6 часов назад
Staff Attack Engineer (Cybersecurity)
247 000 - 275 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Attack Engineer (Cybersecurity) (Python/Active Directory): Building safe, reliable, autonomous internal-network and Active Directory attack capabilities for the NodeZero pentesting platform with an accent on modern AD tradecraft, hardened enterprise environments, and production-grade Python. Focus on modeling identity and privilege-escalation paths, validating attack scenarios in representative environments, and leading research and engineering for enterprise-scale offensive security.
Location: Remote within the US; up to 10% travel may be required.
Base salary: $247,000–$275,000 per year, plus equity in the form of stock options.
Company
is a remote cybersecurity product company developing NodeZero, an autonomous penetration-testing platform for identifying and safely validating exploitable attack paths.
What you will do
- Lead the technical direction and serve as the subject matter expert for internal-network and Active Directory attack capabilities in NodeZero.
- Research emerging Active Directory and internal-network techniques, including AD Certificate Services, SCCM, Kerberos delegation, NTLM coercion and relay, shadow credentials, ACL and GPO abuse, and hybrid identity pivots.
- Design, build, and maintain production-grade Python for safe, repeatable attacks at enterprise scale.
- Configure and exploit representative Active Directory environments to validate and regression-test attack scenarios.
- Extend attack-path modeling and graph data models for identity, privilege escalation, and lateral movement.
- Set the research roadmap, mentor engineers, collaborate with product and customer-facing teams, and document technical findings.
Requirements
- Deep hands-on offensive security experience against Active Directory and internal enterprise networks, from initial foothold through domain or enterprise compromise.
- Expert-level Python and experience shipping and maintaining production-quality software rather than only scripts or proofs of concept.
- Experience attacking modern hardened environments, including NTLM deprecation, enforced SMB signing, Kerberos-only configurations, and tiered administration.
- 8+ years of combined offensive security and/or software engineering experience, with significant focus on Active Directory and internal-network attacks.
- Technical leadership experience setting direction, driving complex and high-risk work, mentoring engineers, and producing clear technical documentation.
- OSCP, OSEP, CRTO, or an equivalent offensive security certification.
Nice to have
- Experience with SCCM, Windows Admin Center, Entra ID, Entra Connect, primary refresh tokens, seamless SSO, and on-premises-to-cloud pivots.
- Contributions to offensive tooling such as BloodHound, Impacket, or netexec.
- Familiarity with Neo4j, attack-path analysis, multi-tenant SaaS, and production-safe autonomous offensive tooling.
- Public contributions such as open-source tools, technical blog posts, conference talks, or published CVEs.
Culture & Benefits
- Fully remote work model with a collaborative culture focused on respect, ownership, and results.
- Health, vision, and dental insurance for employees and families.
- Flexible vacation policy and generous parental leave.
- Equity package for all full-time roles.
- Career development opportunities in a growing cybersecurity company.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Twilio
6 дней назад
Staff Engineer - Offensive Security (AI)
155 520 - 228 700$
6 часов назад
Lead Cybersecurity Engineer (AI)
230 000 - 280 000$
20 часов назад
Security Engineer (Cloud Security)
155 000 - 190 000$
4 дня назад
Senior Application Security Engineer (AI)
169 000 - 220 000$
17 часов назад
Global Security Engineer Offensive Operations (Cybersecurity)
17 часов назад
Principal Active Defense Engineer (Cybersecurity)
167 200 - 300 000$