RIT logo

Senior SAFE Lab Cybersecurity Engineer

Salary
$81.6K–$100K
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Position Highlights

The Senior SAFE Lab Cybersecurity Engineer leads offensive security assessments and adversary-emulation campaigns for corporate clients. They produce reports and provide briefings to clients. They are responsible for supervising teams of student employees and adjunct consultants.

The Senior Cyber SAFE Engineer is the Cyber Range and Training Center's principal offensive security practitioner and the technical author of the adversary activity on which the Center's commercial, academic, and research programs depend. Realistic, instrumented, repeatable adversary emulation is the core product of the Center's fee-for-service training and assessment work.

Key responsibilities include:

  • leads client-facing security testing and evaluation in the SAFE Lab: penetration testing and ethical hacking of enterprise, government, military, and cyber-physical environments, and the translation of those findings into written reports and briefings that non-technical executives and technical practitioners can both act on.
  • converts assessment findings and current threat intelligence into staged, observable attack campaigns that drive the Center's immersive exercises, competitions, and client engagements -- and ensures that those campaigns generate the telemetry participants must be able to find, in the tools and formats those participants actually use.

The Senior SAFE Lab Cybersecurity Engineer serves as exercise control during live delivery, adapting scenario tempo and injects in real time while paying clients are in the room, and is accountable for the technical integrity of engagements that carry contractual delivery obligations. The position also leads teams of student employees and industry-expert adjunct consultants and is expected to document its work to a standard that allows another qualified engineer to reproduce any engagement independently.

This position reports to the Director of the Cyber Range and Training Center within RIT's ESL Global Cybersecurity Institute and is expected to lead engagements independently with low-touch oversight.

Preferred experience:

  • A minimum of 5 years of professional experience in offensive security, including penetration testing, red teaming, or adversary emulation against production or production-representative environments.
  • A minimum of 2 years of experience designing or executing adversary emulation, red team, purple team, or cyber exercise scenarios in which the activity was instrumented and observed by a defending audience.
  • At least 3 years of client-facing consulting experience, including scoping, statement-of-work input, and level-of-effort estimation for fee-for-service engagements.
  • Demonstrated experience leading engagements and directing the work of other technical contributors.
  • Demonstrated experience delivering written assessment reports and verbal briefings directly to paying or sponsoring clients.
  • Experience designing and deploying system/network environments using Openstack and infrastructure-as-code (ansible/terraform/etc).
  • Experience designing or delivering cyber exercises, wargames, tabletop-to-technical hybrids, or competition infrastructure for external audiences.
  • Detection engineering experience: authoring SIEM correlation content, EDR detections, or purple-team validation of detective controls.
  • Experience with Splunk Enterprise Security, CrowdStrike, or comparable commercial detection stacks in a client-aligned configuration.
  • Experience applying AI and large language model tooling to offensive security or exercise workflows — including agentic tooling and Model Context Protocol integrations — together with sound judgment regarding validation, data handling, and disclosure.
  • Experience evaluating AI-enabled security products under realistic adversarial conditions and reporting evidence-based adoption guidance.
  • Experience with cloud and identity attack paths in Azure/Entra ID, AWS, or Google Cloud.
  • Experience with operational technology, ICS/SCADA, or energy-grid networks, devices, and protocols.
  • Experience creating models or digital twins of tested networks and deploying them using infrastructure as code such as Ansible or Terraform, or simulation platforms such as Unreal Engine or MATLAB Simulink.
  • At least two years of experience managing or maintaining enterprise IT infrastructure (servers, storage, network, or security).
  • Experience mentoring students or junior engineers, and prior involvement in academic or government research projects related to cybersecurity.
  • Certifications such as CISSP, GCIH, GCFA, or PMP.
  • Existing security clearance or the ability to obtain one.
  • Dedication to learning and advancing your skills.

Preferred Skills

  • Deep expertise in penetration testing tools and methodologies, with a current certification such as OSCP, OSEP, GPEN, GXPN, CRTO, or equivalent, or the ability to obtain one within six months of hire.
  • Demonstrated ability to compromise and operate within Windows Active Directory environments, including credential attacks, Kerberos abuse, delegation, trust relationships, and domain persistence.
  • Working command of the MITRE ATT&CK framework and the ability to design attack chains that map to specific techniques and defined learning objectives.
  • Hands-on experience with command-and-control and adversary emulation frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Caldera, or Atomic Red Team, and the judgment to operate them safely in isolated environments.
  • Practical understanding of how offensive activity appears in defensive telemetry, and the ability to validate that an emulated attack produces the intended, discoverable evidence.
  • Working proficiency with SIEM and log platforms — Splunk and Wazuh in particular — including search authoring, data onboarding, field extraction, and log formatting.
  • Proficiency administering Windows and Linux systems and enterprise networking sufficient to build, segment, and troubleshoot isolated exercise environments.
  • Scripting and automation ability in Python, PowerShell, and Bash, and working familiarity with version control and infrastructure-as-code practice.
  • Ability to write clearly for both executive and deeply technical audiences, and to deliver briefings and hotwashes with composure under scrutiny.
  • Ability to maintain accurate documentation to a standard that allows another qualified engineer to reproduce the work independently.
  • Sound professional judgment regarding authorization boundaries, rules of engagement, safety of destructive techniques, client data handling, and export-control obligations.
  • Ability to remain composed and effective while diagnosing technical faults during live, high-visibility, revenue-bearing engagements.
  • Familiarity with regulations and standards relevant to cybersecurity and privacy.
  • Ability to work within a team setting and to direct the work of students and adjunct consultants.
  • Availability for evening, weekend, and consecutive multi-day work in support of exercise schedules, and for occasional travel.

Essential Duties & Responsibilities

  • Conducts vulnerability scanning and penetration testing
  • Investigates services and application security. Performs security comparative review, security risk assessment, and security validation
  • Performs operational duties during security incident responses, troubleshoots and performs root cause analysis for security solutions
  • Analyzes, designs, and installs complex enterprise security solutions and frameworks
  • Designs security solutions architecture, selects tools and partners, and configures and manages capacity, changes, documentation, and reporting
  • Contributes to the documentation of security processes and procedures
  • Other duties as assigned

Knowledge, Skills, & Abilities

  • Knowledge of security architecture principles and best practices for system and network protection
  • Knowledge of advanced cybersecurity tools, such as firewalls and intrusion prevention systems
  • Skill in deploying and configuring cybersecurity tools and technologies to mitigate risks
  • Skill in designing and implementing security measures to protect IT infrastructure and sensitive data
  • Ability to lead complex technical projects
  • Ability to analyze complex security threats and develop proactive solutions to prevent breaches
  • Ability to troubleshoot and resolve advanced security incidents with minimal supervision

Minimum Education & Experience

  • Bachelor's degree in related field
  • 5 years of related experience
  • Equivalent combination of experience & education may be considered

Job Level Overview

Specialized Contributor Level 3 - A senior-level role requiring broad understanding of the profession or field of work. Independently leads diverse and often complex assignments, projects, or programs. May act as a mentor and guide less experienced staff.


FLSA Category

Exempt

Work Location

Hybrid

Compensation

$81,600-$100,000 annually

Application Materials

When you are ready to complete an application for this position please be prepared to submit the below requested information. This will be required to ensure your application is processed in a timely manner.

Cover Letter, Curriculum Vitae or Resume

Candidates must be eligible to work in the United States.


Additional Details

In compliance with NYS's Pay Transparency Act, the salary range for this position is listed above. Rochester Institute of Technology considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and organizational considerations when extending an offer. The hiring process for this position may require a criminal background check and/or motor vehicle records check. Any verbal or written offer made is contingent on satisfactory results, as determined by Human Resources. RIT provides equal opportunity to all qualified individuals and does not discriminate on the basis of race, color, creed, age, marital status, sex, gender, religion, sexual orientation, gender identity, gender expression, national origin, veteran status or disability in its hiring, admissions, educational programs and activities. RIT provides reasonable accommodations to applicants with disabilities under the Rehabilitation Act, the Americans with Disabilities Act, the New York Human Rights Law, or similar applicable law.


If you need reasonable accommodation for any part of the application and hiring process, please contact the Human Resources office at 585-475-2424 or email your request to careers@rit.edu. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.

About Us

Founded in 1829, Rochester Institute of Technology has a long-standing history of innovation that blends the arts, technology, and experiential learning. In addition to its main campus in Rochester, New York, RIT maintains a strong international presence with over 100 active global partnerships and international campuses in Croatia, Dubai, and Kosovo. As of Fall 2024, total student enrollment across all campuses exceeded 21,000. Nationally recognized for its co-op and internship programs, RIT is supported by more than 4,000 dedicated faculty and staff members committed to student success. Its 1,300-acre suburban campus features cutting-edge facilities that reflect RIT’s strengths in applied research, design, and workforce development.

Already a Tiger?

Apply in Workday

Similar jobs

Apply for this job