Назад
Company hidden
6 дней назад

Security Engineer, Level 5, Offensive Security

178 000 - 313 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer, Level 5, Offensive Security (Cloud/Mobile Security): Design and lead offensive security and privacy engagements across corporate environments, cloud infrastructure, internal applications, and mobile clients with an accent on red, purple, and orange team exercises, threat intelligence, and adversary emulation. Focus on developing custom implants, payloads, and exploits, establishing threat killchains, assessing detection coverage, and driving risk mitigation through detailed security reporting.

Location: Los Angeles or Palo Alto, United States; expected to work in an office 4+ days per week

Base salary: $178,000–$313,000 annually, depending on pay zone, plus equity in RSUs.

Company

hirify.global is a technology company operating hirify.globalchat, Specs, Bitmoji, Saturn, and other digital services.

What you will do

  • Design, execute, and lead red, purple, and orange team exercises across corporate environments, cloud accounts, internal applications, and mobile client applications.
  • Analyze real-world threat actors, tools, tactics, procedures, and killchains with the threat intelligence team.
  • Produce post-engagement reports covering vulnerabilities, security strengths and weaknesses, detection coverage, and prioritized mitigation strategies.
  • Build and manage offensive security infrastructure, including custom implants, payloads, and exploits for adversary emulation.
  • Collaborate with security, privacy, development, IT, and executive teams on security reviews, strategic roadmaps, vulnerability reproduction, and incident response.
  • Research emerging topics relevant to the technology stack and apply findings to future exercises.

Requirements

  • 6+ years of post-Bachelor’s security experience, or equivalent experience with an advanced technical degree.
  • Bachelor’s degree in computer science, engineering, information systems, or a related field, or equivalent technical experience.
  • Experience leading offensive security engagements and coordinating multiple security engineers.
  • Expertise in at least four areas including operating system internals, networking, application or mobile development, Kubernetes, AWS or GCP, and payload, implant, or exploit development.
  • Programming proficiency in Java, Python, Go, or another modern language, plus Bash or PowerShell scripting.
  • Ability to threat-model systems, establish killchains, and work in complex technical environments.

Nice to have

  • Experience with the ATT&CK framework.
  • Experience with incident response, digital forensics, detection engineering, and threat hunting.
  • Personal security research, CVEs, bug bounty reports, CTF participation, or security tooling repositories.

Culture & Benefits

  • Default-together work model with in-person collaboration expected 4+ days per week.
  • Paid parental leave and comprehensive medical coverage.
  • Emotional and mental health support programs.
  • Compensation packages that include long-term equity participation through RSUs.
  • Equal opportunity workplace focused on diverse backgrounds and perspectives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →