Sr. Security Researcher leading red team engagements to enhance security posture at Corebridge Financial. Responsibilities include vulnerability assessment, training, and collaboration across security teams.
Responsibilities
Lead and execute red team engagements: Develop and execute comprehensive red team assessments, including reconnaissance, vulnerability scanning, exploitation, and post-exploitation activities.
Lead and mentor junior red team members, providing guidance, training, and hands-on experience.
Develop and maintain red team methodologies, tools, and infrastructure.
Conduct threat modeling and risk assessments to identify potential attack vectors and prioritize targets.
Develop and execute social engineering campaigns, including phishing, vishing, and physical penetration tests.
Vulnerability research and exploitation: Stay abreast of the latest threat intelligence, vulnerabilities, and exploits.
Research and develop new exploitation techniques and tools.
Conduct in-depth analysis of vulnerabilities and their potential impact.
Reporting and communication: Prepare detailed and concise reports documenting red team findings, including technical details, impact assessments, and remediation recommendations.
Effectively communicate findings to technical and non-technical audiences, including senior management.
Present findings and recommendations at security forums and conferences (optional).
Security awareness and training: Develop and deliver security awareness training programs to employees on topics such as social engineering, phishing, and secure coding practices.
Conduct security awareness campaigns to raise employee awareness of security threats and best practices.
Collaboration: Collaborate with other security teams (e.g., blue team, incident response) to improve overall security posture.
Work with development teams to identify and remediate security vulnerabilities in applications and systems.
Build and maintain relationships with external security researchers and the cybersecurity community.
Requirements
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
5+ years of experience in cybersecurity, with 3+ years of hands-on experience in penetration testing, red teaming.
Understanding of blended attacks.
Proven experience leading and mentoring junior security professionals.
Strong understanding of networking, systems administration, and programming concepts.
Expertise in penetration testing methodologies and tools (e.g., Cobalt Strike, Outflank, Sliver, PowerShell Empire, Metasploit, Kali Linux, Nmap).
Proficiency in scripting languages (e.g., Python, Ruby, PowerShell).
Strong understanding of network protocols (e.g., TCP/IP, HTTP, DNS).
Experience with vulnerability scanners, intrusion detection systems, and firewalls.
Experience with cloud security (e.g., AWS, Azure, GCP) is a plus.
Relevant security certifications (e.g., RTO I, RTO II, OSCP, OSCE, GPEN, CRTP) are highly desired.
Excellent analytical and problem-solving skills.
Strong communication and interpersonal skills.
Ability to work independently and as part of a team.
Strong attention to detail and accuracy.
Ability to adapt to new technologies and challenges.
Project Management.
Benefits
Health and Wellness: We offer a range of medical, dental and vision insurance plans, as well as mental health support and wellness initiatives to promote overall well-being.
Retirement Savings: We offer retirement benefits options, which vary by location. In the U.S., our competitive 401(k) Plan offers a generous dollar-for-dollar Company matching contribution of up to 6% of eligible pay and a Company contribution equal to 3% of eligible pay (subject to annual IRS limits and Plan terms). These Company contributions vest immediately.
Employee Assistance Program: Confidential counseling services and resources are available to all employees.
Matching charitable donations: Corebridge matches donations to tax-exempt organizations 1:1, up to $5,000.
Volunteer Time Off: Employees may use up to 16 volunteer hours annually to support activities that enhance and serve communities where employees live and work.
Paid Time Off: Eligible employees start off with at least 24 Paid Time Off (PTO) days so they can take time off for themselves and their families when they need it.
Job title
Senior Security Researcher, Offensive Security – Red Team
Cybersecurity professional executing the cybersecurity program at Nightwing Intelligence Solutions. Responsible for RMF documentation, vulnerability assessments, and incident response in Sterling, VA.
Senior Network Security Engineer driving Zero Trust security fabric design and optimization at CRC Group. Hands - on role managing Zscaler and Palo Alto implementations across multi - cloud environments.
Lead Cybersecurity Engineer driving security testing automation at AT&T. Collaborating with teams to enhance security across telecom networks and systems.
Cybersecurity Intern supporting the Information Security team at Toyota Insurance. Assisting in developing security programs and conducting risk assessments for enterprise systems.
Cyber Security Intern contributing to security initiatives and real projects at Luminor Group in Estonia. Opportunity to learn and grow within a dynamic banking environment supporting Pan - Baltic operations.
Cyber Security Intern contributing to real projects in a dynamic banking environment with Luminor. Collaborating with interns and building practical skills through meaningful work.
Cyber Security Intern contributing to real projects in a dynamic banking environment at Luminor. Collaborating with teams and gaining hands - on experience in cyber security.
Cybersecurity Engineer performing risk assessment and defining mitigation strategies for railway sub - systems. Collaborating with engineers to ensure secure architecture and compliance with European standards.
Senior Information Security Engineer responsible for evolving data security practices at Mastercard. Focused on data classification, loss prevention and regulatory compliance in a dynamic environment.