> Markdown version of [/jobs/ext/1920048-staff-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/1920048-staff-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Offensive Security Engineer - **Company:** Cloaked, Inc. - **Location:** New York, NY, United States (Remote available) - **Salary:** $200,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Business Logic, Software as a Service, Identity and Access Management, Cloud Services, Red Team (Cyber Security), Subversion, Multi-Cloud, Blue Team (Cyber Security), Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fde7c36a74bb3e0d ## About the Role * Non-Linear Background: You have seen the tech stack from every angle. We value a diverse background - whether you've spent time in customer support, QA/test, development, blue team, red team, or all of the above. You know how users break things accidentally, which fuels how you break them intentionally. * Cloud & SaaS Mastery: Your playground is modern infrastructure. You are fluent in multi-cloud environments and complex SaaS architectures. You know exactly how to abuse IAM trust boundaries, tenant isolation flaws, and API misconfigurations. * No Ego: You have the communication skills to translate a highly complex exploit into actionable engineering requirements without talking down to the engineers who built it. ## Description You are not a vulnerability scanner; you are a strategic adversary. Your directive is to compromise our most critical assets before actual adversaries do. * Absolute Autonomy: There is no daily task list. You are handed the Rules of Engagement. From there, it is on you to design, dictate, and execute campaigns that provide uncompromising coverage of our attack surface, backed by thorough, rigorous test cases. * Beyond the Tooling: Off-the-shelf scanners will not find what you are looking for here. We need you for the complex logical flaws and chained vectors that require human intuition. Furthermore, you aren't just using tools - you are building them. You will engineer complex, future-forward offensive systems that redefine how we test our own defenses at scale. * Ruthless Prioritization: You have an infinite attack surface and finite time. You must be able to cut through the noise and prioritize your targets based on catastrophic business risk rather than easy, low-impact wins. * Business Subversion: You do not operate in a vacuum. You will partner directly with product and engineering leaders to deeply understand the core business logic of our platforms - and then weaponize that logic against them. * Force Multiplier: Breaking in is only half the mandate. When the operation concludes, you teach. You will deconstruct your attack paths and help engineering eradicate entire attack classifications at the root. By driving foundational system hardening and secure development standards, you ensure whole categories of vulnerabilities never see production again. * Ubiquitous Ownership: Despite the advanced mandate, our ultimate bottom line is protecting our customers, which means finding flaws early across every single part of the business. You will cross business units to provide hands-on security guidance, rigorous architecture review, and audit support. One day you might be red-teaming a physical system, and the next you are tearing apart our flagship product. We demand apex-level hacking, but we have zero tolerance for a "that's not my job" mentality., We offer flexible work arrangements and the ability to work remotely as needed. Cloaked provides a home office stipend in addition to a new company laptop (and other tech depending on the role). ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [The Algorithm That Nearly Killed Me: When Testing Isn't Enough](https://www.wearedevelopers.com/videos/2110-the-algorithm-that-nearly-killed-me-when-testing-isn-t-enough) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Defeat that legacy monster! Guerilla refactoring with web standards](https://www.wearedevelopers.com/videos/647-defeat-that-legacy-monster-guerilla-refactoring-with-web-standards) - [Where we're going we don't need JavaScript - Programming with Type Annotations](https://www.wearedevelopers.com/videos/455-where-we-re-going-we-don-t-need-javascript-programming-with-type-annotations) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)