TL;DR
Staff Offensive Security Engineer (Fintech): Identifying and validating security risks across hirify.global's products, infrastructure, and corporate environment with an accent on red teaming, adversarial simulation, and hands-on security testing. Focus on designing and executing offensive security engagements that challenge assumptions and improve detection and response capabilities.
Location: The role is located in the office location(s) listed on this job description which will align with our in-office working environment.
Salary: $191,250 - $225,000 CAD
Company
hirify.global's mission is to democratize finance for all.
What you will do
- Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
- Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.
- Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.
- Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.
- Write and maintain tooling to automate and scale offensive security assessments.
- Serve as a subject matter expert by documenting findings, recommending remediation strategies, and supporting teams through fixes.
Requirements
- 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
- Demonstrated experience mentoring or guiding other security engineers.
- Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.
- Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.
- Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monitoring, including common evasion techniques.
- Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation.
Nice to have
- Experience working in financial technology or regulated environments.
- Prior experience serving as a technical lead on security initiatives.
Culture & Benefits
- Committed to providing an inclusive and welcoming interview experience for all candidates.
- AI tools enhance the efficiency and consistency of our hiring process; however, all hiring decisions are made by our hiring teams.
- Eligible for bonus opportunities + equity + benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →