Назад
Company hidden
3 часа назад

Senior Principal Engineer, Offensive Security

190 000 - 240 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Principal Engineer, Offensive Security (AI Infrastructure): Defining and executing offensive security programs across silicon, firmware, software, cloud, and enterprise IT with an accent on red teaming, penetration testing, and vulnerability research. Focus on developing exploits, modeling threats with MITRE ATT&CK, automating continuous security validation, and driving remediation with engineering teams.

Location: San Jose, California, United States

Salary: $190,000–$240,000 per year, depending on experience, level, and business need. The role may also be eligible for discretionary bonuses, incentives, and benefits.

Company

hirify.global develops semiconductor-based connectivity solutions and software for rack-scale AI infrastructure, integrating technologies such as CXL, Ethernet, NVLink, PCIe, and UALink.

What you will do

  • Define and lead offensive security strategy across hardware, firmware, software, cloud, and enterprise IT.
  • Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets.
  • Conduct vulnerability research and exploit development across hardware, firmware, embedded systems, cloud, and SaaS environments.
  • Drive threat modeling, attack surface analysis, and adversary simulation aligned with real-world threat actors and MITRE ATT&CK.
  • Build tooling and automation for scalable offensive testing and continuous validation of security controls.
  • Partner with product security, engineering, IT, and GRC teams to prioritize findings, validate fixes, and provide architecture guidance.

Requirements

  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field.
  • 12+ years of experience in offensive security, including red teaming, penetration testing, or vulnerability research.
  • Expertise in at least two areas including hardware or firmware security, embedded systems, Azure or SaaS security, network or application penetration testing, and Active Directory or Microsoft enterprise environments.
  • Proficiency with offensive tooling and exploit development using Python, C/C++, and assembly.
  • Deep understanding of attacker tradecraft, TTPs, and frameworks such as MITRE ATT&CK.
  • Demonstrated success driving remediation and measurable security improvements with engineering teams.

Nice to have

  • Advanced degree in a security-related discipline.
  • Certifications such as OSCP, OSEP, OSED, GXPN, or GPEN, or equivalent experience.
  • Experience in semiconductor, hardware, or hyperscale infrastructure, including PCIe, CXL, or high-speed connectivity technologies.
  • Published research, CVEs, conference talks, or notable open-source contributions.
  • Familiarity with secure development lifecycle, threat modeling, and product security programs.

Culture & Benefits

  • Work on connectivity infrastructure used for large-scale AI clusters.
  • Collaborate across product security, engineering, IT, GRC, customers, and ecosystem partners.
  • Mentor security engineers and help build offensive security capabilities across the organization.
  • Potential eligibility for discretionary bonus, incentives, and benefits.
  • Inclusive environment encouraging applications from people with diverse backgrounds and experiences.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →