Назад
Company hidden
24 дня назад

Staff Security Engineer (Penetration Tester)

152 000 - 261 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (Penetration Tester) (Red Team/Web/Mobile/API Security): Performing penetration testing and threat actor simulation campaigns for web, mobile, API, and network environments with an accent on vulnerability exploitation, security control bypasses, and remediation guidance. Focus on developing offensive security scripts and tools, testing Linux and network security, and executing red team campaigns.

Location: Seattle, USA; role based in the Seattle office

Salary: $152,000–$261,000 per year base pay, plus a potential annual bonus of 0–20%.

Company

hirify.global is a large global public e-commerce company building shopping, food, and lifestyle services, combining startup culture with substantial organizational resources.

What you will do

  • Perform penetration testing across web, mobile, API, and network environments.
  • Identify security weaknesses and test methods for bypassing technical security controls.
  • Provide remediation guidance and improvements for vulnerabilities discovered during engagements.
  • Conduct threat actor simulation activities and red team campaigns.
  • Develop scripts and tools to support offensive security testing.

Requirements

  • 5+ years of technical experience in offensive security.
  • Proficiency in web, mobile, and API security testing.
  • Experience with penetration testing tools such as Burp Suite, Metasploit, Kali Linux, and Nmap.
  • Strong understanding of operating system security, Linux, networking, and TCP/IP.
  • Proficiency with command-line tools and at least one programming language, such as Python or Java.
  • Fluent Korean and English are preferred.

Nice to have

  • Experience in e-commerce.
  • Cloud experience, including AWS, and understanding of cloud versus traditional data-center environments.
  • Knowledge of the Cyber Kill Chain and MITRE ATT&CK framework.
  • Computer Science, Computer Engineering, or a related technical degree.
  • Recognized offensive security certifications such as OSCP, OSCE, OSED, CREST, or SANS.

Culture & Benefits

  • Medical, dental, vision, life, AD&D, disability, FSA, and HSA benefits.
  • 401(k) plan with company match.
  • 18–21 paid time-off days annually, based on tenure, plus 12 public holidays.
  • Six weeks of paid parental leave and pre-tax commuter benefits.
  • Employee assistance program and free electric car charging.

Hiring process

  • Application review.
  • Phone interview.
  • Onsite or virtual onsite interview, followed by an offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →