Sr. Offensive Security Engineer, Security Monitoring

1 month ago


Pittsburgh, United States Merrick Bank Full time
Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right thing, putting the customer first, and Earn, Learn, Have Fun (aka E.L.F.), have defined who we are as an Employer of Choice. Give Yourself Credit, Work at Merrick

Position Summary:

The Senior Offensive Security Engineer operates, monitors, and improves information security processes and systems that protect the Bank’s data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism. This role focuses on application and development security, application penetration testing capabilities, and cloud infrastructure/platform security.

 

Essential Functions:

 

Key Offensive Security responsibilities include:

  • Conducting Red Team Exercises to simulate Advanced Persistent Threats (APTs) against web, mobile, and cloud-based applications to identify security weaknesses and assess the effectiveness of security controls.
  • Perform in-depth manual and automated penetration testing against Cloud and On Prem Networks and applications to discover vulnerabilities and weaknesses that could be exploited.
  • Work with development teams to identify potential security threats early in the software development lifecycle (SDLC) and provide recommendations to mitigate risks.
  • Develop and enhance tools, scripts, and frameworks to automate testing and reporting processes, including setting up continuous integration (CI) security checks.
  • Document findings in detailed, actionable reports for both technical and non-technical stakeholders. Communicate effectively with developers, engineers, and executive leadership on remediation strategies.
  • Collaborate with Blue Team (defensive security), DevOps, and engineering teams to improve detection and response capabilities.
  • Stay updated on the latest security threats, vulnerabilities, and exploits, and apply this knowledge to enhance Red Team operations.

 

 

Each Security Engineer is also responsible to cross-train and be familiar with other security functions as assigned:

  • Security Monitoring & Response - Detects and responds to security events by identifying, reporting, mitigating, and recovering from security incidents.
  • Security Control Engineering and Operations - Enables and protects business services with appropriate access, endpoint, network, data storage, and data loss prevention controls, including vulnerability and controls testing.
  • Security Risk & Program Management - Assesses and advises technology and business groups by identifying, prioritizing, managing, and reporting security risk.
  • Performs other duties as assigned.

 

Compliance with Laws & Regulations: 

  • Responsible for complying with all of the Bank’s internal control policies and procedures.
  • Responsible for understanding and complying with all laws and regulations to which the Bank is subject.
  • Responsible for communicating problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.

 

 

 

Education and Experience:

  • Bachelor’s degree in computer science, Cybersecurity, Information Security, or a related field. Equivalent experience will also be considered.
  • 5-8+ years of experience in application security, penetration testing, or Red Team operations.

 

Summary of Qualifications:

  • Proficient in programming/scripting languages such as C#, Python, JavaScript, PowerShell, Bash, or other relevant to security testing.
  • Strong Foundational Linux skills.
  • Expertise in using security testing tools (e.g., Burp Suite, Nessus, C2 Frameworks, SQLMap, NMAP etc.).
  • Strong knowledge of web application frameworks, APIs, microservices, and cloud environments (AWS, Azure, GCP).
  • Familiarity with Secure Software Development Lifecycle (SSDLC) and DevSecOps practices.
  • Familiarity with highly regulated industries, and specifically the banking industry (including FDIC regulations) is preferred.
  • Demonstrated skills with security concepts, defense-in-depth strategies, security tools, and protocols.
  • “White-hat” mentality, with a healthy sense of paranoia (security awareness and risk).
  • Positive, inquisitive, can-do attitude.
  • Self-starter, requires minimal oversight to perform as expected, work well independently and as part of a team.
  • Comfortably perform well under pressure, deliver to commitments on tight deadlines.
  • Meticulous attention to detail.
  • Passion for cybersecurity and technology trends, news, and hacking techniques.

 

 

 

Work Environment/Physical Demands:

  • May require some travel to company, partner, or vendor locations for various job duties.
  • May require some lifting of up to 50 pounds to rack/maintain IT or security equipment

 

Security Responsibilities - General:

This classification requires heightened security awareness to safeguard the Bank's data, including customer non-public personal information.  This security level means that the job includes exposure to all categories of Bank data, including customer non-public personal information.

 

General Disclosure:

The above statements reflect the general information considered necessary to describe the principal functions of the job and should not be considered as a detailed description of all work requirements that may be inherent to the position. In addition, the incumbent may be called upon to personally handle projects or assignments not usually related to the position’s day-to-day activities. Understand and comply with laws and regulations that are applicable to my job function. Understand and comply with company policies and procedures that are applicable to my job function.

We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location. Our benefits offerings include medical, dental, vision, life insurance, 401(k) plan with company match, paid vacation time, sick time, as well as other benefits and programs to meet the needs of our employees. Further details will be shared during the interview or offer process, as appropriate and applicable.
 

 

We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic.  We will conduct a thorough background check for all hires in compliance with applicable law which includes (but may not be limited to) a review of factors including drug testing and employment/personal references. 

Apply Now
  • Engineer I

    3 weeks ago


    Pittsburgh, United States Merrick Bank Full time

    Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right...


  • Pittsburgh, United States Merrick Bank Full time

    Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right...


  • Pittsburgh, United States Merrick Bank Full time

    Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right...


  • Pittsburgh, United States PalAmerican Security Full time

    Experienced unarmed guard needed for a store inside Ross Park Mall. Duties are to observe and report.Shifts available: Tues 5p-8p, Wed 9a-8p, Thurs 9a-8p, Fri 9a-9p (must be able to work all these days and times). Hiring bonus: $750 ($375 after 90 days and a favorable review, $375 90 days after that)PalAmerican Security - Unarmed Security GuardAre you...


  • Pittsburgh, United States PalAmerican Security Full time

    Two experienced unarmed guards needed for a store inside Ross Park Mall. Duties are to observe and report.Shifts available: Shift 1: Sat - 9a-9p, Sun 9a-6p, Mon 9a-8p and Tues from 9a-5p (must be able to work all these days and times). Shift 2: Tues 5p-8p, Wed 9a-8p, Thurs 9a-8p, Fri 9a-9p (must be able to work all these days and times). Hiring bonus: $750...

  • Security Technician

    3 months ago


    Pittsburgh, PA, United States Securitas Electronic Security Full time

    Securitas Technology Corporations is a division of Securitas AB, the largest protective services provider in the world with over 370,000+ Securitas Heroes across the world.   STC offers a full portfolio of video, access, intrusion, fire and integrated systems and services. As a leading systems integrator and alarm monitoring company, we deliver the SES...


  • Pittsburgh, Pennsylvania, United States ACTS-Aviation Security Inc Full time

    Company OverviewACTS-Aviation Security Inc is a leading provider of aviation security solutions, operating in 23 countries with over 16,000 professionals. Our mission is to be the most trusted aviation security provider in the United States, ensuring the safety and security of airports and air transportation networks.Compensation and BenefitsAs an Airport...

  • Security Specialist

    6 months ago


    Pittsburgh, United States Security Industry Specialists, Inc. Part time $19

    About this position:Department: RetailLocation: Pittsburgh, PAEmployment Type: PT/FlexAbout us: Security Industry Specialists, Inc. (SIS) provides security solutions to some of the most recognized companies and brands in the world. We deliver services that consistently exceed those of our peers. We accomplish this through innovation, constant process...


  • Pittsburgh, Pennsylvania, United States Abnormal Security Full time

    About the RoleAbnormal Security is seeking a highly skilled Enterprise Account Executive to join our team. This individual will be responsible for selling our security solutions to enterprise-level accounts within a defined territory.The ideal candidate will have a proven track record of success in enterprise sales, with a strong understanding of security,...


  • Pittsburgh, Pennsylvania, United States Aurora Innovation Full time

    About the RoleAurora Innovation is seeking a highly skilled Product Security Specialist to join our team. As a Product Security Specialist, you will be responsible for ensuring the secure design and implementation of the technology built for the Aurora Driver.Key ResponsibilitiesPerform secure design reviews and threat modeling to identify and prioritize...


  • Pittsburgh, United States Duquesne Light Full time

    Reference #: 18815 Duquesne Light Company, headquartered in downtown Pittsburgh, is a leader in providing electric energy and has been in the forefront of the electric energy market, with a history rooted in technological innovation and superior customer service. Today, the company continues its role as a leader in the transmission and distribution of...


  • Pittsburgh, PA, United States Securitas Electronic Security Full time

    Securitas Technology Corporations is a division of Securitas AB, the largest protective services provider in the world with over 370,000+ Securitas Heroes across the world.   STC offers a full portfolio of video, access, intrusion, fire and integrated systems and services. As a leading systems integrator and alarm monitoring company, we deliver the SES...

  • Security Specialist

    2 days ago


    Pittsburgh, United States Security Industry Specialists Full time

    About this position: •Department: Retail •Location: Pittsburgh, PA •Employment Type: PT/Flex About us: Security Industry Specialists, Inc. (SIS) provides security solutions to some of the most recognized companies and brands in the world. We deliver services that consistently exceed those of our peers. We accomplish this through innovation, constant...

  • Security Specialist

    5 days ago


    Pittsburgh, United States Security Industry Specialists Full time

    About this position: •Department: Retail •Location: Pittsburgh, PA •Employment Type: PT/Flex About us: Security Industry Specialists, Inc. (SIS) provides security solutions to some of the most recognized companies and brands in the world. We deliver services that consistently exceed those of our peers. We accomplish this through innovation, constant...

  • Security Specialist

    1 month ago


    Pittsburgh, Pennsylvania, United States Security Industry Specialists, Inc. Full time

    About the RoleThe Security Specialist, under the direct supervision of the Shift Supervisor, ensures SIS standards and policies are met in overall field services, operations, and functions in assigned areas such as site inspections, emergency response, camera review, client liaison, and special projects as assigned. All duties must be performed in accordance...


  • Pittsburgh, United States Canonical - Jobs Full time

    Job DescriptionJob DescriptionThis is a general track for security-focused engineering in every team at Canonical, across all levels of seniority. Apply here if you are already an exceptional security-focused software engineer.Most product engineering teams at Canonical include one or two spaces for dedicated security-oriented software engineers. Their role...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    Embark on a rewarding career with Securitas Electronic Security Inc as an Electronic Security Systems Specialist. This role offers a unique blend of hands-on experience, virtual training, and industry mentorship through our one-year Technology Apprentice Program.As a specialist, you'll gain practical skills in low-voltage electronic security systems and have...

  • Security Engineer

    3 weeks ago


    Pittsburgh, United States ConsultUSA Full time

    Description:Our client has an immediate need for a Security Engineer, who is responsible for working on multiple initiatives/deliverables simultaneously and to interface with other initiatives that have an impact on their domain.Requirements:Bachelor's Degree in a technical field is a plusExperience delivering and configuring operational security products...

  • Security Engineer

    1 month ago


    pittsburgh, United States ConsultUSA Full time

    Description:Our client has an immediate need for a Security Engineer, who is responsible for working on multiple initiatives/deliverables simultaneously and to interface with other initiatives that have an impact on their domain.Requirements:Bachelor's Degree in a technical field is a plusExperience delivering and configuring operational security products...

  • Security Engineer

    1 month ago


    Pittsburgh, United States ConsultUSA Full time

    Description:Our client has an immediate need for a Security Engineer, who is responsible for working on multiple initiatives/deliverables simultaneously and to interface with other initiatives that have an impact on their domain.Requirements:Bachelor's Degree in a technical field is a plusExperience delivering and configuring operational security products...