Назад
Company hidden
3 дня назад

Offensive Security Engineer (Cloud Security)

145 000 - 200 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Security Engineer (Cloud Security): Testing Palantir’s applications, networks, cloud environments, and containerized infrastructure with an accent on realistic attack paths, exploitation, and remediation. Focus on building agentic LLM-driven offensive security tooling, chaining identity and cloud attack paths, validating detection coverage, and automating penetration testing.

Location: New York, NY; hybrid workplace

Salary: $145,000–$200,000/year, plus potential restricted stock units, sign-on bonus, and other incentives.

Company

hirify.global develops software for data-driven decisions and operations used by organizations in areas such as healthcare, supply chains, and public safety.

What you will do

  • Conduct hybrid web application penetration tests combining source code review and runtime exploitation.
  • Perform external and internal network, Active Directory, cloud, container, and orchestration security assessments.
  • Chain findings into realistic attack paths, validate detection coverage, and collaborate with detection engineering.
  • Scope and manage third-party penetration testing engagements and turn findings into prioritized remediation.
  • Design offensive security tooling and automation, including agentic LLM-driven systems, tailored to the technology stack.
  • Write actionable technical and non-technical reports and partner with engineering to reproduce and verify fixes.

Requirements

  • Must work in a hybrid arrangement from the New York, NY office.
  • 4+ years of professional experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong experience in web application, external network, internal network, Active Directory, cloud, and containerized environment assessments.
  • Proficiency in at least one scripting or programming language, such as Python or Go, for building testing tools.
  • Knowledge of CI/CD, infrastructure-as-code, cloud security, container security, identity attack paths, and common enterprise misconfigurations.
  • Clear written and verbal communication, strong organization, and the ability to track remediation through verified completion.

Nice to have

  • Eligibility and willingness to obtain a U.S. security clearance.
  • Offensive security certifications such as OSCP or OSWE.
  • Experience in CTF competitions or bug bounty programs.

Culture & Benefits

  • Hybrid work options are commonly available, with office attendance encouraged for collaboration and innovation.
  • Medical, dental, vision, life, AD&D, and disability insurance.
  • Paid time off, paid holidays, supportive leave programs, and paid parental leave.
  • Commuter benefits, family-building benefits, backup care, and new-child expense support.
  • 401(k) plan and relocation assistance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →