Staff, Security Engineer

Macy's

Johns Creek (GA)

On-site

USD 170,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Macy's is seeking a Staff Vulnerability Engineer to lead penetration testing and vulnerability management across complex applications, OS, and networks. The role drives proactive assessment against real-world tactics, techniques, and procedures (TTPs) to strengthen Macy’s security resilience.

You will develop threat-based testing programs, mentor engineers, and collaborate with security and engineering teams to implement mitigations and improvements across cloud and on-prem environments.

Qualifications

  • PhD or Master’s degree in a technical discipline preferred.
  • AI, Cloud, or Cybersecurity certifications are a plus.
  • 10+ years of experience in software engineering, cybersecurity, AI/ML, or related fields with production-scale deployments.

Responsibilities

  • Establish a risk-based approach for evaluating and prioritizing new and emerging threats.
  • Stay current on emerging technology trends and the threat landscape, providing subject matter knowledge on specific adversarial threats and risks to assist with mitigation strategies.
  • Design, coordinate, and lead simulations based on organizationally defined threat scenarios.
  • Participate in reviewing and developing security strategies, best practices, policies, and procedures.
  • Provide leadership, share knowledge, and mentor team members.
  • Build working relationships with Macy’s TMRC, leadership, and third parties to identify top threats.
  • Develop standard Rules of Engagement for real-time testing.
  • Document detailed findings, analysis, and recommendations.

Skills

AI & Machine Learning
Security Engineering
Cloud & Infrastructure
Threat Protection
Research & Innovation
Leadership & Collaboration
Communication
Education/Certifications
Experience

Education

PhD or Master’s degree in a technical discipline

Job description

The Staff, Vulnerability Engineer is a specialist in Penetration Testing and Information Security Vulnerability Management. This hands-on role involves conducting penetration tests and vulnerability assessments on complex applications, operating systems, and wired and wireless networks. In response to an ever-changing threat landscape, they establish a proactive program to assess Macy’s resilience against real-world tactics, techniques, and procedures (TTPs).

What You Will Do
  • Establish a risk-based approach for evaluating and prioritizing new and emerging threats.
  • Stay current on emerging technology trends and the threat landscape, providing subject matter knowledge on specific adversarial threats and risks to assist with mitigation strategies.
  • Design, coordinate, and lead simulations based on organizationally defined threat scenarios.
  • Participate in reviewing and developing security strategies, best practices, policies, and procedures.
  • Provide leadership, share knowledge, and mentor team members.
  • Build working relationships with Macy’s TMRC, leadership, and third parties to identify top threats.
  • Develop standard Rules of Engagement for real-time testing.
  • Document detailed findings, analysis, and recommendations.
Skills You Will Need
  • AI & Machine Learning: Expertise in Generative AI, LLMs, RAG, AI Agents, Prompt Engineering, LangChain/LangGraph, anomaly detection, NLP, transformers, and security-focused ML solutions.
  • Security Engineering: Strong experience in detection engineering, threat hunting, SIEM/XDR/EDR, MITRE ATT&CK, Sigma, OCSF, threat intelligence, and enterprise security operations.
  • Cloud & Infrastructure: Advanced knowledge of AWS, Azure, GCP, Databricks, Kubernetes, Docker, CI/CD, and scalable cloud-native security architectures.
  • Threat Protection: Experience protecting large enterprise environments through advanced analytics, behavioral detection, adversary simulation, and AI-powered security automation.
  • Research & Innovation: Proven track record of cybersecurity research, patents, publications, and development of innovative security technologies.
  • Leadership & Collaboration: Ability to lead cross-functional initiatives, influence architecture decisions, mentor engineers, and partner effectively across security and engineering organizations.
  • Communication: Excellent written, verbal, and presentation skills, with experience communicating technical concepts to executive and technical audiences.
  • Education/Certifications: PhD or Master's degree in a technical discipline preferred; AI, Cloud, or Cybersecurity certifications are a plus.
  • Experience: 10+ years of experience in software engineering, cybersecurity, AI/ML, or related fields with production-scale deployments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff, Security Engineer
Staff, Security Engineer

Bloomingdale's Inc. • Johns Creek (GA)

On-site
USD 80,000 - 120,000
Health and Wellness Benefits
401k match opportunity
Paid Time Off
+1
Vulnerability & Pen-Testing Engineer — Threat Leader
Vulnerability & Pen-Testing Engineer — Threat Leader

Macy's • Johns Creek (GA)

On-site
USD 170,000 - 210,000
Staff Security Engineer - Cyber Security
Staff Security Engineer - Cyber Security

Macy's • Duluth (GA)

On-site
USD 100,000 - 130,000
Merchandise discounts
Performance-based incentives
Annual merit review
+2
Security Operations Vice President - Vulnerability Management
Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 90,000 - 110,000
Attack Surface Analyst 2
Attack Surface Analyst 2

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Principal Security Engineer
Principal Security Engineer

Valley Bank • Morristown (NJ)

On-site
USD 180,000 - 240,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000