> Markdown version of [/jobs/ext/2680503-aws-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2680503-aws-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AWS Penetration Tester - **Company:** OffChain Labs, Inc. - **Location:** United States (Remote available) - **Experience:** Starter - **Salary:** $75,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Artificial Intelligence, Amazon Web Services, Applications Architecture, Software System Penetration Testing, Delphi (Programming Language), Burp Suite, Computer Programming, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Machine Learning, OpenShift, Open Web Application Security, Systems Development Life Cycle, Release Management, Blockchain, Web Application Security, Software Systems, SQL Databases, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Backend, Ethereum, Web3.js, Microservices - **Published:** September 2, 2026 - **Apply:** https://jobs.lever.co/offchainlabs/5dc0b755-8c1f-43c8-b268-df4b372a31d1/apply?lever-origin=applied&lever-source%5B%5D=BuiltInNationwide ## About the Role * 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field. * Extensive experience with conducting code audits to identify and remediate security issues. * Experience with binary exploitation. * Mastery of AWS & specific attack techniques and configuration weaknesses. * Strong understanding of adversary tactics and frameworks like MITRE ATT&CK. * In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories. * Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks. * Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation. * Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations. * A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems. Nice-to-haves * Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review. * Familiarity with Ethereum L1 / L2 node architecture and security risks. * Experience in blockchain infrastructure penetration testing. ## Description * As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools. * You'll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities. * Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2. What you'll do: * Conduct comprehensive code audits across a variety of internal applications and infrastructure. * Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications. * Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality. * Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed. * Offer offensive security expertise during incident investigations, including log analysis and root cause reviews. * Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community. * Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange., Lead customer implementations of SOPHiA GENETICS genomic analysis solutions, from planning and sample selection through configuration, training, adoption, and issue resolution. Manage MaxCare Program schedules, timelines, sampling strategies, Statements of Work, technical setup, and cross-functional delivery. Translate laboratory, bioinformatics, data, and clinical regulatory requirements into practical solutions while building trusted customer relationships. The field-based US role includes approximately 30% travel. Top Skills: BioinformaticsCustom ReportingFederated Sso AuthenticationLibrary PreparationNext-Generation SequencingSophia Ddm Platform PNC Bank Software Engineer 2 Hours Ago Remote or Hybrid USA 75K-150K Annually Junior 75K-150K Annually Junior Machine Learning * Payments * Security * Software * Financial Services Develops, tests, deploys, maintains, and debugs software across the full project lifecycle. Translates business requirements into technical designs, supports production systems, documents solutions, estimates development tasks, collaborates with teammates, and mentors newer developers. The role requires application architecture, SDLC, testing, troubleshooting, and maintenance experience using Java, .NET, and/or Delphi, with Delphi preferred. Top Skills: .NetDelphiJava PNC Bank Senior Software Engineer 2 Hours Ago Remote or Hybrid USA Senior level Senior level Machine Learning * Payments * Security * Software * Financial Services Designs, develops, tests, deploys, maintains, and debugs software solutions. Leads complex technical initiatives, Java microservices and API integration, OpenShift deployments, server and database administration, release management, production support, vulnerability remediation, incident resolution, and vendor coordination. Supports remote deposit platforms while managing application resiliency, security compliance, documentation, and stakeholder communication. Top Skills: AgileAPIsCandescent Remote Deposit/CaptureCloud-Native ArchitecturesConnect:DirectContainerizationDevOpsJavaLinuxMicroservicesMicrosoft Sql ServerOpenshift Container PlatformPowershellPythonSdlcShell ScriptingWindows Server What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [Smart Contract fundamentals - My first DApp](https://www.wearedevelopers.com/videos/52-smart-contract-fundamentals-my-first-dapp) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [SSO with Ethereum and Next JS](https://www.wearedevelopers.com/videos/288-sso-with-ethereum-and-next-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)