# Senior Security Engineer, Offensive Security

**Company:** [Docker](https://hotfix.jobs/companies/docker)
**Location:** Remote
**Role:** Security Engineering
**Salary:** €119k – €170k/yr
**Experience:** 5+ years
**Skills:** Penetration Testing, Red Teaming, Threat Modeling, Exploit Development, Python, Go, OAuth, Cryptography, Zero Trust, AWS, GCP, Azure, Burp Suite, Owasp, Kubernetes
**Posted:** 2026-09-09

> Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

## Job Description

## Responsibilities
- Execute penetration tests and red-team/adversary-emulation engagements against products, services, applications, APIs, cloud infrastructure, and containerized environments.
- Develop proof-of-concept exploits, risk-rated findings, remediation guidance, security tests, and automation; retest fixes.
- Perform security reviews and threat modeling across design, architecture, code, AI/ML products, and infrastructure.
- Build and maintain offensive security tooling and automation for vulnerability discovery, reconnaissance, and penetration testing.
- Partner with engineering, product, and leadership to implement security architecture, controls, and durable remediations.
- Support security programs including automated design reviews, vulnerability management, incident response, security monitoring, and anomaly detection.
- Participate in an on-call rotation, investigate threats, coordinate remediation, and improve incident response capabilities.
- Promote security practices and security-by-design through cross-functional collaboration.
- Support audits and compliance efforts, including SOC 2 and ISO 27xxx.

## Requirements
- 3+ years of security engineering experience, including hands-on offensive security and penetration testing across applications and infrastructure.
- 2+ years of hands-on development experience in Python or Golang.
- Expertise in authentication, authorization, OAuth, cryptography, and Zero Trust principles.
- Hands-on experience securing AWS, Google Cloud, and Azure environments.
- Penetration testing experience with SaaS web applications and APIs, including manual exploitation beyond automated scanners.
- Proficiency with offensive security tooling and techniques, including Burp Suite and OWASP frameworks.
- Ability to write security tests and develop exploits and proof-of-concept attacks.
- Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
- Experience using LLMs and agentic tooling to automate vulnerability discovery, reconnaissance, and penetration testing.
- Experience building security programs and automations from scratch using risk-based prioritization.
- Experience performing security reviews and improving security-review automation.
- Strong communication and cross-functional collaboration skills.
- Familiarity with industry standards and emerging security technologies and models.
- Offensive security certification such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.

## Nice-to-haves
- Published CVEs, original security research, or conference talks.
- Experience with container escape, Kubernetes attack paths, or cloud red teaming.
- Experience testing AI/ML systems for prompt injection, model extraction, and data poisoning.

## Compensation
- EU compensation: €118,860–€169,800 plus equity.
- Technology stipend equivalent to US$100 net per month.
- Annual learning and development stipend.
- Paid parental leave and paid time off.

## Similar jobs

- [Senior Security Engineer](https://hotfix.jobs/jobs/1a2fd041-7d0b-4c40-84e6-55032dca268f) - Mixpanel - London, United Kingdom - $103k – $140k/yr
- [Senior Manager, Product Security Engineering](https://hotfix.jobs/jobs/8fa92a96-1812-406c-8ae5-324c42e42eea) - GitLab - Remote - $168k – $245k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Security Engineer, Detection and Response](https://hotfix.jobs/jobs/02ff0cde-e8e1-4f38-9c48-d8149d22a95b) - Writer - London, United Kingdom

**Apply:** https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96
**Canonical:** https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96