Staff Security Engineer – Red Team (ai)

GEICO GEICO · Insurance · Seattle, WA +3

Staff Security Engineer for Red Team focusing on AI-driven adversary operations. The role involves planning, executing, and delivering Red Team and Adversary Emulation operations, with a specific emphasis on testing AI applications and agents, and leveraging AI for Red Team efficiencies. Requires deep technical expertise in offensive security and AI/LLM architecture.

What you'd actually do

  1. Participate in AI-focused adversary operations: plan, execute and deliver Red Team, Purple Team and other Adversary Emulation operations.
  2. Scope and design operations: define objectives, target scope, success criteria, safety controls.
  3. Develop and run emulations: build, customize, and execute emulation plans using platforms such as MITRE Caldera, or similar products.
  4. Execute advanced AI-leveraged tradecraft across enterprise environments (identity, endpoints, networks, cloud, SaaS) in a controlled, measurable way.
  5. Partner with defenders: work directly with Detection Engineering, Threat Intelligence, and Risk Management to validate telemetry coverage, tune detections, improve response playbooks, and close visibility gaps.

Skills

Required

  • 8+ years of experience in Offensive Security operations
  • 5+ years of hands-on experience running Red Team, Purple Team, and other Adversary operations in enterprise environments
  • Deep understanding of LLM architecture and familiarity with how models process input, manage context, and generate output
  • Experience with AI frameworks and tools such as PyTorch, TensorFlow, Hugging Face, and LangChain
  • Experience with Azure, AWS, GCP or other cloud providers
  • Strong working knowledge of MITRE ATLAS and ATT&CK, and the ability to translate TTPs into repeatable emulations and measurable detection outcomes
  • Hands-on experience with adversary emulation platforms, including building/maintaining emulations and running operations
  • Demonstrated capability with core operator tradecraft (C2, payload delivery, privilege escalation, lateral movement, persistence, and operational security) appropriate to authorized testing
  • Extensive use of red team frameworks: Cobalt Strike, Sliver, Metasploit, Empire, BloodHound

Nice to have

  • OSCP, OSCE, CRTO, CISSP, or relevant Red Team/offensive security certs
  • GIAC Penetration Testing, Red Team certifications (GCTI, GPEN, GXPN) a plus
  • Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing
  • Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)
  • Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections

What the JD emphasized

  • AI-driven adversary operations
  • testing/evaluation of AI applications and agents
  • leveraging of agentic AI for efficiencies
  • AI-focused adversary operations
  • Deep understanding of LLM architecture
  • Experience with AI frameworks and tools

Other signals

  • AI-driven adversary operations
  • testing/evaluation of AI applications and agents
  • leveraging of agentic AI for efficiencies
  • AI-focused adversary operations
  • Deep understanding of LLM architecture
  • Experience with AI frameworks and tools