Senior SAFE Lab Cybersecurity Engineer

Rochester Institute of Technology

Rochester, NY

ID: 7372111
Posted: Newly posted
Application Deadline: Open Until Filled

Job Description

Key responsibilities include:

leads client-facing security testing and evaluation in the SAFE Lab: penetration testing and ethical hacking of enterprise, government, military, and cyber-physical environments, and the translation of those findings into written reports and briefings that non-technical executives and technical practitioners can both act on.
converts assessment findings and current threat intelligence into staged, observable attack campaigns that drive the Center's immersive exercises, competitions, and client engagements -- and ensures that those campaigns generate the telemetry participants must be able to find, in the tools and formats those participants actually use.


The Senior SAFE Lab Cybersecurity Engineer serves as exercise control during live delivery, adapting scenario tempo and injects in real time while paying clients are in the room, and is accountable for the technical integrity of engagements that carry contractual delivery obligations. The position also leads teams of student employees and industry-expert adjunct consultants and is expected to document its work to a standard that allows another qualified engineer to reproduce any engagement independently.

This position reports to the Director of the Cyber Range and Training Center within RIT's ESL Global Cybersecurity Institute and is expected to lead engagements independently with low-touch oversight.





Preferred experience:

A minimum of 5 years of professional experience in offensive security, including penetration testing, red teaming, or adversary emulation against production or production-representative environments.
A minimum of 2 years of experience designing or executing adversary emulation, red team, purple team, or cyber exercise scenarios in which the activity was instrumented and observed by a defending audience.
At least 3 years of client-facing consulting experience, including scoping, statement-of-work input, and level-of-effort estimation for fee-for-service engagements.
Demonstrated experience leading engagements and directing the work of other technical contributors.
Demonstrated experience delivering written assessment reports and verbal briefings directly to paying or sponsoring clients.
Experience designing and deploying system/network environments using Openstack and infrastructure-as-code (ansible/terraform/etc).
Experience designing or delivering cyber exercises, wargames, tabletop-to-technical hybrids, or competition infrastructure for external audiences.
Detection engineering experience: authoring SIEM correlation content, EDR detections, or purple-team validation of detective controls.
Experience with Splunk Enterprise Security, CrowdStrike, or comparable commercial detection stacks in a client-aligned configuration.
Experience applying AI and large language model tooling to offensive security or exercise workflows — including agentic tooling and Model Context Protocol integrations — together with sound judgment regarding validation, data handling, and disclosure.
Experience evaluating AI-enabled security products under realistic adversarial conditions and reporting evidence-based adoption guidance.
Experience with cloud and identity attack paths in Azure/Entra ID, AWS, or Google Cloud.
Experience with operational technology, ICS/SCADA, or energy-grid networks, devices, and protocols.
Experience creating models or digital twins of tested networks and deploying them using infrastructure as code such as Ansible or Terraform, or simulation platforms such as Unreal Engine or MATLAB Simulink.
At least two years of experience managing or maintaining enterprise IT infrastructure (servers, storage, network, or security).
Experience mentoring students or junior engineers, and prior involvement in academic or government research projects related to cybersecurity.
Certifications such as CISSP, GCIH, GCFA, or PMP.
Existing security clearance or the ability to obtain one.
Dedication to learning and advancing your skills.


Preferred Skills

Deep expertise in penetration testing tools and methodologies, with a current certification such as OSCP, OSEP, GPEN, GXPN, CRTO, or equivalent, or the ability to obtain one within six months of hire.
Demonstrated ability to compromise and operate within Windows Active Directory environments, including credential attacks, Kerberos abuse, delegation, trust relationships, and domain persistence.
Working command of the MITRE ATT&CK framework and the ability to design attack chains that map to specific techniques and defined learning objectives.
Hands-on experience with command-and-control and adversary emulation frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Caldera, or Atomic Red Team, and the judgment to operate them safely in isolated environments.
Practical understanding of how offensive activity appears in defensive telemetry, and the ability to validate that an emulated attack produces the intended, discoverable evidence.
Working proficiency with SIEM and log platforms — Splunk and Wazuh in particular — including search authoring, data onboarding, field extraction, and log formatting.
Proficiency administering Windows and Linux systems and enterprise networking sufficient to build, segment, and troubleshoot isolated exercise environments.
Scripting and automation ability in Python, PowerShell, and Bash, and working familiarity with version control and infrastructure-as-code practice.
Ability to write clearly for both executive and deeply technical audiences, and to deliver briefings and hotwashes with composure under scrutiny.
Ability to maintain accurate documentation to a standard that allows another qualified engineer to reproduce the work independently.
Sound professional judgment regarding authorization boundaries, rules of engagement, safety of destructive techniques, client data handling, and export-control obligations.
Ability to remain composed and effective while diagnosing technical faults during live, high-visibility, revenue-bearing engagements.
Familiarity with regulations and standards relevant to cybersecurity and privacy.
Ability to work within a team setting and to direct the work of students and adjunct consultants.
Availability for evening, weekend, and consecutive multi-day work in support of exercise schedules, and for occasional travel.