Senior Penetration Tester
Conduct penetration testing across Snowflake’s cloud environments, applications, systems, and networks, developing novel attack methods and automation while partnering with security and engineering teams. The role requires at least five years of penetration-testing experience and broad cloud-native technology expertise.
About the job
Responsibilities
- Perform penetration testing engagements against diverse cloud environments, identifying vulnerabilities in software, systems, and networks.
- Set scope, priority-based test plans, and timelines for penetration testing engagements.
- Develop testing approaches for new applications, technologies, protocols, controls, and concepts without established methodologies.
- Work with security and engineering teams to manage product releases, plan engagements, communicate findings and recommendations, and inform stakeholders.
- Partner with Product Security engineers to drive reviews, designs, and controls based on penetration-testing outcomes.
- Advocate for and support other software development lifecycle processes as needed.
- Develop automated security testing tools and security automation frameworks to improve scalability and eliminate recurring vulnerabilities.
Requirements
- 5+ years of penetration-testing experience.
- Experience finding and exploiting vulnerabilities in Java, TypeScript, JavaScript, Go, Python, or C++.
- Experience testing Kubernetes, AWS, Azure, or Google Cloud environments.
- Experience with cloud-native systems and applications, AI agents and agentic workloads, client-side applications, microservices, database systems, drivers, connectors, and web applications.
- Strong understanding of technologies supporting applications and systems to assess the breadth and impact of risks and solutions.
- Ability to develop new attack methods using fundamental technology knowledge rather than relying primarily on tools.
- Strong communication skills and a track record of delivering results.
- Experience balancing security and business demands while performing penetration testing for products approaching release.
Benefits and Compensation
- Opportunity to work on innovative cloud and application security programs and a wide variety of emerging technologies.
- Support from customers and the business for security initiatives.
- Collaborative team with diverse backgrounds and skills.
- Significant opportunity for impact at a fast-growing software company.
Skills
Penetration Testing, Kubernetes, AWS, Microsoft Azure, GCP, Java, TypeScript, JavaScript, Go, Python, C++, Cloud-Native Systems, AI Agents, Microservices, Web Applications
Similar jobs
Security Engineering jobsLeads advanced network security incident response for sophisticated DDoS attacks, routing anomalies, and infrastructure threats. The role requires 8+ years of relevant experience, expert BGP and GRE knowledge, detection engineering skills, and automation experience with Python, Go, Bash, or AI tooling.
Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.