Boosting offensive security with AI
Expert Services Engineer – Cybersecurity
Location
South Korea
Posted
85 days ago
Salary
0
Seniority
Lead
Job Description
Expert Services Engineer – Cybersecurity
XBOW
• Act as customers technical PoC post-sales • Work on integrating the XBOW product with customer environments • Lead self-hosted product deployments, support and upgrades • Support feature prototyping • Provide Tier 2 support for customer technical issues • Be open to supporting pre-sales support roles when required • Provide feedback to product teams on what you are seeing in the Field • Help explain the technical and business value of the product to users and stakeholders • Support hand-off between pre and post sales teams • Run Expert Services engagements
Job Requirements
- 10+ years Security Engineering/DevSecOps/Infrastructure Engineering or adjacent experience
- Experience as a Expert Services/Field Engineer in the security space, preferably with a SaaS product
- Understanding of SAST, SCA, CWP and DAST products in the market
- Hands on experience building cloud infrastructure, deploying products in cloud environments and integrating with VPN and SSO technologies
- Strong command of security concepts such as the OWASP Top 10
- Understanding of security frameworks and compliance, such as ISO-27001, FedRAMP, SOC2, PCI or HIPAA
- Can support CSM teams by resolving customers technical issues, and providing Tier 2 support
- Comfortable prototyping features for customers
- Experience working with Cloud vendors such as AWS, Azure, GCP and OCI
- Capable of explaining complex security concepts clearly to mixed audiences
- Used to tailoring messaging to CISOs, security engineers and executives
- Experience working with Product Engineering teams to communicate customer learnings
- Basic understanding of customer post-sales buying drivers and objections
- Comfortable learning new languages such as Go and TypeScript
- Fluent in English and Korean, both written and spoken.
Benefits
- Competitive salary, clear performance-based incentives, and equity package, making you an integral part of XBOW’s growth story.
- Significant opportunities to progress within the sales organization and shape your career trajectory as we scale.
- You’ll directly impact XBOW’s mission to revolutionize cybersecurity and protect organizations worldwide.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Respond to customer security questionnaires utilizing a combination of knowledgebases, generative AI and subject matter expertise. • Produce and maintain documentation that can be utilized on our public Trust Center, enabling customers to self-serve. • Drive improvements to our knowledgebase through partnerships with product and technology colleagues. • Provide metrics and reports to management, demonstrating overall trends and performance on a regular cadence.
Offensive Security Engineer
Charles Schwab CorporationCharles Schwab Corporation is an investment services firm that strives to disrupt the Wall Street status quo. The company believes that when people find ways to improve the investi
• The Offensive Security Engineer scopes, designs and executes controlled cybersecurity offensive operations, penetration tests and threat adversary emulation exercises to identify vulnerabilities and risks, evaluate the effectiveness of security controls and the incident response process. • The Offensive Security Engineer documents any identified risks, translates technical findings into clear, actionable recommendations and works with stakeholders to identify appropriate mitigating controls to manage any outstanding risk. • The Offensive Security Engineer works closely with counterparts in defensive teams to improve threat detection and response and engineering teams to mitigate risk before it's introduced into the environment. • Scope, develop and execute penetration tests, purple team assessments and red team exercises. • Design and develop tools, infrastructure and exploits in support of red team operations. • Research and implement assessments based on emerging threats, threat intelligence, and vulnerabilities. • Identify gaps in threat detection, Prevention and response. • Work collaboratively with counterparts in Cyber Defense roles to enhance the firms security posture. • Effectively communicate vulnerabilities, risks and technical findings to stakeholders and work with stakeholders to recommend and validate mitigating controls.
• Conduct intrusion tests (internal and external) in corporate environments, web applications, APIs, networks, operating systems and cloud infrastructure. • Plan, execute and document simulated offensive campaigns (Red Team operations), focusing on defense evasion, lateral movement, persistence and data exfiltration. • Develop and apply adversary simulation techniques, based on frameworks such as MITRE ATT&CK, APT TTPs and other threat intelligence sources. • Use and customize offensive tools such as Cobalt Strike, Metasploit, Empire, Sliver, BloodHound, Burp Suite, among others. • Identify vulnerabilities, misconfigurations and potential attack vectors that could be exploited by malicious actors. • Prepare technical and executive reports with findings, evidence and recommendations for mitigation. • Work closely with Blue Team, SOC and Vulnerability Management teams, supporting Purple Team exercises and improving the organization's defenses. • Continuously update knowledge on new attack techniques, tools, exploits and threat landscape trends.
• Conduct thorough research on target systems, applications, and networks to identify potential vulnerabilities. • Develop and execute custom attack vectors using various tools and techniques (e.g., fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side-Request-Forgery (SSRF), Remote Code Execution). • Identify and exploit vulnerabilities in a responsible manner, ensuring that no harm is caused to the system or data being tested. • Document all findings, including detailed descriptions of discovered vulnerabilities, proof-of-concept code, and steps taken to reproduce the issue. • Participate in regular bug bounty programs and contribute to the improvement of our products and services.




