Lead, Offensive Security Engineer

Newark, NJ, USA March 16, 2026 Full Time Workday
Job Classification: Technology - Information Security Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.   Your Team & Role     As a Lead Offensive Security Engineer on the Attack Surface Management team, you will be at the forefront of our efforts to identify and mitigate security risks. Your responsibilities will include conducting sophisticated red team and purple team exercises to challenge and refine our defensive strategies. You will conduct a variety of penetration testing activities, focusing on diverse targets such as web applications, AI systems, and Active Directory environments, in order to uncover and address vulnerabilities. Beyond traditional offensive security operations, you will also play a key role in supporting and advancing our bug bounty program, ensuring that any potential threats are swiftly identified and resolved. Here is What You Can Expect on a Typical Day  Conduct Purple Team Assessments: Collaborate with the defensive (blue) team to run combined exercises that enhance detection and response capabilities, fostering a stronger overall security posture. Perform Penetration Testing: Execute comprehensive penetration tests on various systems, including web applications, mobile applications, external networks, AI/ML systems, and SaaS environments. Adversary Emulation: Emulate tactics, techniques, and procedures (TTPs) of known threat actors to test the effectiveness of security controls and incident response processes. Vulnerability Identification and Exploitation: Identify and exploit weaknesses in systems and applications to demonstrate potential risks and impact. Support Bug Bounty Programs: Participate in and enhance the bug bounty program by validating submissions, providing detailed analysis, and collaborating with researchers and internal stakeholders to address vulnerabilities. STRIDE Threat Modeling: As an SME in attack and vulnerability exploitation techniques, assist stakeholders in comprehensive Threat Modeling exercises to identify potential weaknesses and harden systems. Develop Offensive Security Tools: Create and maintain tools and scripts to assist with red team operations and penetration testing efforts. Conduct Security Research: Regularly research and learn new TTPs in public and closed forums. Work with teammates to assess Prudential’s risk and work with teams to implement and validate controls as necessary. Threat Intelligence Integration: Utilize threat intelligence to inform red team scenarios and improve the realism and relevance of simulations. Plan and Execute Red Team Exercises: Design and carry out advanced red team operations to simulate real-world attacks, identifying and exploiting vulnerabilities within client environments. Reporting and Documentation: Produce detailed reports of findings, including technical descriptions of vulnerabilities, potential impacts, and recommended remediation steps. Engage with Stakeholders: Communicate effectively with internal and external stakeholders to present findings, provide recommendations, and support remediation efforts. Knowledge Sharing and Training: Conduct internal training sessions, workshops, and presentations to share insights and improve the overall skill level of the security team. Mentor and knowledge share with other Offensive Security engineers on the team. Continuous Improvement: Regularly review and refine testing methodologies, tools, and processes to ensure cutting-edge offensive security practices. Provide Remediation Guidance: Offer expert recommendations to internal stakeholders on how to address and mitigate identified security vulnerabilities, ensuring they adopt best practices for enhanced protection.   The Skills & Expertise You Bring    Bachelor of Computer Science or Engineering or experience in related fields    Ability to coach others with minimal guidance and effectively leverage diverse ideas, experiences, thoughts and perspectives to the benefit of the organization Experience with agile development methodologies Knowledge of business concepts tools and processes that are needed for making sound decisions in the context of the company's business    Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges    Excellent problem solving, communication and collaboration skills   Advanced experience and/or expertise with several of the following:  Proven experience conducting a variety of offensive security operations, including red teaming and penetration testing across multiple domains such as network, web applications, mobile platforms, cloud environments, social engineering tactics, and scripting or tool creation. Expertise in Active Directory red teaming, with a deep understanding of advanced offensive tactics, techniques, and procedures (TTPs) used to exploit Active Directory environments. Experience performing security reviews of existing infrastructure and demonstrating vulnerabilities Building, deploying, and maintaining red team infrastructure Knowledge of adversarial TTPs Proficiency rating vulnerabilities using the CVSS scoring system Experience with Threat Modeling, preferably using the STRIDE methodology Competent with testing frameworks and tools such as Burp Suite, Metasploit, VECTR, Cobalt Strike, Kali Linux, Nessus, PowerShell, Empire and AutoSploit. Understanding of OWASP, the MITRE ATT&CK framework and the software development lifecycle (SDLC). CVE/Bug Bounty/Responsible disclosures Exploit development Proven success in planning, executing, and debriefing complex red team campaigns. Experience with enterprise attack surface reduction strategies and mapping attack paths in complex Active Directory environments. Proficiency in one or more programming languages, and can both read and understand code written by others. Proficient in scripting languages such as Python, PowerShell, and Bash. Knowledge of exploiting vulnerabilities in Entra ID, AWS IAM, or other cloud identity systems. Background in emulating sophisticated threat actor, including TTPs mapped to the MITRE ATT&CK framework.   Preferred qualifications:  IT Security certifications (e.g., GPEN, GWAPT, OSCP, OSCE, OSWE, OSEP, OSCE, RTO, GRTP, AWS/Azure/GCP Security certs, etc.).   Cloud (AWS, Azure, GCP, etc.) Certs  Other Security Certifications beyond intro level  Scripting background (Python, Perl, bash, etc.) You’ll Love Working Here Because You Can  Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we’ll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You’ll be surprised by what this rock-solid organization has in store for you.  What we offer you: Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $128,100.00 to $190,700.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills. Market competitive base salaries, with a yearly bonus potential at every level. Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave. 401(k) plan with company match (up to 4%). Company-funded pension plan. Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs. Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development. Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs. Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period), after one year of service. Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week. Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom. Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law. If you need an accommodation to complete the application process, please email [email protected]. If you are experiencing a technical issue with your application or an assessment, please email [email protected] to request assistance. Prudential Financial, Inc. (NYSE: PRU), a global financial services leader and premier active global investment manager with approximately $1.4 trillion in assets under management as of Dec. 31, 2023, has operations in the United States, Asia, Europe, and Latin America. Prudential’s diverse and talented employees help make lives better and create financial opportunity for more people by expanding access to investing, insurance, and retirement security. Prudential’s iconic Rock symbol has stood for strength, stability, expertise and innovation for 150 years. For more information please visit news.prudential.com. Our Commitment to an Inclusive Workplace Prudential Financial, Inc. serves its customers in more than 40 countries and territories, and we seek talented, creative individuals from a variety of backgrounds, worldviews, and life circumstances to work with us. We are focused on creating a fully inclusive culture, where all employees feel comfortable bringing their authentic selves to work. We don’t just accept difference—we celebrate it, support it, and thrive on it. At Prudential, employees have a unique opportunity to build their career path by owning their development, their career, and their future. We encourage employees to hone their skills and explore continued opportunities within Prudential. PGIM, the global asset management business of Prudential Financial, Inc. (NYSE: PRU), is a global investment manager with US $1.3 trillion in assets under management as of Dec. 31, 2023. With offices in 18 countries, PGIM’s businesses offer a range of investment solutions for retail and institutional investors around the world across a broad range of asset classes, including public fixed income, private fixed income, fundamental equity, quantitative equity, real estate, and alternatives. For more information about PGIM, visit pgim.com. Prudential Financial, Inc. (PFI) of the United States is not affiliated in any manner with Prudential plc, incorporated in the United Kingdom, or with Prudential Assurance Company, a subsidiary of M&G plc, incorporated in the United Kingdom. For more information please visit news.prudential.com. PGIM Inc. (PGIM) is the principal asset management business of Prudential Financial, Inc. (PFI), a company incorporated and with its principal place of business in the United States. PFI of the United States is not affiliated in any manner with Prudential plc, incorporated in the United Kingdom or with Prudential Assurance Company, a subsidiary of M&G plc, incorporated in the United Kingdom. Our Commitment to an Inclusive Workplace Prudential Financial, Inc. serves its customers in more than 40 countries and territories, and we seek talented, creative individuals from a variety of backgrounds, worldviews, and life circumstances to work with us. We are focused on creating a fully inclusive culture, where all employees feel comfortable bringing their authentic selves to work. We don’t just accept difference—we celebrate it, support it, and thrive on it. At Prudential, employees have a unique opportunity to build their career path by owning their development, their career, and their future. We encourage employees to hone their skills and explore continued opportunities within Prudential.
Apply on company site

How to Get Hired at Prudential Financial

  • Prudential Financial is a Newark-based Fortune 500 insurer and asset manager with roughly 40,000 employees and more than $1.5 trillion in assets under management and administration, organized around PGIM, Individual Solutions, Group Insurance, and Retirement Strategies.
  • Applications run through a Workday-hosted portal at jobs.prudential.com; building a clean, parsable resume profile and reusing it across requisitions is the most efficient path through the funnel.
How to apply to Prudential Financial

How well do you match this role?

Check My Resume