Job Closed
This listing is no longer active.
Build the future of communications.
Staff Engineer, Offensive Security
Location
Ireland
Posted
90 days ago
Salary
0
Seniority
Lead
Job Description
Staff Engineer, Offensive Security
Twilio
• Full-Stack Penetration Testing: Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android) • Internal/External Network Audits: Conduct network and cloud level assessments with various tooling • Vulnerability Validation: Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives • AI/LLM Probing: Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs) • Technical Reporting: Draft high-quality reports that detail the "path to compromise" with clear, reproducible steps for developers • Tool Maintenance: Manage and update the team's testing infrastructure (e.g., Burp Suite, and basic C2 listeners) • Remediation Support: Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR • Adversary Emulation: Design and lead multi-week Red Team operations that mimic specific threat actors to test the SIRT detection capabilities • Custom Exploit Development: Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth • AI Red Teaming Architecture: Build automated testing frameworks for AI systems to test for models related to sensitive data leakage • Cloud & Infrastructure Attacks: Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes • Purple Teaming: Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on the techniques used during an engagement • Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes
Job Requirements
- 7-10 years in offensive security, penetration testing, a high-volume bug bounty background, AppSec, or vulnerability exploitation
- Expert Knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs
- Proficient in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark
- Ability to write functional scripts in Python or Bash to automate repetitive testing tasks, proficiency in coding and scripting like Python, C++, and scripting for creating custom offensive exploits
- Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks
Benefits
- Competitive pay
- Generous time off
- Ample parental and wellness leave
- Healthcare
- Retirement savings program
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Manager, Cybersecurity
LoadSpring SolutionsGlobal market leader in cloud-based project management solutions. Intersecting business and data
• Lead, mentor, and develop a high-performing team of Cybersecurity Engineers, ensuring continuous growth and success. • Own and evolve LoadSpring’s cybersecurity strategy for a SaaS, cloud-first environment. • Ensure compliance with customer and industry requirements such as SOC 2, GDPR, and other applicable frameworks. • Manage audits where required. • Lead customer security-focused meetings. • Oversee security operations, including threat detection, incident response, vulnerability management, and remediation. • Partner with Engineering and Product teams to integrate security into the SDLC, CI/CD pipelines, and cloud architecture. • Manage cloud security across platforms, including IAM, network security, logging, and monitoring. • Lead security incident response efforts, including customer impact assessment, communications, and post-incident reviews. • Conduct and manage risk assessments related to architecture, third-party vendors, and customer integrations. • Ensure compliance with customer and industry requirements such as SOC 2, GDPR, and other applicable frameworks. • Support customer security inquiries, audits, and due diligence requests (security questionnaires, trust portals, sales support). • Oversee vulnerability management and penetration testing programs, ensuring timely remediation. • Select, implement, and manage security tools such as SIEM, CSPM, IAM, and endpoint security solutions. • Develop and manage the cybersecurity vendor relationships and contracts. • Deliver regular risk posture and security metrics reporting to senior leadership. • Drive security awareness and secure security training across the organization.
Security Architect – AI Silicon & Systems
SambaNova SystemsSupercharge AI apps with SambaNova Cloud! Accelerate your AI journey. Unlock lightning-fast inference on Llama 3.1.
• Lead the security architecture of next-generation AI silicon and systems. • Conduct research and development in state-of-the-art security solutions for AI silicon. • Define and own security architecture specifications for performant, robust, and efficient AI hardware and systems. • Lead cross-functional efforts to integrate security into the product lifecycle. • Collaborate with executive leadership to align security initiatives with product competitiveness and market requirements. • Stay current with industry standards and contribute to advancements representing SambaNova. • Develop threat models and security protocols for AI accelerators and cluster environments. • Enhance secure deployment processes, including manufacturing, provisioning, and supply chain security.
Senior Strategic Account Manager – Security
Johnson ControlsTransforming the buildings where people live, work, learn and play to become smarter, healthier and more sustainable.
• Identify and develop new business opportunities within the data center market. • Manage the full sales cycle from prospecting to closing deals. • Build and maintain strong relationships with key decision-makers at hyperscale and colocation providers. • Present and demonstrate Johnson Controls’ security solutions, including physical security systems and cloud-based platforms. • Collaborate with internal teams (Product Management, Engineering, Operations) to ensure customer requirements are met. • Prepare proposals, respond to RFPs, and negotiate contracts. • Achieve or exceed assigned sales targets and KPIs.
Security Systems Applications Manager
Johnson ControlsTransforming the buildings where people live, work, learn and play to become smarter, healthier and more sustainable.
• Support the Applications Engineer by managing workflow assignments and ensuring seamless collaboration within the team. • Develop comprehensive application solutions and precise estimates tailored for Johnson Controls sales opportunities. • Provide essential technical and sales support to the field organization for large and/or integrated systems, ensuring that client needs are met with the highest level of service and expertise. • Analyze and review SalesForce.com dashboards and reports to ensure adherence to Center of Excellence (CoE) processes and best practices. • Assign and prioritize requests for design and technical specifications based on project requirements and timelines. • Review bid specifications meticulously, developing exception documentation as necessary to clarify customer needs and project scope. • Collaborate with Sales Managers to prepare accurate and compelling bid responses and functional specifications that address customer goals. • Work closely with Sales and Business Operations team members to prepare detailed project cost estimates that align with budgetary expectations. • Ensure compliance with company Policies and Procedures throughout all phases of project preparation and implementation to maintain quality and consistency. • Provide technical assistance during system startup.



