Databricks, Kubernetes, Docker, CI/CD, and scalable cloud-native security architectures.

Software Development: Strong programming skills in Python, SQL, JavaScript, C/C++, API development, automation, and distributed systems engineering.

Threat Protection: Experience protecting large enterprise environments through advanced analytics, behavioral detection, adversary simulation, and AI-powered security automation.

Research & Innovation: Proven track record of cybersecurity research, patents, publications, and development of innovative security technologies.

Leadership & Collaboration: Ability to lead cross-functional initiatives, influence architecture decisions, mentor engineers, and partner effectively across security and engineering organizations.

Communication: Excellent written, verbal, and presentation skills, with experience communicating technical concepts to executive and technical audiences.

Education/Certifications: PhD or Master's degree in a technical discipline preferred; AI, Cloud, or Cybersecurity certifications are a plus.

Experience: 10+ years of experience in software engineering, cybersecurity, AI/ML, or related fields with production-scale deployments.

Who You Are
  • This role involves performing essential job functions such as communication, collaboration, and use of office and computer systems. Responsibilities include the ability to access and review written and electronic information, and to move within the work environment and interact with workplace materials as needed to carry out job responsibilities.

What We Can Offer You
  • An inclusive, challenging, and refreshingly fun work environment
  • Competitive pay and benefits rooted in principles of equity
  • Performance incentives and annual merit review
  • Merchandise discounts
  • Health and Wellness Benefits across medical, dental, vision, and additional insurance
  • Retirement Savings Plan with 401k match opportunity
  • Employee Assistance Program (mental health counseling and legal/financial advice)
  • Resources for continuous learning, career growth, and leadership development
  • 8 paid holidays
  • Paid Time Off (first year prorated depending on start date)
  • Tuition reimbursement program
  • Colleague Resource Groups (CRGs) and give-back/volunteer opportunities
  • Empowerment and autonomy to perform impactful work with tangible results

Similar Jobs

More Jobs at Macy's

More Information Technology Jobs

Find similar Staff, Security Engineer jobs: