Offensive Security Engineer
New
S
StripeFinancial Infrastructure
This role is remote within the United States., Eastern and Pacific time zonesFull-TimeSenior
Salary$170,400 – $255,700
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- AWSPythonGCPAzureGo
Requirements
- 5+ years of experience in offensive security, penetration testing, red teaming, or a related field.
- Strong programming skills in Python, Go, or similar languages.
- Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes.
- Hands-on experience with cloud platforms (AWS, Azure, or GCP) and cloud-native attack techniques.
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, or BloodHound.
- Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK.
- Excellent written and verbal communication skills.
- Ability to think like an adversary and holistically assess risk in complex environments.
Responsibilities
- Conduct comprehensive penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure.
- Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors, including initial access, lateral movement, persistence, and data exfiltration.
- Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams.
- Partner with detection engineering, threat intelligence, and incident response teams to validate security controls and identify coverage gaps.
- Contribute adversary tradecraft insights to inform detection rule development and incident response playbooks.
- Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency.
- Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site