Senior Security Engineer, Offensive Security
Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
About the job
Responsibilities
- Execute penetration tests and red-team/adversary-emulation engagements against products, services, applications, APIs, cloud infrastructure, and containerized environments.
- Develop proof-of-concept exploits, risk-rated findings, remediation guidance, security tests, and automation; retest fixes.
- Perform security reviews and threat modeling across design, architecture, code, AI/ML products, and infrastructure.
- Build and maintain offensive security tooling and automation for vulnerability discovery, reconnaissance, and penetration testing.
- Partner with engineering, product, and leadership to implement security architecture, controls, and durable remediations.
- Support security programs including automated design reviews, vulnerability management, incident response, security monitoring, and anomaly detection.
- Participate in an on-call rotation, investigate threats, coordinate remediation, and improve incident response capabilities.
- Promote security practices and security-by-design through cross-functional collaboration.
- Support audits and compliance efforts, including SOC 2 and ISO 27xxx.
Requirements
- 3+ years of security engineering experience, including hands-on offensive security and penetration testing across applications and infrastructure.
- 2+ years of hands-on development experience in Python or Golang.
- Expertise in authentication, authorization, OAuth, cryptography, and Zero Trust principles.
- Hands-on experience securing AWS, Google Cloud, and Azure environments.
- Penetration testing experience with SaaS web applications and APIs, including manual exploitation beyond automated scanners.
- Proficiency with offensive security tooling and techniques, including Burp Suite and OWASP frameworks.
- Ability to write security tests and develop exploits and proof-of-concept attacks.
- Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
- Experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and penetration testing.
- Experience building security programs and automations from scratch using risk-based prioritization.
- Experience performing security reviews and improving security-review automation.
- Strong communication and cross-functional collaboration skills.
- Familiarity with industry standards and emerging security technologies and models.
- Offensive security certification such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
Nice-to-haves
- Published CVEs, original security research, or conference talks.
- Experience with container escape, Kubernetes attack paths, or cloud red teaming.
- Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning.
Compensation
- EU compensation: €118,860–€169,800 plus equity.
- Technology stipend equivalent to US$100 net per month.
- Annual learning and development stipend.
- Paid parental leave and paid time off.
Skills
Penetration Testing, Red Teaming, Threat Modeling, Exploit Development, Python, Go, OAuth, Cryptography, Zero Trust, AWS, GCP, Azure, Burp Suite, Owasp, Kubernetes
Similar jobs
Security Engineering jobsThe Senior Security Engineer will build and operate detection and response capabilities across Mixpanel’s product, cloud, corporate, and identity environments. The role requires deep detection-as-code expertise, Google Cloud and Python proficiency, and the ability to lead EMEA incident response.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.