Security Engineer II (Offensive Operations)
Core
Execute manual penetration testing, code audits, and adversarial simulations to identify and remediate vulnerabilities in cloud infrastructure, web applications, and APIs.
Role type
Senior IC offensive security engineer (penetration testing & red teaming)
Builds
Hardened cloud environments, secure APIs, and robust detection rules via adversarial emulation
Domain
Cybersecurity / Cloud Security / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
manual penetration testing, web application security, API security, source code auditing, SAST/DAST analysis, Python/Java/Ruby scripting, AWS cloud security, MITRE ATT&CK framework, bug bounty program management, technical report writing
Preferred skills
OSCP, OSCE, SANS GXPN, OffSec OSAI
Technologies
Kali Linux, AWS, REST/GraphQL, Python, Java, Ruby, SIEM, CI/CD, IaC
Responsibilities
Execute internal and external penetration testing across multicloud environments; Perform deep-dive testing on web applications and APIs for business logic flaws; Review SAST/DAST findings and conduct targeted code audits; Partner with Blue Team during adversary emulation exercises; Participate in goal-oriented red team engagements; Manage external vulnerability disclosure and bug bounty programs; Apply emerging threat actor TTPs to align testing methodologies with MITRE ATT&CK
Seniority
Mid-Senior, hands-on IC