{"id":1673589,"url":"https://alion.io/job/key-com-senior-offensive-security-engineer-red-team","title":"Senior Offensive Security Engineer (Red Team)","company":{"id":450627,"name":"KeyBank","domain":"key.com","url":"https://alion.io/company/key-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":96000,"max":181000,"currency":"USD","period":"year","gross":null,"usd_annual":181000},"salary_estimate":null,"experience_years_min":12,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Bash","optional":false},{"name":"GCP","optional":false},{"name":"Go","optional":false},{"name":"JavaScript","optional":false},{"name":"Kali Linux","optional":false},{"name":"Linux","optional":false},{"name":"Machine Learning","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SIEM","optional":false},{"name":"Windows","optional":false},{"name":"AI Agents","optional":true}],"status":"live","first_seen_at":"2026-09-17T00:00:00Z","employer_posted_date":"2026-09-17","last_verified_at":"2026-10-07T00:23:35Z","board_verified":true,"closed_at":null,"days_open":20,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":20},"description":"Location:\n4910 Tiedeman Road, Brooklyn OhioPosition Summary\nOur Cyber Adversary and Exposure Management team rolls up into Key’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense.\nThe Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense Red Team and is responsible for guiding team execution, capability development, operational maturity, and offensive security strategy. The role is responsible for advancing the maturity, consistency, and effectiveness of adversarial simulation, red team, and penetration testing capabilities while providing day-to-day leadership for team execution. The role establishes testing strategy and standards, guides engagement planning and quality, coordinates priorities and resources, mentors team members, and drives measurable improvement across the offensive security program. The role also supports Continuous Threat Exposure Management (CTEM) objectives by validating prioritized exposures, assessing attack paths, and measuring the effectiveness of remediation activities against realistic adversary scenarios.\nThe role also simulates advanced cyber adversaries and emulates real-world adversaries to assess and improve KeyBank’s detection, response, and resilience capabilities. This work goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes.\nThe ideal candidate will bring significant experience directing adversary emulation, red team engagements, and offensive security operations across enterprise on-premises and cloud environments, with experience leading or participating in physical security assessments. The role demands exceptional technical proficiency, strategic leadership, operational discipline, and the ability to clearly articulate complex security findings and risk implications to audiences ranging from engineers to senior executives.\nKey Responsibilities\nTeam Leadership & Operational Management\nProvide day-to-day technical and operational team leadership for the Red Team, reporting to the CAEM manager, including work prioritization, engagement assignments, execution oversight, issue escalation, and coordination of team deliverables.\nCoach and mentor team members, facilitate knowledge sharing, identify capability gaps, and support development of technical depth and leadership readiness across the team.\nProvide third-party vendor support, dependencies, and stakeholder communications to keep engagements on track and ensure risks, blockers, and decisions are elevated promptly.\nProvide hands-on technical guidance during complex engagements and reinforce safe, responsible, and repeatable adversarial tradecraft.\nPartner with Detection Engineering, Security Operations, Threat Intelligence, and Incident Response teams to conduct purple team exercises that validate control effectiveness, detection coverage, and response capabilities against real-world adversary behaviors.\nRed Team Strategy, Governance & Program Maturity\nLead the development and execution of a maturity roadmap for adversarial simulation, red team, and penetration testing capabilities, including repeatable methodologies, standards, tooling, automation, and quality assurance practices.\nEstablish and maintain a risk-based testing strategy and engagement pipeline aligned with enterprise threats, critical assets, regulatory expectations, and stakeholder priorities.\nDefine and report program metrics that demonstrate coverage, execution quality, remediation outcomes, control validation, and progress against the offensive security maturity roadmap.\nUse program metrics and engagement outcomes to identify trends, communicate risk, and prioritize improvements to testing coverage and team capabilities.\nDrive continuous improvement of adversarial emulation methodologies, tooling, documentation, and operating practices.\nPresent offensive security program metrics, engagement outcomes, risk themes, and strategic recommendations to cybersecurity leadership, governance forums, and executive stakeholders.\nAlign adversarial testing activities with exposure management priorities by validating remediation efforts, identifying exploitable attack paths, and measuring reductions in organizational exposure.\nAdversarial Simulation & Red Team Operations\nLead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.\nDesign and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.\nConduct physical, external/internal, wireless network, web application, and mobile application security assessments.\nLead security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS), identity infrastructure, privileged access management solutions, hybrid enterprise environments, and embedded systems.\nDevelop and operationalize Red Team tooling, automation, and adversary emulation capabilities that replicate real-world threat actor behaviors and enable repeatable assessment of application, cloud, infrastructure, and network security controls.\nEmploy these tools and techniques within the environment with minimal supervision while mentoring team members in their safe and responsible use.\nLead adversarial testing of AI-enabled applications, machine learning systems, generative AI technologies, large language models, and autonomous agents to identify exploitable weaknesses, misuse scenarios, and gaps in preventive, detective, and responsive security controls.\nEngagement Oversight & Stakeholder Management\nReview engagement plans, rules of engagement, testing evidence, findings, and reports to promote consistent quality, accuracy, safety, and actionable outcomes.\nLead cross-functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats.\nCoordinate and monitor third-party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting.\nProvide detailed post-mortem reports and executive briefings with prioritized recommendations.\nPresent engagement outcomes, risk themes, maturity assessments, and strategic recommendations to senior leadership, governance committees, and cybersecurity stakeholders. \nThreat Intelligence, Detection Validation & Purple Teaming\nPartner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape and that real-world tactics, techniques, and procedures (TTPs) are translated into emulation plans.\nEvaluate the effectiveness of detection and response capabilities across SOC, EDR/XDR, SIEM, and other security layers.\nBuild collaborative relationships with blue teams to conduct purple team exercises and improve detection engineering.\nFindings Management & Risk Reduction\nLead efforts to track remediation of findings to completion through coordination with application and technology system owners.\nValidate the effectiveness of remediation actions through retesting, attack path analysis, and other exposure validation activities.\nSupport Continuous Threat Exposure Management (CTEM) initiatives by validating prioritized exposure reductions and measuring security improvements resulting from remediation activities.\nResearch, Innovation & Capability Development\nExpand team capabilities through:Development of custom offensive security tools and automation capabilities to support adversary emulation and security testing.\nIncorporation of artificial intelligence, automation, and emerging technologies to improve offensive security testing efficiency, scalability, and effectiveness.\nResearch and development of novel offensive techniques and tradecraft.\nIncorporation of threat actor intelligence into emulation scenarios.\nDelivery of internal presentations and knowledge-sharing sessions.\n\nRequired Qualifications\nEducation & Experience\nBachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent professional experience.\n12+ years of experience in Red Team or Penetration Testing roles.\nDemonstrated experience leading complex offensive security engagements and coordinating the work of technical teams.\nExperience building or maturing a Red Team, adversarial simulation, or penetration testing program, including methodologies, quality standards, metrics, and multi-year capability planning.\nOffensive Security & Adversary Emulation Expertise\nProficiency with Red Team tools and Command-and-Control (C2) frameworks.\nAdvanced networking knowledge and experience with attack simulation.\nDeep understanding of the MITRE ATT&CK framework and adversary TTPs.\nDeep understanding of one or more penetration testing methodologies, such as PTES, ISECOM, ISSAF, or OSSTMM.\nDemonstrated knowledge of AI security risks and adversarial testing techniques, including experience evaluating generative AI applications, model and agent integrations, data exposure, prompt-based attacks, excessive agency, and other emerging AI threat scenarios.\nTechnical & Platform Knowledge\nStrong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang, or similar languages.\nDeep understanding of Windows, Linux, Kali Linux, and macOS operating systems.\nDirect experience with one or more cloud platforms:Microsoft Azure\nAWS\nGoogle Cloud Platform (GCP)\n\nResearch, Analysis & Communication\nStrong research and reporting skills.\nAbility to translate technical findings into actionable recommendations for technical and executive audiences.\nLeadership & Program Management\nStrong team leadership, coaching, prioritization, stakeholder management, and executive communication skills.\nExperience presenting offensive security findings, program metrics, and strategic recommendations to executive leadership, governance committees, audit stakeholders, and technical teams.\nExperience defining strategy, establishing standards, measuring performance, and driving continuous improvement of offensive security capabilities.\nAbility and willingness to travel for on-site assessments.\nPreferred Qualifications\nExperience leading purple team engagements.\nExperience validating security controls through adversarial simulation.\nExperience supporting Continuous Threat Exposure Management (CTEM) or attack path analysis programs.\nExperience assessing generative AI and agentic AI platforms.\nPreferred Certifications\nOffensive Security Certified Professional (OSCP)\nOffensive Security Certified Expert (OSCE)\nOffensive Security Experienced Penetration Tester (OSEP)\nCertified Red Team Professional (CRTP)\nCertified Red Team Operator (CRTO)\nCertified Red Team Operator II (CRTO II)\nGIAC Penetration Tester (GPEN)\nGIAC Web Application Penetration Tester (GWAPT)\nGIAC Exploit Researcher and Advanced Penetration Tester (GXPN)\nCREST Registered Penetration Tester / CBEST Qualifications\nCertified Azure Red Team Professional (CARTP)\nCertified Azure Red Team Expert (CARTE)\nCOMPENSATION AND BENEFITS\nThis position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.Please click here for a list of benefits for which this position is eligible.\nKey has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectiv...","description_format":"text","description_chars":12646,"description_truncated":true,"requirements":{"experience_years_min":12,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Financial Services","Professional Services","Consumer Loans & Pawnshops"],"lifecycle":[{"event":"open","at":"2026-10-02T07:33:54Z"}],"visa":[],"liveness":{"score":81,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":0.9,"age_days":19,"expected_fill_days":39,"reasons":["conf:3","velocity","win:mid","comp:brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":{"stated_usd_annual":181000,"is_top_pay":true},"html_url":"https://alion.io/job/key-com-senior-offensive-security-engineer-red-team","json_url":"https://alion.io/job/key-com-senior-offensive-security-engineer-red-team.json","meta":{"generated_at":"2026-10-07T01:11:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1986,"day_limit":5000,"remaining_today":3014,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":450627},"rest":"https://alion.io/mcp/rest/get_company?id=450627"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fkey-com-senior-offensive-security-engineer-red-team"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fkey-com-senior-offensive-security-engineer-red-team"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fkey-com-senior-offensive-security-engineer-red-team"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/key-com-senior-offensive-security-engineer-red-team\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fkey-com-senior-offensive-security-engineer-red-team"}]}