Jobs and Careers
EA

Sr. Offensive Security Engineer

Early Warning
Scottsdale, United Statesfull_timeVerifiedPosted 17 Dec 2024
💰 $150,000/yr($130,000/yr – $150,000/yr)

About the role

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose 

This position within the Offensive Security team is responsible for identifying and documenting security vulnerabilities through approved penetration testing activities for the purpose of securing Early Warning’s systems, infrastructure, and applications. Additional responsibilities include mentoring junior offensive security engineers, triaging bug bounty submissions, control validation, threat model consultation, emerging threat PoC exploitation, and password cracking and phishing campaigns.

Essential Functions  

  • Performs internal and external penetration tests focused on web applications, web services, wireless, cloud platforms, and network technologies. 
  • Conduct cloud penetration testing engagements to assess specific services and implementations (i.e. AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weakness.
  • Mentor other team members in offensive security testing techniques and approaches.
  • Work with Security and Technology partners to scope engagements by clearly articulating penetration testing approach and methodology to technical and non-technical audiences. 
  • Report generation that clearly communicates testing and assessment details, results, and remediation recommendations to internal teams. 
  • Occasionally supports 3rd party PTaaS vendor penetration tests by provisioning Kali Linux VMs and AMIs within the environment.
  • Facilitates ticket creation for tracking remediation of vulnerabilities and issues found during penetration tests. 
  • Work with external third parties and researchers through Bug Bounty and Responsible Disclosure programs to reproduce submissions, assess organizational risk impact (CVSS, CWE, Enterprise Risk Ranking Impact/Likelihood), and further investigate reported issues. 
  • Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements. 
  • Performs ad hoc security control testing as needed, including remediation testing of previous penetration test findings. 
  • Performs monthly security campaign audits for phishing, password reuse, and password complexity. 
  • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data. 
  • The above job description is not intended to be an all-inclusive list of duties and standards of the position. Qualified candidates will follow instructions and perform other related duties as assigned by their supervisor. 

Minimum Qualifications 

  • Bachelor’s degree in Computer Science, Computer Information Systems, Information Security, Engineering, Math, or related field or equivalent years of professional experience to meet job requirements and expectations. 
  • 4-6 years of professional experience with risk assessment tools, technologies, and methods focused on Information Assurance, Information Systems/Network Security, Infrastructure Design, or Vulnerability Assessments. 
  • Effective knowledge of tools and techniques used to conduct network, wireless, or web application penetration testing. 
  • Effective web application penetration testing and source code review experience.
  • Knowledge of open security testing standards and projects, including OWASP, PCI, & MITRE ATT&CK. 
  • Experience with scripting, editing existing code, and programming (e.g. Python, Bash, Powershell, Golang, .NET, Java, etc.) 
  • Proven ability to use, configure, troubleshoot, and administer *nix, Mac OSX, and Windows operating systems.
  • Experience with vulnerability scanners and Kali Linux associated toolsets included but not limited to InsightVM, Burp Suite Pro/Enterprise, hashcat, nmap, and/or Bloodhound. 
  • Knowledge of application, database, and web server secure design and implementation. 
  • Knowledge of network, web, and cloud application security testing. Red teaming or security operations

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Early Warning

View company profile →