Senior Security Engineer, Threat & Offensive Security
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
About the job
Responsibilities
- Conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
- Manage and implement security testing tools and frameworks that simulate real-world attacks and validate security controls.
- Design and implement AI-enabled workflows to scale security testing and threat operations.
- Manage and operationalize threat intelligence to anticipate emerging threats and adjust defenses proactively.
- Partner with external penetration-testing firms on periodic independent reviews.
- Perform security reviews of systems, features, architectures, and third-party integrations, providing risk-based recommendations.
- Collaborate with Engineering, IT, Product, and other teams to remediate vulnerabilities and strengthen controls.
- Develop playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response.
- Monitor and manage security alerts and incidents, analyze data, and respond to security events.
- Support security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and related operational processes.
Requirements
- At least 5 years of experience in security engineering, penetration testing, threat intelligence, or related roles.
- Bachelor's degree in Computer Science, Information Security, Technology, or a related field.
- Hands-on experience with security testing tools and frameworks such as Burp Suite, Metasploit, Nmap, or Cobalt Strike.
- Experience with AI and automation for threat detection, security testing, and response operations.
- Proficiency in manual and automated testing techniques.
- Strong understanding of attack techniques, exploitation methods, and MITRE ATT&CK.
- Experience with SIEM, EDR, and other detection and monitoring platforms.
- Experience with cloud security and cloud environments, including GCP and AWS.
- Knowledge of threat intelligence platforms, vulnerability scanners, security monitoring, and response technologies.
- Applied knowledge of OWASP, NIST, MITRE ATT&CK, CIS, SOC 2, and ISO 27001 concepts.
- Ability to work autonomously, lead projects, investigate complex security issues, and collaborate with technical and non-technical stakeholders.
- Relevant certifications such as CISSP, CEH, OSCP, GPEN, or GCIH are preferred.
- Startup experience is a plus.
Compensation and Benefits
- Base salary: $180,000–$230,000.
- Equity and 401(k) plan.
- Medical, dental, and vision benefits.
- Commuter benefits.
- Flexible paid time off, sick days, and 11 company holidays.
- Fully paid 12-week baby bonding leave for birthing and non-birthing parents.
Skills
Penetration Testing, Burp Suite, Metasploit, Nmap, Cobalt Strike, Threat Intelligence, Incident Response, Mitre Att&Ck, SIEM, Edr, GCP, AWS, Owasp, Nist, Cis
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.
Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.