Engr Iv-security Engineering

Verizon Verizon · Telecom · Hyderabad, India +1

Security Engineer (Engr IV) for Verizon's Red Team, focusing on adversary simulation against modern software supply chains, full-stack applications, cloud environments, and AI-driven applications. The role involves testing AI security risks, LLM agents, and leveraging generative AI for offensive operations, while also validating cyber hygiene and compliance. Responsibilities include executing adversary simulations, managing attack infrastructure, and collaborating with development teams for purple teaming.

What you'd actually do

  1. Design and execute complex, objective-based Red Team campaigns modeled on real-world adversaries targeting the telecom industry, utilizing the MITRE ATT&CK framework.
  2. Focus attacks on the modern software supply chain, full-stack applications (Node, Angular, Java), and cloud environments. Participate in offensive engagements against AI-driven applications, including testing Model Context Protocol (MCP) integrations, custom LLM agents, and human-in-the-loop (HITL) validations.
  3. Look beyond complex exploit chains to identify and expose systemic failures in foundational cyber hygiene. Map campaign findings against enterprise security policies and regulatory compliance requirements to prove where technical controls are failing.
  4. Actively leverage generative AI and modern tooling to accelerate vulnerability research, automate custom payload generation, and enhance red team workflows.
  5. Operate with stealth and precision to evaluate Verizon's logging, alerting, and incident response pipelines in real-time, focusing on "Living off the Land" methodologies.

Skills

Required

  • Bachelor’s degree with four or more years of work experience in a relevant security field.
  • Four or more years of dedicated, hands-on experience in Red Teaming, adversary simulation, or advanced penetration testing.
  • OSCP, CRTO, CRTP, or GXPN certification.
  • Understanding of the MITRE ATT&CK framework, Threat Intelligence integration, and APT emulation, including experience bypassing modern EDR/XDR solutions.
  • Development experience with enterprise tech stacks (specifically Node.js, Angular, and Java) to conduct white-box source code reviews, exploit complex web applications, and build bespoke attack tooling.
  • Applied knowledge of AI security risks and usage, including prompt engineering, LLM jailbreaking, manipulating AI agent frameworks/APIs (e.g., MCP), and using AI models to accelerate offensive workflows.
  • Knowledge of enterprise cyber hygiene principles, industry security frameworks (e.g., NIST CSF, CIS Controls), and experience translating offensive findings into actionable data for compliance, risk, and audit stakeholders.
  • Expertise in configuring and safely utilizing Command and Control (C2) frameworks (e.g., Cobalt Strike, Mythic, Sliver).
  • Demonstrated experience in collaborative Purple Teaming, translating technical attack narratives into actionable detection engineering rules.

Nice to have

  • Master’s degree in a relevant technical field.
  • In-depth knowledge of securing and attacking cloud-native architectures, containerization platforms (Docker, Kubernetes), and modern CI/CD pipelines.
  • OSEP, OSWE, OSED, or advanced cloud security architecture certifications.
  • Proficiency in programming and scripting languages (such as C#, C++, Go, Rust, Python, Bash, or PowerShell) to develop custom implants, droppers, and evasive tooling.
  • A solid understanding of continuous attack surface management methodology.

What the JD emphasized

  • rigorously test
  • native speaks the language of modern software engineering
  • treats offensive operations as an engineering discipline
  • prioritize strategy over tooling
  • emulating adversary Tactics, Techniques, and Procedures (TTPs)
  • AI security risks
  • LLM jailbreaking
  • manipulating AI agent frameworks/APIs
  • using AI models to accelerate offensive workflows
  • foundational cyber hygiene
  • regulatory compliance requirements
  • technical controls are failing
  • AI-augmented offensive operations
  • logging, alerting, and incident response pipelines
  • Living off the Land" methodologies
  • collaborating closely with product and development teams
  • build robust detection rules and secure coding practices
  • automated CI/CD pipelines
  • explicit Rules of Engagement
  • comprehensive asset inventories
  • strict operational safety and legal compliance
  • dedicated, hands-on experience in Red Teaming, adversary simulation, or advanced penetration testing
  • core offensive security certifications
  • bypassing modern EDR/XDR solutions
  • white-box source code reviews
  • exploit complex web applications
  • build bespoke attack tooling
  • Applied knowledge of AI security risks and usage
  • translating offensive findings into actionable data for compliance, risk, and audit stakeholders
  • collaborative Purple Teaming
  • translating technical attack narratives into actionable detection engineering rules

Other signals

  • AI security risks
  • LLM agents
  • AI-augmented offensive operations
  • testing AI-driven applications