> Markdown version of [/jobs/ext/2633947-senior-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/2633947-senior-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Offensive Security Engineer - **Company:** World Wide Technology - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $116,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), Private Networks, Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, C++ (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Kali Linux, Open Web Application Security, Windows PowerShell, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Web Applications, Google Cloud, Cloud Platform System, Software Security, Mitre Att&ck, Information Technology, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** August 15, 2026 - **Apply:** https://www.jobmonkeyjobs.com/career/27938264/Senior-Offensive-Security-Engineer-Any-Remote-Nationwide-7449 ## About the Role * 5-7+ years hands-on offensive security or penetration testing experience in web application, network, and cloud environments * Demonstrated experience designing, leading, or maturing an offensive security program or methodology * Experience scoping and overseeing internal and third-party offensive security engagements including rules of engagement, authorization, and scope management * Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses * Hands-on Active Directory and internal network exploitation experience (e.g., Kerberoasting, delegation abuse, lateral movement, privilege escalation) * Working knowledge of cloud attack surfaces, including IAM misconfigurations, container security, and CI/CD pipeline attacks * Experience using AI tools to accelerate offensive security workflows * Deep understanding of OWASP Top 10, MITRE ATT&CK, CVSS and other severity scoring frameworks, and full attack-chain thinking * Scripting and automation ability to build or extend custom tooling (e.g., Python, Bash, Powershell) * Hands-on threat modeling experience (STRIDE, PASTA, or equivalent) * Understanding of secure handling, storage, and reporting of sensitive engagement data and findings * Excellent interpersonal, written, and verbal communication - able to explain and document security risk and remediation credibly to both technical and non-technical stakeholders * Self-starter, team player, and enthusiasm for learning * Applicants must be authorized to work in the United States without sponsorship. We are unable to provide sponsorship now or in the future for this position., * Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related field - or equivalent hands-on experience. * OSCP, OSWE, OSEP, or equivalent red-team oriented certification * Cloud security certification (AWS, Azure, GCP) * Experience with C2 frameworks or interest in growing adversary emulation capabilities * Familiarity with SIEM/EDR or detection engineering from a defender's perspective * Programming experience beyond scripting for exploit development or evasion tooling (C/C++, JavaScript, Go, Python) * Working knowledge of SAST, DAST, SCA, and vulnerability management tooling * Experience building or maintaining offensive security testing playbooks * Familiarity with compliance frameworks and compliance-driven testing requirements (SOC 2, ISO 27001, etc.) * Track record of mentoring team members ## Description World Wide Technology's Information Security organization is hiring a Senior Offensive Security Engineer to help build and mature an offensive security capability that identifies and validates real-world risk across the organization's applications, networks, and cloud infrastructure. While this role sits within the Application Security team, your scope extends well beyond applications. You'll plan and execute offensive engagements across organization-owned web applications and APIs, internal and external networks, and cloud environments, thinking like an adversary to find what automated tooling misses. Your focus is hands-on testing, retesting, and validation paired with clear, actionable reporting that helps both engineers and leadership understand and close real risk. You'll partner closely with multiple teams to drive remediation, strengthen detection, and inform testing priorities across the business. This is a role for an offensive security practitioner who wants to build a program, not just execute within one. Key Responsibilities Testing Execution * Plan and execute offensive tests across WWT owned web applications, APIs, internal and external networks, and cloud infrastructure * Retest and validate remediated findings to confirm the fixes resolve the gaps * Support scoping, oversight, and execution of internal and third-party engagements Reporting & Metrics * Write clear, actionable reports for technical teams and leadership with reproducible steps and remediation guidance * Track and report on trends across engagements, such as recurring finding types, time-to-remediate, and risk exposure, to inform leadership and program prioritization Collaboration & Compliance * Collaborate across engineering, security, and GRC to drive remediation, validate findings, and inform testing prioritities * Support compliance-driven testing requirements * Contribute adversary-perspective input into threat modeling, architecture/design reviews, secure coding standards, and vulnerability management program Program & Tooling * Maintain and evolve internal testing playbooks as the program matures * Leverage AI tools to accelerate testing workflows, analysis, and reporting * Build, adapt, or evaluate offensive security tooling and third-party vendors to support testing and reduce manual overhead ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)