# Staff Offensive Security Engineer

**Company:** [Greenlight](https://hotfix.jobs/companies/greenlight)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** AWS, Kubernetes, Serverless Security, IAM, Node.js, Python, Go, Bash, CI/CD, Red Teaming, Penetration Testing, Vulnerability Research, Mobile Security, Purple Teaming, Incident Response
**Posted:** 2026-08-31

> Leads continuous offensive security validation across cloud, mobile, corporate, and hardware environments. Requires 8+ years in offensive security, deep AWS and application-security expertise, advanced scripting ability, and leadership in red teaming and vulnerability research.

## Job Description

## Responsibilities
- Define the long-term technical vision for continuous offensive security validation.
- Design and execute complex, multi-stage red-team operations and adversary simulations across AWS cloud infrastructure, iOS and Android mobile applications, and internal corporate environments.
- Conduct deep-dive vulnerability research into high-risk areas, including zero-day vulnerabilities and sophisticated logic flaws.
- Partner with DevOps and Engineering to build automated security guardrails and self-healing infrastructure.
- Support Detection and Response through purple-team exercises that validate monitoring and alert coverage.
- Mentor senior and mid-level engineers and promote security-minded development across the R&D organization.

## Requirements
- 8+ years of experience in offensive security, red teaming, or penetration testing.
- Proven ability to uncover critical vulnerabilities in complex environments.
- Deep knowledge of AWS security architecture, IAM bypass techniques, Kubernetes container escapes, and serverless security.
- Application security experience, including manual code review in Node.js, Python, or Go and bypass techniques for modern web and mobile security controls.
- Ability to script in Python, Bash, or Go to automate exploitation chains or integrate security testing into CI/CD pipelines.
- Ability to communicate complex technical risks as business impact to executive stakeholders and collaborate effectively with software engineers.
- Curiosity, persistence, and an ethical-hacking mindset.

## Nice-to-haves
- OSCP, OSCE, GXPN, or equivalent advanced offensive-security certification.

## Benefits
- Medical, dental, vision, and HSA match.
- Paid life insurance, AD&D, and disability benefits.
- Traditional 401(k) with company match.
- Unlimited PTO and paid company holidays.
- Professional development stipend and mental health resources.
- One-on-one financial planners.
- Fertility healthcare.
- Fully paid parental and caregiving leave, including cleaning service and meals during leave.
- Flexible work-from-home and in-office opportunities.
- Stocked kitchen, catered lunches, and occasional in-office events.
- Employee resource groups.

## Similar jobs

- [Staff Security Researcher](https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b) - GitLab - Remote - $168k – $238k/yr
- [Staff Identity Governance and Access Engineer](https://hotfix.jobs/jobs/8fe7fe60-ff7a-48f4-a805-f3f100e1814f) - Okta - Bellevue, WA - $161k – $221k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/29576103-a601-455c-a963-ce04128098e5) - Twilio - Remote - $156k – $194k/yr
- [Staff IAM Engineer](https://hotfix.jobs/jobs/7a722d47-b173-4ffc-9981-f10ed9f3ce9c) - Ironclad - San Francisco, CA - $170k – $190k/yr
- [Staff Identity Engineer](https://hotfix.jobs/jobs/9840c62b-d314-4749-aa98-2057f5343be2) - Okta - Bellevue, WA - $161k – $221k/yr

**Apply:** https://hotfix.jobs/jobs/5bbddd1b-817b-4c24-b9a0-7537ae6a2393
**Canonical:** https://hotfix.jobs/jobs/5bbddd1b-817b-4c24-b9a0-7537ae6a2393