Offensive Security Engineer (Red Team)
Quick Summary
5+ years of professional experience in offensive security, red teaming, penetration testing, detection validation, or closely related security disciplines. Strong understanding of adversary tactics,
This remote role sits within a Product Security team and focuses on strengthening security through hands-on offensive testing and adversary emulation. You will assess modern cloud environments, infrastructure, identity architectures, CI/CD pipelines, containers, and cloud-native services. The role combines technical investigation with close collaboration across security, engineering, blue team, and detection functions. You will simulate realistic attacker behavior to uncover vulnerabilities, validate security controls, and identify practical attack paths. Your findings will help engineering teams prioritize remediation and improve organizational resilience. The position is suited to an experienced offensive security professional who enjoys exploring emerging cloud attack techniques and translating complex findings into actionable improvements.
-
Plan and execute red team operations, adversary simulations, penetration tests, and targeted offensive security assessments across cloud environments.
-
Evaluate the security posture of cloud infrastructure, identity architectures, CI/CD pipelines, containerized workloads, and cloud-native services.
-
Identify and validate realistic attack paths involving IAM misconfigurations, excessive privileges, exposed secrets, metadata services, insecure automation, and cloud configuration weaknesses.
-
Conduct security assessments designed to replicate relevant attacker behaviors and techniques in modern enterprise environments.
-
Validate the effectiveness of security monitoring and detection capabilities by testing logging, alerting, monitoring, and incident-response processes.
-
Partner with blue team and detection engineering functions to identify gaps in defensive coverage and improve detection and response capabilities.
-
Document vulnerabilities, attack paths, and security weaknesses in concise, actionable reports.
-
Work with software and engineering teams to communicate findings, support remediation efforts, and help reduce security risk.
-
Track emerging attacker tactics, cloud exploitation techniques, and new abuse paths that could affect cloud-native environments.
-
Map offensive security findings and adversary behaviors to established frameworks such as MITRE ATT&CK.
-
Serve as a trusted security partner to engineering teams, helping strengthen security practices through practical offensive expertise.
Requirements
~2 min read-
5+ years of professional experience in offensive security, red teaming, penetration testing, detection validation, or closely related security disciplines.
-
Strong understanding of adversary tactics, techniques, and procedures, with the ability to apply them to realistic security assessments.
-
Experience conducting offensive security assessments in cloud environments and evaluating modern cloud infrastructure and services.
-
Practical understanding of cloud identity and access management, CI/CD security, containers, secrets management, and cloud-native architectures.
-
Ability to identify and validate complex attack paths involving IAM weaknesses, overprivileged identities, exposed credentials or secrets, metadata services, insecure automation, and configuration issues.
-
Experience evaluating security monitoring and detection capabilities through adversary simulation or detection-validation exercises.
-
Ability to map findings and attacker behavior to frameworks such as MITRE ATT&CK.
-
Strong written and verbal communication skills, including the ability to explain complex technical security issues to engineering teams and other stakeholders.
-
Ability to produce concise, actionable security reports that clearly communicate technical findings, business relevance, and remediation considerations.
-
Strong analytical and investigative mindset with a willingness to explore emerging attack techniques and unfamiliar technologies.
-
Relevant industry certifications such as OSCP, OSEP, GXPN, GPEN, or recognized cloud security certifications are valued.
-
Ability to work effectively in a remote environment and collaborate across technical and security teams.
-
Authorization to work in Canada and meet applicable requirements for accessing controlled technologies and commodities.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- September 29, 2026
Signal breakdown
Similar Offensive Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.