Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Offensive Security Engineer (Offensive Security/Python/Go): Conducting full-stack security assessments and building repeatable breach attack simulation and security testing frameworks with an accent on purple team exercises, detection engineering, and security metrics. Focus on validating detection coverage, automating offensive security testing, and measuring the effectiveness of security controls across web applications, APIs, cloud infrastructure, and backend systems.
Location: San Mateo, California, United States; office-based roles are onsite Tuesday through Thursday, with optional presence on Monday and Friday.
Salary: $196,750–$243,290 USD per year
Company
Roblox builds tools and a platform for creating and experiencing 3D immersive digital experiences.
What you will do
- Perform full-stack offensive security assessments across web applications, APIs, cloud infrastructure, and backend systems.
- Partner with detection engineers through purple team exercises, attack simulations, and threat emulation.
- Develop and maintain security testing tools, breach attack simulation frameworks, and automation scripts.
- Build metrics frameworks to measure security control effectiveness, detection coverage, and improvement over time.
- Research evolving attack techniques and contribute to offensive and defensive security improvements.
- Share security knowledge across teams and collaborate with architecture and engineering partners.
Requirements
- 4+ years of professional experience in offensive security.
- Experience with purple team exercises, breach attack simulation, detection engineering collaboration, and security assessments.
- Proficiency in Python or Go for security tooling and automation, including SOAR platforms and configuration management.
- Knowledge of OWASP Top 10, MITRE ATT&CK, PTES, BAS methodologies, EDR, SIEM, XDR, exploit development, and post-exploitation.
- Experience with cloud security across AWS, Azure, or GCP; container security; CI/CD pipeline security; API security; and security metrics.
- OSCP, OSCE, GXPN, or equivalent practical experience, along with strong technical writing and communication skills.
Nice to have
- Experience with reverse engineering and deploying or configuring open-source security software.
- Experience evaluating security tools and making build-versus-buy decisions.
Culture & Benefits
- Cross-functional collaboration across information security, detection engineering, architecture, and engineering teams.
- Focus on continuous improvement, measurable security outcomes, and knowledge sharing.
- Full-time employees are eligible for equity compensation and company benefits.
- US work authorization related to certain visa categories may not be supported, and future H-1B sponsorship may not be available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Senior Security Engineer, Red Team (Cybersecurity)
159 800 - 235 000$
5 дней назад
Manager, Security Posture Validation (Cybersecurity)
208 800 - 438 000$
5 дней назад
Red Team Manager (AI Security)
170 000 - 230 000$
6 дней назад
Offensive Security Manager (Red Team)
170 000 - 230 000$
1 день назад
Staff Security Researcher (AI)
225 000 - 300 000$
4 дня назад