
Offensive Security Engineer
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in United States.
• Execute in-depth penetration tests on web applications, APIs, cloud environments, mobile apps, and internal infrastructures.
• Strategize and carry out red team engagements that mimic cyber and criminal threat actors focusing on financial services.
• Conduct assumed-breach and objective-focused assessments to evaluate detection and response capabilities.
• Collaborate with detection engineering, threat intelligence, and incident response teams to validate security controls and enhance detection accuracy.
• Contribute insights from adversary tradecraft to detection rules, threat hunting strategies, and incident response playbooks.
• Assist in incident investigations utilizing offensive expertise, log examination, and root cause analysis.
• Create, develop, and uphold custom offensive tools, scripts, and automation frameworks.
• Establish internal platforms and workflows for efficient and repeatable offensive operations.
• Automate testing procedures, payload creation, and reporting workflows.
• Generate reports detailing technical findings, business risks, and remediation strategies.
• Serve as a subject-matter expert and primary contact for offensive security projects.
• Oversee projects from inception to completion, mentor junior team members, and promote continuous learning.
• Keep abreast of emerging threats, vulnerabilities, and attack methods; share research with internal teams and the broader security community.
• A minimum of 5 years of experience in offensive security, penetration testing, red teaming, or a related discipline.
• Proficient programming skills in Python, Go, or comparable languages, with proven experience in developing tools, automations, or custom exploits.
• Extensive knowledge of web application security, including the OWASP Top 10, ASVS, and prevalent vulnerability types.
• Practical experience with AWS, Azure, or GCP, covering cloud-native attack strategies and configuration issues.
• Expertise in offensive tools such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
• Familiarity with the MITRE ATT&CK framework and adversary tactics, techniques, and procedures for gaining initial access, privilege escalation, lateral movement, and data exfiltration.
• Exceptional written and verbal communication skills, capable of conveying complex technical findings in straightforward, risk-focused recommendations.
• Ability to adopt an adversary's mindset — innovative, tenacious, and adept at assessing risk in multifaceted environments.
• Stake in the growth of Stripe through equity participation.
• 401(k) plan with matching contributions available from the first day of employment.
• Comprehensive healthcare coverage, including medical, dental, and vision plans.
• Wellness stipends to promote employee health.
• Annual budget allocated for training, certifications, and attending conferences.
• Option for remote work from home within the United States.
• Opportunities for office visits for team meetings, on-site tasks, and events.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.