Geico

Staff Security Engineer - Red Team (AI)

Geico$110K — $260K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in Offensive Security operations
  • 5+ years of direct Red Team, Purple Team experience in enterprise settings
  • Deep knowledge of LLM architecture and its operational implications
  • Experience with AI frameworks like PyTorch and TensorFlow
  • Familiarity with cloud platforms such as AWS, Azure, or GCP
  • Strong grasp of MITRE ATT&CK for creating measurable emulations
  • Expertise with adversary emulation platforms and operational tradecraft

Responsibilities

  • Plan and execute AI-driven adversary operations
  • Define objectives, success criteria, and safety measures for operations
  • Customize and execute emulation plans using tools like MITRE Caldera
  • Leverage AI for advanced security tradecraft in various environments
  • Collaborate with Detection Engineering to enhance telemetry coverage and incident response
  • Innovate techniques and methodologies for adversary operations
  • Deliver actionable findings mapped to identified threats and vulnerabilities

Benefits

  • Comprehensive Total Rewards package tailored for employee well-being
  • 401K savings plan with a 6% match, vested from day one
  • Flexible work options including remote work for four weeks a year
  • Tuition assistance and performance-based incentives
  • Access to mental healthcare and family planning assistance
Full Job Description
We are seeking a hands-on Staff Security Engineer for our Red Team with deep technical expertise in running AI-driven adversary operations that measurably improve detection and response processes. You'll execute at the intersection of offensive security and AI, developing novel Red Team capabilities and running operations against AI-powered systems. This role is responsible for working with other stakeholders in planning, executing, and delivering Red Team, Purple Team, and other Adversary Emulation operations. Outcomes will directly inform detection engineering, incident response readiness, and control validation. You will be responsible for the testing/evaluation of AI applications and agents as well as the leveraging of agentic AI to gain efficiencies for Red Team and penetration testing efforts. Success in this role means you can champion operations end-to-end: shape the scope and objectives, define safety controls and deconfliction, build or tailor emulation plans, execute advanced operator tradecraft in authorized environments, and deliver clear findings mapped to TTPs, telemetry gaps, and detection opportunities. You are someone with progressive experience on Offensive Security operations who can consistently translate realistic adversary behavior into practical defensive improvements and repeatable emulation capability. This role offers a unique opportunity to expand your influence, forge critical alliances, and lead the evolution of Adversary Emulation programs in a fast-paced environment. Your impact will be felt across the organization as we strengthen our defenses against ever-evolving cyber threats through simulation of real-world cyberattacks and attempts to breach the organization's defenses. Responsibilities: - Participate in AI-focused adversary operations: plan, execute and deliver Red Team, Purple Team and other Adversary Emulation operations. - Scope and design operations: define objectives, target scope, success criteria, safety controls. - Develop and run emulations: build, customize, and execute emulation plans using platforms such as MITRE Caldera, or similar products. - Execute advanced AI-leveraged tradecraft across enterprise environments (identity, endpoints, networks, cloud, SaaS) in a controlled, measurable way. - Partner with defenders: work directly with Detection Engineering, Threat Intelligence, and Risk Management to validate telemetry coverage, tune detections, improve response playbooks, and close visibility gaps. - Champion continuous improvement and innovation in adversary operations techniques, tools, and methodologies. Required Qualifications: - 8+ years of experience in Offensive Security operations. - 5+ years of hands-on experience running Red Team, Purple Team, and other Adversary operations in enterprise environments. - Deep understanding of LLM architecture and familiarity with how models process input, manage context, and generate output. - Experience with AI frameworks and tools such as PyTorch, TensorFlow, Hugging Face, and LangChain. - Experience with Azure, AWS, GCP or other cloud providers. - Strong working knowledge of MITRE ATLAS and ATT&CK, and the ability to translate TTPs into repeatable emulations and measurable detection outcomes. - Hands-on experience with adversary emulation platforms, including building/maintaining emulations and running operations. - Demonstrated capability with core operator tradecraft (C2, payload delivery, privilege escalation, lateral movement, persistence, and operational security) appropriate to authorized testing. - Extensive use of red team frameworks: Cobalt Strike, Sliver, Metasploit, Empire, BloodHound. Preferred Qualifications: - OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs. - GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus. - Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing. - Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions). - Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections. Education: - Bachelor's degree in Cybersecurity, Computer Science or a related field. Annual Salary $110,000.00 - $260,000.00 The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate's work experience, education and training, the work location as well as market and business considerations. GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.

About Geico

GEICO (Government Employees Insurance Company) is an American auto insurance company with headquarters in Chevy Chase, Maryland. It is the second largest auto insurer in the United States, after State Farm. GEICO is a wholly owned subsidiary of Berkshire Hathaway that provides coverage for more than 24 million motor vehicles owned by more than 15 million policy holders as of 2017. GEICO writes private passenger automobile insurance in all 50 U.S. states and the District of Columbia. The insurance agency sells policies through local agents, called GEICO Field Representatives, and over the phone directly to the consumer, and through their website.
Learn more about Geico
Size
40,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Geico

More Information Technology Jobs

Find similar Staff Security Engineer - Red Team (AI) jobs: