Job Closed
This listing is no longer active.
Procter & Gamble, or P&G, is the parent company behind some of the world's most recognizable household and personal care brands. The company was established in
Senior Offensive Security Engineer, Red Team
Location
Ohio
Posted
135 days ago
Salary
$110K - $165K / year
Seniority
Senior
Job Description
Senior Offensive Security Engineer, Red Team
Procter & Gamble
• Lead end-to-end red team operations aligned to priority threat actors: scenario design, ROE, pre-briefs, execution, and hot-wash/AAR • Support purple-team engagements with DFIR/SOC and Detection Engineering to convert TTPs into durable detections, runbooks, and response improvements with measurable outcomes • Orchestrate assumed-breach campaigns emphasizing evasion and control bypass (EDR/AV, email/web security, identity/conditional access, network segmentation, cloud guardrails) • Perform campaign/TTP research, develop internal PoCs/tooling (e.g., tradecraft to exercise specific controls, lightweight payloads), and steward OPSEC • Produce executive-ready risk narratives and technical reporting (ATT&CK mapping, artifacts, evidence handling) and brief senior leadership • Mentor junior engineers; set standards for craft quality, methodology, and safety • Coordinate multi-party/third-party exercises; manage risk, deconflict with production, and ensure stakeholder alignment • Contribute to operational expansion by researching, prototyping, and developing novel capabilities for offensive use • Contribute to program maturity: metrics/KPIs, roadmap, methodology standardization, control validation cadence, and integration with vulnerability management
Job Requirements
- BA or BS degree in Information Security, Cyber Security, Computer Science, or related field (OR 7+ years of relevant experience required in lieu of a degree)
- 3+ years running offensive or emulation operations in large/complex environments, with demonstrated impact on detections/response
- Expertise across 2+ domains: enterprise/web/mobile apps; identity; cloud (AWS/GCP/Azure); network/endpoint; IoT/OT; or directory services
- Proven ability to bypass preventative/detective controls and reach mission objectives while maintaining safety and ROE
- Strong engineering skills (Python, PowerShell, GO, C++, Web Frameworks); comfort with low-level concepts a plus) and familiarity with C2 tradecraft
- Deep command of MITRE ATT&CK and threat-informed defense; history partnering with DFIR/SOC and Detection Engineering
- Excellent executive and technical communication
Benefits
- salary + bonus (if applicable) + benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Technical Implementation Guide Analyst
CACI International IncExpertise and Technology for National Security
• Conduct monthly reviews of Tenable and SteelCloud STIG reports • Analyze STIG data to remediation actions and identify responsible parties to conduct those actions • Document comprehensive action plans for identified STIGs • Develop and maintain custom STIG reports tailored for individual Air Force bases • Provide specific, actionable feedback to Air Force bases and leadership on how to remediate STIGs they are responsible for • Work closely with base IT teams, Enterprise security teams, and other stakeholders to ensure effective STIG management • Stay current with the latest STIG trends, threat intelligence, and best practices in STIG management
• Lead the design and implementation of SAP Security across S/4HANA, Fiori, and the SAP NS2 Private Cloud Edition landscape. • Develop the SAP security architecture and ensure alignment with DoD cybersecurity, RMF, STIGs, and NIST 800-53 controls. • Own the identity and access management strategy, including business role design, authorization concepts, and user provisioning processes. • Lead implementation and ongoing use of SAP GRC Access Control (ARA, EAM, BRM, ARM). • Define and maintain USTRANSCOM-specific Segregation of Duties (SoD) rulesets and automated risk analyses. • Coordinate with SAP NS2 teams to support secure operations, boundary protections, patching, and compliance requirements. • Support security readiness activities, compliance assessments, vulnerability mitigation, and ATO documentation. • Guide security design through project phases including blueprinting, build, testing, cutover, deployment, and sustainment. • Provide consultative guidance on SAP Security and GRC best practices to internal teams and government stakeholders. • Manage and mentor SAP security analysts supporting daily operations and project delivery. • Work on Application Security, Compliance, and Delivery in the areas of SAP S/4HANA Security and GRC implementation.
Professional Services Consultant – Email Security
ProofpointProofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.
• Engage with newly signed enterprise customers as a Proofpoint product expert to implement Proofpoint solutions at their sites, typically using remote web conferencing tools. • Implementation activities include installation, configuration, troubleshooting, customization, testing, and documentation. • Deliver training to customers and partners. • Provide technical expertise and real-life experience in creating solutions, designs, proof of concept and implementation. • Drive high levels of customer satisfaction. • Be a strong voice for your customers into the Marketing and Engineering teams to improve the product and ensure that Proofpoint deployments successful. • Coordinate with multiple parties -- internal departments as well as the customer -- to ensure timely and satisfactory resolution to technical issues, and completion of projects. • Define and document the best practice techniques, processes, templates, and architectures for use by the greater field organization.
Splunk Cybersecurity SME
A.C.Coy CompanyStaffing and consulting firm specializing in IT, Accounting & Finance, Engineering and Sales placements.
• Design, deploy, and maintain on-premises and cloud-based Splunk environments to support enterprise-level monitoring, alerting, and reporting. • Execute new projects as well as data and user onboarding. • Manage knowledge objects (fields, extractions, tags, event types, lookups, workflow actions, aliases, macros, and so on) – through automation, scripting, management server functions; to include .conf and .cfg files in scope of the last four Splunk Enterprise versions. • Mentor and guide junior researchers or team members. • Support off-hours and weekend efforts for incident investigations and systems maintenance.



