Conduct advanced vulnerability research, reverse engineering, threat analysis, and exploit development across application, mobile, operating-system, and cloud platforms. The role requires at least five years of offensive-security experience or a strong published research track record.
120k – 150k/yr
Remote5+ YOESecurity Engineering
About the role
Responsibilities
Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern web and API platforms, mobile operating systems, low-level operating system stacks, cloud infrastructures, and critical enterprise software.
Identify high-impact vulnerabilities and novel attack surfaces; develop proof-of-concept exploits to demonstrate real-world risk.
Research emerging threat vectors and maintain testing guidelines across cloud environments, APIs, mobile platforms, and AI/ML technologies.
Collaborate with Product and Engineering teams to build scalable security assessment capabilities, automated testing workflows, and platform intelligence.
Translate complex security research into actionable customer value and platform improvements.
Provide technical guidance, benchmarking, mentorship, and quality assurance for complex research initiatives.
Represent the company through technical blog posts, advisories, whitepapers, and conference presentations.
Requirements
5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering; alternatively, 3+ years with a proven record of published research, CVE disclosures, or open-source security tooling.
Expertise in modern application stacks, including Node.js, Go, Python, Java, and Rust.
Knowledge of Linux, Windows, and macOS security internals.
Experience with containerized cloud environments, including Docker, Kubernetes, AWS, and GCP.
Ability to analyze binary, source code, or bytecode and construct reliable proof-of-concept exploits for complex vulnerability classes.
Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities.
Ability to communicate complex technical findings and remediation guidance to engineers, product teams, and executives.
Must reside in the United States; EST or CST time-zone alignment is preferred.
Nice to Have
Familiarity with AI/ML security concepts, LLM risk models, and novel software integrations.
Experience with Ghidra, IDA Pro, Binary Ninja, GDB, or LLDB.
Published CVEs, security advisories, or bug-bounty recognition.
Certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist.
Contributions to open-source security tools or research projects.
Compensation and Benefits
OTE salary range of $120,000–$150,000 per year, plus equity and benefits.
401(k) program in the US.
Medical, dental, vision, and life insurance in the US.
Wellness, work-from-home equipment and Wi-Fi, and learning and development stipends.
Senior Security Engineer building security architectures and controls from the ground up for Northwood's global phased array ground station network enabling real-time satellite communications. Requires 5+ years IaC experience, deep knowledge of FedRAMP/NIST 800-171, ability to obtain TS/SCI clearance, and ownership of incident response, compliance automation, and government liaison duties.
120k – 190k/yrOn-site5+ YOESecurity Engineering
Senior Detection and Response Engineer
Northwood SpaceLos Angeles, CA
Senior Detection and Response Engineer building and operating a SOC for a global satellite ground station network. Lead incident response, threat hunting, detection engineering, and forensics for mission-critical space infrastructure and national security systems.
120k – 190k/yrOn-site5+ YOESecurity Engineering
Senior Security Engineer, Bug Bounty
MozillaUnited States
Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
116k – 183k/yrRemote3+ YOESecurity Engineering
Corporate Security Lead
Northwood SpaceLos Angeles, CA +1
Builds and leads corporate IT security operations including helpdesk, endpoint management, SIEM deployment, and team hiring for a space communications company. Requires 5+ years in IT/security/DevSecOps, hands-on tools like Okta and AWS, and compliance knowledge.
125k – 206k/yrOn-site5+ YOESecurity Engineering
Senior Security Automation Engineer
ClickhouseUnited States
Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.