Principal-security Engrg

Verizon Verizon · Telecom · Hyderabad, India +1

Principal Security Engineer to lead Red Team and Adversary Simulation capability, focusing on testing People, Processes, and Technology against advanced threats. The role involves designing and executing Red Team campaigns, targeting modern architectures and AI ecosystems, leveraging generative AI for offensive operations, testing detection and response, driving Purple Teaming, managing attack infrastructure as code, and providing mentorship. Requires practical experience in Red Teaming, enterprise tech stacks, and AI security risks, including prompt engineering and LLM jailbreaking.

What you'd actually do

  1. Lead Adversary Simulations: Design and execute complex, objective-based Red Team campaigns modeled on real-world adversaries targeting the telecom industry, utilizing the MITRE ATT&CK framework.
  2. Target Modern Architectures & AI Ecosystems: Focus attacks on the modern software supply chain, full-stack applications (Node, Angular, Java), and cloud environments. Spearhead offensive engagements against AI-driven applications, including testing Model Context Protocol (MCP) integrations, custom LLM agents, and human-in-the-loop (HITL) validations.
  3. AI-Augmented Offensive Operations: Actively leverage generative AI and modern tooling to accelerate vulnerability research, automate custom payload generation, and scale red team workflows.
  4. Test Detection and Response: Operate with stealth and precision to evaluate Verizon's logging, alerting, and incident response pipelines in real-time, focusing on "Living off the Land" methodologies.
  5. Drive True Purple Teaming: Embrace a Gray/White-box methodology by walking alongside product and development teams. Lead post-campaign replay exercises with the Blue Team and developers to build robust detection rules and secure coding practices.

Skills

Required

  • Red Teaming
  • Adversary Simulation
  • Offensive Security
  • MITRE ATT&CK framework
  • Threat Intelligence integration
  • APT emulation
  • EDR/XDR solutions
  • Node.js
  • Angular
  • Java
  • AI security risks
  • prompt engineering
  • LLM jailbreaking
  • AI agent frameworks/APIs
  • Command and Control (C2) frameworks
  • Cobalt Strike
  • Mythic
  • Sliver
  • Purple Teaming
  • detection engineering
  • secure coding practices

Nice to have

  • cloud-native architectures
  • containerization platforms
  • Docker
  • Kubernetes
  • CI/CD pipelines
  • OSCP
  • CRTO
  • CRTP
  • GXPN
  • OSEP
  • OSWE
  • OSED
  • cloud security architecture
  • C#
  • C++
  • Go
  • Rust
  • Python
  • Bash
  • PowerShell
  • attack surface management
  • OSINT collection
  • telecommunications industry threat landscape
  • executive communication skills

What the JD emphasized

  • extensive work experience in a relevant security field
  • dedicated, hands-on experience in Red Teaming, adversary simulation, or advanced offensive security
  • core offensive security certifications: OSCP, CRTO, CRTP, or GXPN
  • Practical development experience
  • Applied knowledge of AI security risks and usage

Other signals

  • AI-augmented offensive operations
  • AI security risks and usage
  • custom LLM agents