Sr. Offensive Security Engineer, Security Monitoring

3 months ago


Pittsburgh, United States Merrick Bank Full time
Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right thing, putting the customer first, and Earn, Learn, Have Fun (aka E.L.F.), have defined who we are as an Employer of Choice. Give Yourself Credit, Work at Merrick

Position Summary:

The Senior Offensive Security Engineer operates, monitors, and improves information security processes and systems that protect the Bank’s data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism. This role focuses on application and development security, application penetration testing capabilities, and cloud infrastructure/platform security.

 

Essential Functions:

 

Key Offensive Security responsibilities include:

  • Conducting Red Team Exercises to simulate Advanced Persistent Threats (APTs) against web, mobile, and cloud-based applications to identify security weaknesses and assess the effectiveness of security controls.
  • Perform in-depth manual and automated penetration testing against Cloud and On Prem Networks and applications to discover vulnerabilities and weaknesses that could be exploited.
  • Work with development teams to identify potential security threats early in the software development lifecycle (SDLC) and provide recommendations to mitigate risks.
  • Develop and enhance tools, scripts, and frameworks to automate testing and reporting processes, including setting up continuous integration (CI) security checks.
  • Document findings in detailed, actionable reports for both technical and non-technical stakeholders. Communicate effectively with developers, engineers, and executive leadership on remediation strategies.
  • Collaborate with Blue Team (defensive security), DevOps, and engineering teams to improve detection and response capabilities.
  • Stay updated on the latest security threats, vulnerabilities, and exploits, and apply this knowledge to enhance Red Team operations.

 

 

Each Security Engineer is also responsible to cross-train and be familiar with other security functions as assigned:

  • Security Monitoring & Response - Detects and responds to security events by identifying, reporting, mitigating, and recovering from security incidents.
  • Security Control Engineering and Operations - Enables and protects business services with appropriate access, endpoint, network, data storage, and data loss prevention controls, including vulnerability and controls testing.
  • Security Risk & Program Management - Assesses and advises technology and business groups by identifying, prioritizing, managing, and reporting security risk.
  • Performs other duties as assigned.

 

Compliance with Laws & Regulations: 

  • Responsible for complying with all of the Bank’s internal control policies and procedures.
  • Responsible for understanding and complying with all laws and regulations to which the Bank is subject.
  • Responsible for communicating problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.

 

 

 

Education and Experience:

  • Bachelor’s degree in computer science, Cybersecurity, Information Security, or a related field. Equivalent experience will also be considered.
  • 5-8+ years of experience in application security, penetration testing, or Red Team operations.

 

Summary of Qualifications:

  • Proficient in programming/scripting languages such as C#, Python, JavaScript, PowerShell, Bash, or other relevant to security testing.
  • Strong Foundational Linux skills.
  • Expertise in using security testing tools (e.g., Burp Suite, Nessus, C2 Frameworks, SQLMap, NMAP etc.).
  • Strong knowledge of web application frameworks, APIs, microservices, and cloud environments (AWS, Azure, GCP).
  • Familiarity with Secure Software Development Lifecycle (SSDLC) and DevSecOps practices.
  • Familiarity with highly regulated industries, and specifically the banking industry (including FDIC regulations) is preferred.
  • Demonstrated skills with security concepts, defense-in-depth strategies, security tools, and protocols.
  • “White-hat” mentality, with a healthy sense of paranoia (security awareness and risk).
  • Positive, inquisitive, can-do attitude.
  • Self-starter, requires minimal oversight to perform as expected, work well independently and as part of a team.
  • Comfortably perform well under pressure, deliver to commitments on tight deadlines.
  • Meticulous attention to detail.
  • Passion for cybersecurity and technology trends, news, and hacking techniques.

 

 

 

Work Environment/Physical Demands:

  • May require some travel to company, partner, or vendor locations for various job duties.
  • May require some lifting of up to 50 pounds to rack/maintain IT or security equipment

 

Security Responsibilities - General:

This classification requires heightened security awareness to safeguard the Bank's data, including customer non-public personal information.  This security level means that the job includes exposure to all categories of Bank data, including customer non-public personal information.

 

General Disclosure:

The above statements reflect the general information considered necessary to describe the principal functions of the job and should not be considered as a detailed description of all work requirements that may be inherent to the position. In addition, the incumbent may be called upon to personally handle projects or assignments not usually related to the position’s day-to-day activities. Understand and comply with laws and regulations that are applicable to my job function. Understand and comply with company policies and procedures that are applicable to my job function.

We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location. Our benefits offerings include medical, dental, vision, life insurance, 401(k) plan with company match, paid vacation time, sick time, as well as other benefits and programs to meet the needs of our employees. Further details will be shared during the interview or offer process, as appropriate and applicable.
 

 

We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic.  We will conduct a thorough background check for all hires in compliance with applicable law which includes (but may not be limited to) a review of factors including drug testing and employment/personal references. 

Apply Now
  • Engineer I

    2 months ago


    Pittsburgh, United States Merrick Bank Full time

    Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right...


  • Pittsburgh, United States Merrick Bank Full time

    Job DescriptionJob DescriptionMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right...


  • Pittsburgh, Pennsylvania, United States Security Systems of America Full time

    About This Opportunity:We are seeking a highly skilled Electrical Security System Engineer to join our team at Security Systems of America. As an Electrical Security System Engineer, you will play a critical role in designing, installing, and maintaining complex security systems that protect homes and businesses throughout Western Pennsylvania, Ohio, West...


  • Pittsburgh, Pennsylvania, United States KPMG Full time

    Job SummaryKPMG is seeking a skilled Cyber Operations Content Development & Engineering professional to join our Enterprise Security Services organization. As a Cyber Operations Content Development & Engineering professional, you will play a key role in managing and performing day-to-day operational responsibility of security monitoring and incident response...


  • Pittsburgh, Pennsylvania, United States Security 101 Full time

    Sr. Security Systems Engineer - Join Our Team!We are a leading national organization looking for a skilled Sr. Security Systems Engineer to join our team! As a key member of our engineering team, you will be responsible for designing, implementing, and maintaining complex security systems for our clients.This role offers a competitive salary of $70,000 per...


  • Pittsburgh, United States Security Care Inc. Part time

    Job DescriptionJob DescriptionAs an Unarmed Security Office, the primary responsibility is to ensure the safety and protection of client assets in accordance with all local, state and federal laws.Downtown Pittsburgh and East LibertyMonday - Friday 7am -5pm | Consistent part time hours availableEssential Job FunctionsTo provide logistical support regarding...


  • Pittsburgh, Pennsylvania, United States GuidePoint Security Full time

    We are looking for an Enterprise Security Account Manager to join our team at GuidePoint Security. As an Account Executive, you will be responsible for managing and developing relationships with customers, providing a consultative sales approach that delivers the highest level of account management services.About the RoleThe ideal candidate will have a...


  • Pittsburgh, United States Enkompas Full time

    Sr Cyber Security Engineer (Must be a US Citizen) Contract (Three months) Location Pittsburgh (hybrid)Payrate (Commensurate with experience level) The Cyber Detection and Response Engineering role for our client will be responsible for developing and maintaining new threat detection capabilities, triaging and tuning security events and incidents, and...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Full time

    **About Us**Securitas Electronic Security is a world-leading provider of integrated security solutions. Our mission is to help make your world a safer place by delivering unparalleled client experiences.Job SummaryWe are seeking a skilled Program Manager to oversee programs for regional financial, strategic financial, fortune 1000, global accounts retail,...


  • Pittsburgh, Pennsylvania, United States Security 101 Full time

    Job OverviewWe are seeking a skilled and certified Electronics Security Installation Specialist to join our team at Security 101. As a key member of our national organization, you will play a vital role in servicing and installing commercial access and video surveillance systems.The ideal candidate will possess experience in system design, installation,...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    Securitas Electronic Security Inc is a world-leading provider of integrated security solutions that protect and optimize businesses of all types.The company's purpose is to make the world a safer place, with over 13,000 colleagues in 40 countries focused daily on delivering an unparalleled client experience.The company offers a full portfolio of video,...


  • Pittsburgh, Pennsylvania, United States Security 101 Full time

    Are you a motivated and experienced professional looking for a challenging role? As a Low Voltage Security Solutions Technician, you will be responsible for installing, servicing, and programming IP-based security systems. You will work closely with our sales team to evaluate new project opportunities and provide technical support. To succeed in this role,...


  • Pittsburgh, Pennsylvania, United States Security Systems of America Full time

    About the RoleThis is an exciting opportunity for a skilled security alarm technician to join our team and contribute to the protection of homes and businesses throughout Western Pennsylvania, Ohio, West Virginia and Maryland.The successful candidate will work independently and as part of a team to deliver high-quality services to our customers. A valid...

  • Security Specialist

    8 months ago


    Pittsburgh, United States Security Industry Specialists, Inc. Part time $19

    About this position:Department: RetailLocation: Pittsburgh, PAEmployment Type: PT/FlexAbout us: Security Industry Specialists, Inc. (SIS) provides security solutions to some of the most recognized companies and brands in the world. We deliver services that consistently exceed those of our peers. We accomplish this through innovation, constant process...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    Company Overview:Securitas Electronic Security Inc. is a world-leading provider of integrated security solutions that protect, connect, and optimize businesses of all types and sizes.Our company has more than 13,000 colleagues in 40 countries, all dedicated to helping make the world a safer place.We deliver unparalleled client experiences through our...


  • Pittsburgh, United States Security Systems of America Full time

    Job DescriptionJob DescriptionSUMMARY DESCRIPTIONSecurity Systems of America is seeking a highly motivated and determined Security Alarm Technician. The Security Alarm Technician works closely with both customers and the sales department to install, program, maintain and repair security alarm wiring and equipment in accordance with all relevant standards,...


  • Pittsburgh, United States Software Engineering Institute Full time

    What We Do: The SEI helps advance software engineering principles and practices and serves as a national resource in software engineering and computer security. The SEI works closely with academia, defense and government organizations, and industry to continually improve software-intensive systems. Our core purpose is to help organizations improve software...


  • Pittsburgh, United States Software Engineering Institute Full time

    About the role Are you an engineer who enjoys a challenge? Are you excited about working for an FFRDC focused on areas critical to national security? Do you want to join a collaborative team that develops and uses best-in-class tools to enable end-to-end software development? If so, we want you for our team, where you'll be part of an exciting and impactful...


  • Pittsburgh, Pennsylvania, United States Security Systems of America Full time

    Job OverviewWe are seeking a highly motivated and determined security alarm technician to join our team. The successful candidate will work closely with customers and the sales department to install, program, maintain and repair security alarm wiring and equipment in accordance with all relevant standards, guidelines and electrical code requirements.The...


  • Pittsburgh, Pennsylvania, United States Security Systems of America Full time

    Job OverviewWe are seeking a highly motivated and determined Security Alarm Technician to join our team. The ideal candidate will work closely with customers and the sales department to install, program, maintain, and repair security alarm wiring and equipment in accordance with all relevant standards, guidelines, and electrical code requirements.The...