Jobs and Careers
CR

Staff Security Engineer, Offensive Security

Cruise LLC
San Francisco, United Statesfull_timeVerifiedPosted 6 Jul 2023
💰 $275,900/yr($187,700/yr$275,900/yr)

About the role

We're Cruise, a self-driving service designed for the cities we love.

We’re building the world’s most advanced self-driving vehicles to safely connect people to the places, things, and experiences they care about. We believe self-driving vehicles will help save lives, reshape cities, give back time in transit, and restore freedom of movement for many.

In our cars, you’re free to be yourself. It’s the same here at Cruise. We’re creating a culture that values the experiences and contributions of all of the unique individuals who collectively make up Cruise, so that every employee can do their best work. 

Cruise is committed to building a diverse, equitable, and inclusive environment, both in our workplace and in our products. If you are looking to play a part in making a positive impact in the world by advancing the revolutionary work of self-driving cars, come join us. Even if you might not meet every requirement, we strongly encourage you to apply. You might just be the right candidate for us.

We are building a world-class Threat Defense organization, and are looking for an exceptional technical leader to take our Red Team to the next level.

The Offensive Security team plays a major role in securing Cruise's uncharted attack surface. We aim to out-think and out-develop Cruise's most sophisticated adversaries, executing complex offensive security operations in Cruise's environment to identify areas to improve the company's security posture and blue team capabilities.

You will come to intimately understand Cruise’s environment and business, and leveraging your in-depth expertise in penetration testing, offensive security and software development, independently plan and execute offensive security operations. You will deliver comprehensive reports and presentations on your team's operations, findings and recommendations. Further, leveraging your deep software development abilities, you will develop tooling, systems and infrastructure to automate certain attacks.

Applicants should look forward to solving hard problems, employing their outstanding written and verbal communication skills, and leading and mentoring others. You should possess extensive experience in offensive security, and be someone who stands out as a top performer, innovator and leader.
 

What You’ll Be Doing

  • Provide day-to-day technical leadership and support to a team of offensive security engineers

  • Set a compelling vision and strategy for offensive security operations and tool development

  • Partner closely with the team’s manager to define and gain leadership support for key operational objectives

  • Mentor junior and senior security engineers

  • Lead complex offensive security operations from ideation through documentation and executive presentation

  • Craft novel tools, techniques and procedures to exploit vulnerabilities, gain and establish a foothold across various environments and infrastructure, and successfully carry out complex operational objectives

  • Build and support relationships with key partners within and outside of Security

  • Educate engineering teams to identify and mitigate security vulnerabilities

  • Embody Cruise behaviors and values: Stay Safe, Own It, Stay Focused, Seek Truth, Work Together, Be a Customer, Be Humble

What You Must Have

  • In-depth knowledge of current opportunistic and/or advanced threat actor ecosystem, their targeting patterns, and associated tradecraft

  • Ability to identify bugs and security flaws in even the most well-guarded systems

  • Exceptional communication skills with a knack for building cross-functional relationships 

  • Deep understanding of both hardware and software security flaws

  • Security expertise in cryptography and exploit development

  • Exceptional written and verbal communication skills, with experience presenting rules of engagement and operation findings to executives

  • Experience as a red teamer in a fast-paced, collaborative environment

  • Experience performing penetration testing of web applications and infrastructure

  • Understanding of the Red Team operation lifecycle, from drafting rules of engagement to developing stealthy, reliable malware implants and command and control (C2) protocols

  • Expertise in system design, PaaS environments, container orchestration systems, data science platforms

  • Ability to write maintainable code for use in offensive operations

  • Experience carrying out sophisticated operations in at least one of the following cloud environments: GCP, AWS, Azure

  • Passion for breaking things, and an offensive mentality

  • Coding proficiency in one or more languages, and the a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Cruise LLC

View company profile →