> Markdown version of [/jobs/ext/985853-senior-offensive-security-engineer-red-team](https://www.wearedevelopers.com/jobs/ext/985853-senior-offensive-security-engineer-red-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Offensive Security Engineer (Red Team) - **Company:** Salesforce.com, Inc. - **Location:** United States - **Experience:** Expert - **Salary:** $148,500.0 - $223,900.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Red Team (Cyber Security), Scripting - **Published:** June 30, 2026 - **Apply:** https://diversityjobs.com/career/17426595/Senior-Offensive-Security-Engineer-Red-Team-Maryland ## About the Role * Deep hands-on experience in offensive security, red teaming, or high-impact penetration testing. * Proven experience executing complex offensive engagements in production-like environments. * Strong understanding of: + Adversary tactics, techniques, and procedures (TTPs) + Identity and access abuse + Application and infrastructure attack chains + Cloud and hybrid enterprise attack surfaces * Hands-on experience with: + Manual exploitation and attack chaining + Writing custom scripts, tooling, or payloads + Bypassing security controls and detections * Ability to clearly articulate: + How attacks were performed + Why defenses failed + What mitigations will meaningfully reduce risk * Strong communication skills and experience collaborating with security and engineering teams. ## Description We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on attacker mindset to execute advanced offensive security operations across our products, platforms, and enterprise environment. This role is highly execution-focused. You will work closely with the Red Team Director to design and carry out real-world adversary simulations, uncover high-impact attack paths, and validate how weaknesses can be chained to achieve meaningful attacker objectives. The emphasis is on real exploitation, depth and impact, not checklist-driven testing. You will play a key role in translating red team operations into actionable insights that improve prevention, detection, and response capabilities across the organization., * Execute hands-on red team operations simulating real-world threat actors across applications, platforms, cloud infrastructure, and enterprise environments. * Identify, exploit, and chain high-impact vulnerabilities and weaknesses to achieve defined attacker goals. * Perform advanced offensive activities, including: + Manual exploitation and attack chaining + Abuse of identity, authorization, and trust relationships + Bypassing security controls and detections * Contribute to the design and execution of end-to-end attack campaigns under the guidance of the Red Team Director. * Develop a deep understanding of products and systems through the lens of adversary abuse and exploitation. * Collaborate closely with: + Detection & Response teams to test alerts, visibility, and response workflows + Incident Response teams during simulated incidents + Engineering and platform teams to explain exploitation paths and root causes * Produce clear, technically detailed findings that translate into actionable remediation guidance. * Contribute to tooling, automation, and tradecraft improvements, including collaboration with the AI-Automation team. * Share knowledge and mentor junior red team engineers, helping raise overall tradecraft quality. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Introduction to Responsible AI: Balancing Value and Risk](https://www.wearedevelopers.com/videos/1972-introduction-to-responsible-ai-balancing-value-and-risk) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)