Назад
Company hidden
4 дня назад

Senior Security Engineer, Offensive Security

118 860 - 169 800
Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France/UK/US +4 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, Offensive Security (Cloud, Containers, and AI/ML): Conducting adversarial testing, penetration tests, threat modeling, and exploit development across Docker products, cloud infrastructure, containerized environments, and AI/ML systems with an accent on vulnerability discovery, security architecture, and automated testing. Focus on building offensive security tooling, validating remediation, strengthening Zero Trust controls, and responding to security incidents through on-call participation.

Location: Remote in England, Germany, Italy, Portugal, or Spain

Salary: €118,860–€169,800 per year plus equity

Company

hirify.global builds developer tools and infrastructure products including hirify.global Desktop, hirify.global Hub, and hirify.global Scout, used by millions of developers worldwide.

What you will do

  • Plan and execute penetration tests, red-team exercises, and adversary-emulation engagements across hirify.global products, services, and cloud infrastructure.
  • Develop proof-of-concept exploits, security tests, offensive tooling, and automation to expand testing coverage.
  • Perform architecture, design, code, and threat-modeling reviews, including reviews of emerging AI products.
  • Partner with engineering and product teams to design security controls, remediate vulnerabilities, and promote security by design.
  • Participate in on-call rotations, incident response, threat investigations, and post-incident activities.
  • Support the security roadmap, monitoring and anomaly detection, audits, and compliance initiatives.

Requirements

  • 3+ years of security engineering experience, including hands-on offensive security and penetration testing across applications and infrastructure.
  • 2+ years of development experience with Python or Golang.
  • Deep knowledge of authentication, authorization, OAuth, applied cryptography, and Zero Trust principles.
  • Hands-on experience securing AWS, GCP, or Azure and testing SaaS web applications and APIs beyond automated scanners.
  • Experience with Burp Suite, OWASP frameworks, exploit development, security testing, and risk-based security automation.
  • Understanding of AI/ML security risks, including prompt injection, data poisoning, model extraction, and adversarial attacks, plus practical use of LLMs and agentic tooling for security workflows.

Nice to have

  • Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO.
  • Published CVEs, original security research, or conference talks.
  • Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing.

Culture & Benefits

  • Remote-first work from home, with offices in Seattle and Paris for connection and collaboration.
  • Flexible scheduling, generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.
  • Home office support and a technology stipend of US$100 net per month.
  • Annual learning and development stipend for conferences, courses, certifications, and continued education.
  • Paid parental leave, equity for full-time employees, and country-specific medical, retirement, and paid-holiday benefits.

Hiring process

  • Meet with the security team and engineering partners, review internal systems and documentation, and complete security awareness and compliance onboarding.
  • Review application architecture, technology stacks, data flows, risk registers, and roadmaps; shadow an engineer during on-call and security operations rotations.
  • Interview recordings may be used only with the candidate’s explicit consent, and AI-assisted tools may be used during recruiting.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →