Назад
1 день назад

Senior Offensive Security Engineer

196 750 - 243 290$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Offensive Security Engineer (Offensive Security/Python/Go): Conducting full-stack security assessments and building repeatable breach attack simulation and security testing frameworks with an accent on purple team exercises, detection engineering, and security metrics. Focus on validating detection coverage, automating offensive security testing, and measuring the effectiveness of security controls across web applications, APIs, cloud infrastructure, and backend systems.

Location: San Mateo, California, United States; office-based roles are onsite Tuesday through Thursday, with optional presence on Monday and Friday.

Salary: $196,750–$243,290 USD per year

Company

Roblox builds tools and a platform for creating and experiencing 3D immersive digital experiences.

What you will do

  • Perform full-stack offensive security assessments across web applications, APIs, cloud infrastructure, and backend systems.
  • Partner with detection engineers through purple team exercises, attack simulations, and threat emulation.
  • Develop and maintain security testing tools, breach attack simulation frameworks, and automation scripts.
  • Build metrics frameworks to measure security control effectiveness, detection coverage, and improvement over time.
  • Research evolving attack techniques and contribute to offensive and defensive security improvements.
  • Share security knowledge across teams and collaborate with architecture and engineering partners.

Requirements

  • 4+ years of professional experience in offensive security.
  • Experience with purple team exercises, breach attack simulation, detection engineering collaboration, and security assessments.
  • Proficiency in Python or Go for security tooling and automation, including SOAR platforms and configuration management.
  • Knowledge of OWASP Top 10, MITRE ATT&CK, PTES, BAS methodologies, EDR, SIEM, XDR, exploit development, and post-exploitation.
  • Experience with cloud security across AWS, Azure, or GCP; container security; CI/CD pipeline security; API security; and security metrics.
  • OSCP, OSCE, GXPN, or equivalent practical experience, along with strong technical writing and communication skills.

Nice to have

  • Experience with reverse engineering and deploying or configuring open-source security software.
  • Experience evaluating security tools and making build-versus-buy decisions.

Culture & Benefits

  • Cross-functional collaboration across information security, detection engineering, architecture, and engineering teams.
  • Focus on continuous improvement, measurable security outcomes, and knowledge sharing.
  • Full-time employees are eligible for equity compensation and company benefits.
  • US work authorization related to certain visa categories may not be supported, and future H-1B sponsorship may not be available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →