Skip to content

Staff Offensive Security Engineer

Leads continuous offensive security validation across cloud, mobile, corporate, and hardware environments. Requires 8+ years in offensive security, deep AWS and application-security expertise, advanced scripting ability, and leadership in red teaming and vulnerability research.

About the job

Responsibilities

  • Define the long-term technical vision for continuous offensive security validation.
  • Design and execute complex, multi-stage red-team operations and adversary simulations across AWS cloud infrastructure, iOS and Android mobile applications, and internal corporate environments.
  • Conduct deep-dive vulnerability research into high-risk areas, including zero-day vulnerabilities and sophisticated logic flaws.
  • Partner with DevOps and Engineering to build automated security guardrails and self-healing infrastructure.
  • Support Detection and Response through purple-team exercises that validate monitoring and alert coverage.
  • Mentor senior and mid-level engineers and promote security-minded development across the R&D organization.

Requirements

  • 8+ years of experience in offensive security, red teaming, or penetration testing.
  • Proven ability to uncover critical vulnerabilities in complex environments.
  • Deep knowledge of AWS security architecture, IAM bypass techniques, Kubernetes container escapes, and serverless security.
  • Application security experience, including manual code review in Node.js, Python, or Go and bypass techniques for modern web and mobile security controls.
  • Ability to script in Python, Bash, or Go to automate exploitation chains or integrate security testing into CI/CD pipelines.
  • Ability to communicate complex technical risks as business impact to executive stakeholders and collaborate effectively with software engineers.
  • Curiosity, persistence, and an ethical-hacking mindset.

Nice-to-haves

  • OSCP, OSCE, GXPN, or equivalent advanced offensive-security certification.

Benefits

  • Medical, dental, vision, and HSA match.
  • Paid life insurance, AD&D, and disability benefits.
  • Traditional 401(k) with company match.
  • Unlimited PTO and paid company holidays.
  • Professional development stipend and mental health resources.
  • One-on-one financial planners.
  • Fertility healthcare.
  • Fully paid parental and caregiving leave, including cleaning service and meals during leave.
  • Flexible work-from-home and in-office opportunities.
  • Stocked kitchen, catered lunches, and occasional in-office events.
  • Employee resource groups.

Skills

AWS, Kubernetes, Serverless Security, IAM, Node.js, Python, Go, Bash, CI/CD, Red Teaming, Penetration Testing, Vulnerability Research, Mobile Security, Purple Teaming, Incident Response

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.