
Senior Security Engineer, Threat & Offensive Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California, +1 more state.
• Lead and perform security assessments and penetration testing on applications, infrastructure, and networks to uncover exploitable vulnerabilities.
• Oversee and implement security testing tools and frameworks to mimic real-world attacks and evaluate security measures.
• Create and deploy AI-driven workflows to enhance the scalability of security testing and threat-related operations.
• Manage and operationalize threat intelligence to foresee emerging threats and proactively adjust defenses.
• Collaborate with external penetration testing firms for regular independent evaluations.
• Conduct security assessments of new systems, features, architectures, and third-party integrations, offering actionable, risk-based recommendations.
• Work alongside Engineering, IT, Product, and various teams to address vulnerabilities and enhance security measures.
• Develop and enhance playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response.
• Monitor and handle security alerts and incidents, analyze data, and respond to security events.
• Assist with general security assessments, security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and other security-related processes.
• At least 5 years of experience in security engineering, penetration testing, threat intelligence, or a related role with pertinent responsibilities and expertise.
• Bachelor's degree in Computer Science, Information Security, Technology, or a similar discipline.
• Relevant security certifications (e.g., CISSP, CEH, OSCP, GPEN, GCIH, or similar).
• Familiarity with cloud environments.
• Experience with security testing, monitoring, and response technologies (threat intelligence platforms, vulnerability scanners, SIEM, EDR, or similar).
• Practical experience with security testing tools and frameworks such as Burp Suite, Metasploit, Nmap, Cobalt Strike, or similar.
• Proven track record of utilizing AI and automation to enhance threat detection, testing, and response operations.
• Proficient in both manual and automated testing methodologies.
• Strong grasp of common attack strategies, exploitation techniques, and MITRE ATT&CK or related frameworks.
• Experience with SIEM, EDR, and other detection/monitoring platforms.
• Familiarity with cloud security and environments, including GCP and AWS.
• Practical knowledge of OWASP, NIST, MITRE ATT&CK, CIS, and SOC 2/ISO 27001 principles.
• Capable of working independently, leading projects, and managing complex, ambiguous security inquiries.
• Exceptional communication and collaboration abilities, including the skill to convey technical findings and risks to both technical and non-technical audiences.
• Experience or exposure to startup environments is a plus.
• Competitive salary with a significant stake in the company through equity.
• 401k plan.
• Comprehensive medical, dental, and vision benefits.
• Pre-tax commuter benefits for public transportation, rideshare services, and parking expenses.
• Company-wide orientation and access to learning & development opportunities.
• Regular review cycles that include 360-degree feedback.
• Quarterly budgets for team and company outings.
• Flexible paid time off.
• Sick days.
• 11 company holidays.
• 12 weeks of fully paid baby bonding time for both birthing and non-birthing parents.
CDW
CDW
Empower
Gormat
Get handpicked remote jobs straight to your inbox weekly.