Span logo
Span1 week ago

Sr. Offensive Security Engineer

$138,000–$184,000 year

On-site · San Francisco, California, United States

Type
Full Time
Level
Senior Level
Education
Not Specified
Company size
Unknown

Job Summary

Senior Offensive Security Engineer responsible for full-scope adversary emulations across SPAN's cloud, web/mobile apps, APIs, and corporate IT infrastructure; lead Technical Incident Response lifecycle during security events; translate offensive findings into proactive detection rules and hardening requirements; own the vulnerability disclosure pipeline (VDP) and liaison with external researchers; build automated security-testing tools and runbooks; leverage MITRE ATT&CK to test live detection capabilities and IR readiness; develop post-incident forensics, IoC timelines, and post-incident reviews. Must have hands-on experience in cloud security (Docker/Kubernetes, IAM), web/API security (OWASP Top 10), scripting in Python/Go/Bash, and a track record of identifying critical vulnerabilities through bug bounties or VDPs. Location: San Francisco, CA; full-time role with competitive compensation and equity.

Required Qualifications

  • 6+ years of professional experience in offensive security (penetration testing, red teaming), dedicated technical incident response, or a closely related field.
Sorce

Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

$138k – $184k / yr

Sr. Offensive Security Engineer · Span

Apply on Sorce