TL;DR
Senior Offensive Security Engineer: Leading penetration testing and adversarial simulation efforts for applications, cloud infrastructure, and corporate networks with an accent on identifying weaknesses across the software and IT stack. Focus on offensive testing of application and enterprise systems and guiding remediation.
Location: San Francisco, USA. U.S. Citizenship, Lawful Permanent Residency, or Refugee/Asylee Status Required.
Salary: $160,000 - $240,000 USD
Company
hirify.global builds and operates advanced satellites for secure networks globally, having raised over $750 million.
What you will do
- Perform penetration tests of web apps, APIs, backend services, cloud infrastructure, and corporate networks.
- Conduct threat emulation exercises, red-team scenarios, and targeted attack simulations.
- Assess CI/CD pipelines, IAM configurations, and internal services for exploitable weaknesses.
- Track emerging threats, techniques, and vulnerabilities relevant to cloud and enterprise environments.
- Develop custom exploits or proof-of-concepts as needed to validate findings.
- Work with development, infra, and IT teams to validate controls and guide effective remediation.
Requirements
- 5+ years of hands-on offensive security experience (AppSec, cloud, or enterprise penetration testing).
- Demonstrated experience leading complex penetration tests for web apps, APIs, and cloud platforms, with proficiency in offensive tooling (Burp Suite, Nmap, Metasploit, proxy tools) and manual testing.
- Familiarity with cloud-native attack vectors (AWS/Azure/GCP) and proficiency in Python, Go, or JavaScript.
- Strong analytical and problem-solving skills with an attacker’s mindset.
- U.S. Citizenship, Lawful Permanent Residency, or Refugee/Asylee Status Required.
Culture & Benefits
- Compensation package includes equity and robust benefits.
- Company-subsidized healthcare, disability, and life insurance benefits.
- Flexible PTO and 401(K) retirement.
- Free on-site catered meals.
- Commitment to a diverse and inclusive workplace.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →