Senior Security Engineer, Offensive Security
jobgether
Switzerland
Vollzeit
Diese Anzeige stammt von Lever
Accountabilities:
As a Senior Security Engineer, you will combine hands-on offensive security work with strategic security engineering, helping teams identify risks early and embed security into product and infrastructure development.
- Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises across products and services.
- Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance.
- Retest vulnerabilities to validate that remediation has been successfully implemented.
- Conduct security reviews and threat modeling across application architecture, designs, code, and emerging AI products.
- Build and maintain offensive security tooling, automation, security tests, and exploit capabilities to expand testing coverage.
- Partner with engineering teams to design and implement security architecture, controls, Zero Trust practices, and least-privilege access.
- Support security programs including automated security design reviews and vulnerability management.
- Investigate security events, participate in incident response, and contribute to a rotating on-call schedule.
- Collaborate with product, engineering, and other stakeholders to promote security-by-design practices.
- Contribute to security roadmaps, monitoring improvements, anomaly detection, compliance initiatives, and security documentation.
- Own recurring penetration tests and adversary-emulation activities while engaging with external security researchers where appropriate.
- Help strengthen security practices for cloud infrastructure, containerized environments, and AI/ML systems.
Requirements
The ideal candidate combines strong hands-on offensive security capabilities with software development expertise, cloud security knowledge, and the ability to influence security practices across technical and non-technical teams.
- 3+ years of experience in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
- 2+ years of hands-on software development experience with Python or Golang.
- Deep knowledge of authentication and authorization, including OAuth, applied cryptography, and Zero Trust principles.
- Strong practical experience securing cloud environments such as AWS, GCP, or Azure.
- Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.
- Proficiency with offensive security tools and techniques, including Burp Suite and OWASP frameworks.
- Ability to develop security tests, exploits, and proof-of-concepts that identify real-world vulnerabilities.
- Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
- Practical experience using LLMs and agentic tools to automate vulnerability discovery, reconnaissance, and penetration testing workflows.
- Experience building security programs and automation from the ground up using risk-based prioritization.
- Experience performing security reviews and developing or improving automated security review processes.
- Excellent communication skills and the ability to explain complex security concepts to both technical and non-technical stakeholders.
- Strong understanding of security standards and a commitment to keeping up with emerging security technologies and models.
- Collaborative mindset with the ability to drive security improvements through cross-functional partnerships.
- Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO are valued.
- Published CVEs, original security research, or conference presentations are a plus.
- Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing is advantageous.
- Ability to work remotely and operate effectively with a high degree of autonomy.
- This position does not offer visa sponsorship.
- Fully remote, remote-first working environment.
- EU compensation of €118,860–€169,800, plus equity.
- Flexible scheduling designed to support autonomy and work-life balance.
- Generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.
- Home office support to help create a comfortable and effective workspace.
- Technology stipend equivalent to US$100 net per month.
- Annual learning and development stipend for conferences, courses, certifications, and professional development.
- 16 weeks of paid parental leave after six months of employment.
- Equity for all full-time employees.
- Comprehensive medical, retirement, and paid holiday benefits, varying by country.
- Opportunity to work on security challenges spanning cloud infrastructure, containers, AI/ML, and large-scale developer platforms.
- Offices available in Seattle and Paris for connection and collaboration when relevant.
- Company merchandise and team perks.
Diese Anzeige stammt von Lever. Originalanzeige ansehen ↗