AWS Penetration Tester

OffChain Labs, Inc.
United States
2 days ago
Apply on jobs.lever.co
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
5 years minimum
Compensation
$75,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Artificial Intelligence Amazon Web Services Applications Architecture Software System Penetration Testing Delphi (Programming Language) Burp Suite Computer Programming Intrusion Detection and Prevention Python (Programming Language) Log Analysis
+16 more
Machine Learning OpenShift Open Web Application Security Systems Development Life Cycle Release Management Blockchain Web Application Security Software Systems SQL Databases Software Vulnerability Management Mitre Att&ck Cyber Threat Analysis Backend Ethereum Web3.js Microservices

Job description

  • As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.
  • You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.
  • Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.

What you’ll do:

  • Conduct comprehensive code audits across a variety of internal applications and infrastructure.
  • Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.
  • Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.
  • Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.
  • Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.
  • Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.
  • Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange., Lead customer implementations of SOPHiA GENETICS genomic analysis solutions, from planning and sample selection through configuration, training, adoption, and issue resolution. Manage MaxCare Program schedules, timelines, sampling strategies, Statements of Work, technical setup, and cross-functional delivery. Translate laboratory, bioinformatics, data, and clinical regulatory requirements into practical solutions while building trusted customer relationships. The field-based US role includes approximately 30% travel. Top Skills: BioinformaticsCustom ReportingFederated Sso AuthenticationLibrary PreparationNext-Generation SequencingSophia Ddm Platform PNC Bank

Software Engineer

2 Hours Ago Remote or Hybrid USA 75K-150K Annually Junior 75K-150K Annually Junior Machine Learning * Payments * Security * Software * Financial Services Develops, tests, deploys, maintains, and debugs software across the full project lifecycle. Translates business requirements into technical designs, supports production systems, documents solutions, estimates development tasks, collaborates with teammates, and mentors newer developers. The role requires application architecture, SDLC, testing, troubleshooting, and maintenance experience using Java, .NET, and/or Delphi, with Delphi preferred. Top Skills: .NetDelphiJava PNC Bank

Senior Software Engineer

2 Hours Ago Remote or Hybrid USA Senior level Senior level Machine Learning * Payments * Security * Software * Financial Services Designs, develops, tests, deploys, maintains, and debugs software solutions. Leads complex technical initiatives, Java microservices and API integration, OpenShift deployments, server and database administration, release management, production support, vulnerability remediation, incident resolution, and vendor coordination. Supports remote deposit platforms while managing application resiliency, security compliance, documentation, and stakeholder communication. Top Skills: AgileAPIsCandescent Remote Deposit/CaptureCloud-Native ArchitecturesConnect:DirectContainerizationDevOpsJavaLinuxMicroservicesMicrosoft Sql ServerOpenshift Container PlatformPowershellPythonSdlcShell ScriptingWindows Server

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Requirements

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Extensive experience with conducting code audits to identify and remediate security issues.
  • Experience with binary exploitation.
  • Mastery of AWS & specific attack techniques and configuration weaknesses.
  • Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
  • In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
  • Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.
  • Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
  • A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.

Nice-to-haves

  • Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.
  • Familiarity with Ethereum L1 / L2 node architecture and security risks.
  • Experience in blockchain infrastructure penetration testing.

Benefits & conditions

  • Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
  • Medical, dental & vision coverage (US + some other countries)
  • 401k retirement plan + company match (US only)
  • Wellness stipend
  • Home office set up / ergonomic equipment program

About the company

Conduct code audits and penetration tests across AWS cloud environments, infrastructure, backend applications, and blockchain ecosystem tools. Lead red-team exercises, collaborate with detection engineering and incident response teams, develop offensive security automation, support investigations, research emerging threats, and mentor junior staff. The role requires expertise in AWS attack techniques, binary exploitation, web application security, adversary frameworks, and offensive tooling, with Web3 and blockchain security experience preferred. The summary above was generated by AI At Offchain, we aren’t just building products: we’re leading a movement. As pioneers in blockchain scalability and security, we’re at the forefront of transforming how the world interacts with decentralized applications. We’re laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency. At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you. Why Offchain? Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today. Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack. Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what’s possible on Ethereum and advancing its core infrastructure. To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.lever.co
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:13 min

Introduction to single sign-on with Ethereum

Rahat Chowdhury · JS Congress

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

3:26 min

Automating programmable logic using smart contracts and JavaScript tools

Ryan Arndt · World Congress 2023

49 sec

Connecting existing applications to non-Ethereum networks

Rahat Chowdhury · JS Congress

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · World Congress 2024

Videos

See all

Related articles

See all