Own offensive engagements, including red teams and assumed‑breach exercises, adversary emulation, and goal‑driven purple team work aligned to real threats and business impact
Test applications and APIs end‑to‑end: authNZ flows, business logic, and modern web patterns; deliver clear PoCs that demonstrate impact and paths to fix
Evaluate cloud and infrastructure attack paths, such as identity/IAM escalation, network segmentation, secrets exposure, container/orchestration risks and validate exploit chains safely
Turn findings into action: triage and validate vulnerabilities, partner with engineers on pragmatic remediation, verify fixes, and prevent class‑repeat issues by collaborating with AppSec and CloudSec to build secure‑by‑default patterns
Act as an offensive security subject-matter expert to help triage issues with our SOC
Mentor and coach junior Security Engineers through their assessments, and support our Security Champions
Identify, validate, and triage vulnerabilities from multiple sources and guide remediation to improve overall security posture
Requirements
4+ years of experience in an information security-related role
Bachelor’s degree or higher, preferably in Computer Science, Engineering, or a related field
A passion for security and a desire to work on a high-tempo, supportive team where you can continue learning on the job
Strong understanding of networking (including the OSI model), HTTP protocol, and core Application Security principles
Ability to build strong relationships and work effectively across teams and functions
Excellent verbal and written communication skills, with the ability to deliver results under time-sensitive conditions
Proficient in one or more programming languages, including at least one scripting language