TL;DR
Internship - Offensive Security Engineer: Executing challenging security projects for PS and MSP customers with an accent on technical precision and complex client needs. Focus on developing custom methodologies, payloads, exploits, and tools, continuously improving the bridge between services and product.
Location: Remote, United States
Company
hirify.global is an expert-driven offensive security company with a mission to prevent breaches before they occur.
What you will do
- Execute challenging security projects for customers, ensuring technical precision and resolving complex client needs.
- Develop custom methodologies, payloads, exploits, and tools when off-the-shelf solutions aren't enough.
- Identify vulnerability trends and translate them into improvements.
- Proactively develop new capabilities based on security vulnerabilities identified during projects.
- Learn as much as possible about the industry and offensive security landscape.
Requirements
- A Bachelor’s degree in Computer Science, Engineering, Mathematics, or Physics.
- 0–2 years of experience or relevant internships in cybersecurity, startups, or high-tech environments.
- Experience writing software or scripts using common offensive security languages, specifically Go (Golang), Python, PowerShell, or Bash.
- Early experience or a demonstrated passion for Product Security (App/Mobile/LLM), Cloud Security (AWS/Azure/GCP), Web/Network Penetration Testing, Red Teaming, or IoT/Embedded Security.
- Achievements in CTFs (CCDC, CPTC) or on testing platforms like Hack The Box, TryHackMe, or PortSwigger.
- Hold or are actively pursuing industry-recognized certifications such as OSCP, OSEP, PNPT, BSCP, OSWE, or relevant cloud certifications.
Nice to have
- Verifiable contributions to vulnerability research (CVEs), exploit development, or open-source offsec projects.
- Familiarity with AI prompt engineering for tool/payload generation.
Culture & Benefits
- Work alongside the top 1% of the industry composed of high performers.
- Defined by action, grit, and uncompromising transparency.
- Work protects the world's most critical organizations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →