
Senior/Staff Attack Engineer, Rapid Response
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Conduct research and replicate significant vulnerabilities within enterprise networks, applications, identity systems, cloud environments, and infrastructure.
• Analyze attacker tactics, techniques, procedures, and campaigns encountered in real-world scenarios.
• Transform vulnerability research and observed attacker behavior into safe, repeatable proof-of-exploit capabilities, attack paths, and automated modules for Rapid Response and NodeZero.
• Illustrate realistic impacts, such as privilege escalation, credential access, lateral movement, persistence, and data access, while minimizing unnecessary disruption.
• Verify remediation and containment by securely retesting vulnerabilities and security controls.
• Enhance execution speed, reliability, observability, and quality of evidence.
• Collaborate with research, product, and engineering teams.
• Assist security teams in quickly validating exposure, prioritizing remediation, and ensuring that defenses are functioning effectively.
• Proficient in Python and software engineering, with experience in building, testing, and operating production-quality tools.
• Strong foundation in penetration testing, vulnerability research, and exploit development.
• Practical experience with enterprise networks, applications, identity systems, cloud environments, or endpoint security.
• Proven ability to replicate vulnerabilities and automate manual techniques reliably.
• Knowledge of common attack chains, trust boundaries, authentication and authorization mechanisms, privilege escalation, and lateral movement.
• Capability to balance speed, safety, reliability, coverage, and actionable evidence.
• Strong ownership, judgment, and communication skills in ambiguous or time-sensitive contexts.
• Experience with CISA KEVs, CVE analysis, N-Day research, Zero-Day research, or responsible disclosure is preferred.
• Background in incident response, threat hunting, purple teaming, or security operations is advantageous.
• Familiarity with AWS, Azure, GCP, Kubernetes, Active Directory, Entra ID, Okta, or hybrid environments is preferred.
• Experience in exploit development, reverse engineering, malware analysis, or vulnerability research is a plus.
• Contributions to security research, CVEs, conference presentations, open-source tools, or technical publications are valued.
• Participation in CTFs or equivalent hands-on offensive security practices is a plus.
• Bachelor’s Degree in Computer Science, Computer Engineering, or a related field is preferred.
• OSCP or equivalent certifications are desirable.
• Must be legally authorized to work in the United States.
• Must not require employment visa sponsorship at present or in the future.
• Equity package in the form of stock options for all full-time positions.
• Health insurance for you and your family.
• Vision insurance for you and your family.
• Dental insurance for you and your family.
• Flexible vacation policy.
• Generous parental leave.
• Opportunities for career development.
• An inclusive and collaborative work culture.
• Fully remote work arrangement.
• Up to 10% travel.
Muon Space
Anduril Industries
Siemens Healthineers
Get handpicked remote jobs straight to your inbox weekly.