Offensive Security Engineer
Location
United States
Posted
101 days ago
Salary
0
Seniority
Senior
Job Description
Offensive Security Engineer
Wraithwatch
• Continuously harden Wraithwatch (the company and product) against advanced threats. • Teach the system your expert attack tradecraft and have it evolve to execute it on its own. • Build and ship things on the daily with the core product engineers.
Job Requirements
- 5+ years professional experience conducting complex penetration testing assessments in commercial or government environments.
- Deep, hands-on understanding of the current landscape of offensive cyber tradecraft (in memory, fileless attacks, beacon object files, malleable C2, modern initial access vectors, emerging EDR bypasses, etc).
- Experience implementing or assisting with the implementation of enterprise / corporate security controls such as anti-malware policies, identity and access controls, detection engineering, device management, or similar.
- Interest in adapting AI to red teaming / penetration testing use cases. This is a hard requirement.
- Interest in modern machine learning or artificial intelligence capabilities, especially emerging subsets of Generative AI such as agentic behavior, tool calling, knowledge graph integration, retrieval augmented generation, etc.
- Ability to deal with ambiguity and learn new technologies quickly.
- Willingness to work extended hours and weekends as needed.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Define and execute HavocAI’s port security GTM strategy across both commercial and government customers. • Identify priority accounts across commercial port authorities and terminal operators and federal maritime security stakeholders. • Develop repeatable playbooks for pilots, deployments, and expansion across varied procurement pathways. • Build and manage a robust pipeline within the port security domain. • Carry direct responsibility for pipeline development, opportunity advancement, and revenue growth within the port security vertical. • Lead commercial sales engagements and support government capture efforts. • Partner with marketing to produce specific materials on port security. • Engage directly with port directors, harbor masters, security chiefs, and government maritime leaders.
Security Engineer – Insider Risk
Dragonfli GroupCyberSecurity as a Solution: Enabling Secure Business.
• Assist in developing playbooks, workflows, and implementation roadmaps to mature the Insider Threat operational support program. • Administer and optimize the Insider Risk toolset, specifically DLP, UEBA, SIEM, and Microsoft Defender/Entra/Purview. • Develop and maintain a convergence model to reduce risk to personnel and assets across regional operating divisions. • Lead and assist in the investigation of all incidents involving potential insider threats. • Coordinate with business and technology leaders to develop programmatic solutions and deliver high-level presentations on findings. • Implement federal government and industry standards regarding insider threat programs and maintain programmatic gap analyses.
Senior Legal Advisor
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This position is for a Senior Counsel - REMOTE, where you will join a dynamic Legal and Compliance department, providing high-caliber legal advice to internal stakeholders. Support business units across the company with diverse legal needs. Develop and improve processes for the Legal and Compliance Department. Ensure that legal obligations are met and the company is fully protected. Identify and propose solutions to complex legal challenges. Navigate data privacy legislation to keep policies up-to-date.
• FedRAMP Ownership: Own the entire process for maintaining and managing FedRAMP/GovRamp authorizations, including control implementation, documentation (e.g., System Security Plan - SSP), continuous monitoring, and annual audits (A&A). • Audit Management: Serve as the primary point of contact for all external security and compliance audits (including SOC 2 Type II), coordinating efforts between auditors, legal counsel, and technical teams to ensure successful outcomes and high-quality evidence collection. • Compliance Program Management: Design, implement, and lead the corporate security compliance program, ensuring adherence to the specific controls required by all key frameworks. • Security-by-Design Review: Collaborate closely with the Product Management and Engineering teams, reviewing product roadmaps, features, and architectures to ensure security and government compliance (especially FedRAMP/GovRamp controls) are integrated from the initial design phase (Security-by-Design). • Product Requirements Translation: Translate complex regulatory and certification controls into clear, actionable technical requirements and user stories for product development teams. • Risk Mitigation: Conduct risk assessments on product features, third-party integrations, and new technologies to proactively identify and mitigate compliance and security risks before product launch. • Contractual Review: Support the Legal Team by critically reviewing and negotiating security and privacy clauses in customer contracts, RFPs, vendor agreements, and data processing addendums (DPAs), specifically pertaining to government and regulated clients. • Policy & Training: Develop, document, and enforce comprehensive security, privacy, and data governance policies. Conduct targeted training for teams involved in government-facing products. • Executive Reporting: Provide regular, executive-level reports to the Chief Legal Counsel on the status of compliance efforts, identified risks, and strategic security posture.



