Senior Security Engineer, Offensive Security
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Offensive Security based in France.
Join a remote-first security team focused on proactively identifying and eliminating threats across products, platforms, and cloud infrastructure. In this role, you will apply offensive security expertise to penetration testing, red teaming, threat modeling, exploit development, and security architecture. You will work closely with engineering, product, and leadership teams to transform security findings into durable improvements and resilient controls. The scope spans cloud environments, containerized infrastructure, SaaS applications, APIs, and emerging AI/ML products. You will also help build scalable security automation and strengthen security programs as the organization grows. This is an opportunity to make a direct impact on the security of products used by millions of developers worldwide.
Accountabilities:
As a Senior Security Engineer, you will combine hands-on offensive security work with strategic security engineering, helping teams identify risks early and embed security into product and infrastructure development.
- Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises across products and services.
- Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance.
- Retest vulnerabilities to validate that remediation has been successfully implemented.
- Conduct security reviews and threat modeling across application architecture, designs, code, and emerging AI products.
- Build and maintain offensive security tooling, automation, security tests, and exploit capabilities to expand testing coverage.
- Partner with engineering teams to design and implement security architecture, controls, Zero Trust practices, and least-privilege access.
- Support security programs including automated security design reviews and vulnerability management.
- Investigate security events, participate in incident response, and contribute to a rotating on-call schedule.
- Collaborate with product, engineering, and other stakeholders to promote security-by-design practices.
- Contribute to security roadmaps, monitoring improvements, anomaly detection, compliance initiatives, and security documentation.
- Own recurring penetration tests and adversary-emulation activities while engaging with external security researchers where appropriate.
- Help strengthen security practices for cloud infrastructure, containerized environments, and AI/ML systems.
- 3+ years of experience in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
- 2+ years of hands-on software development experience with Python or Golang.
- Deep knowledge of authentication and authorization, including OAuth, applied cryptography, and Zero Trust principles.
- Strong practical experience securing cloud environments such as AWS, GCP, or Azure.
- Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.
- Proficiency with offensive security tools and techniques, including Burp Suite and OWASP frameworks.
- Ability to develop security tests, exploits, and proof-of-concepts that identify real-world vulnerabilities.
- Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
- Practical experience using LLMs and agentic tools to automate vulnerability discovery, reconnaissance, and penetration testing workflows.
- Experience building security programs and automation from the ground up using risk-based prioritization.
- Experience performing security reviews and developing or improving automated security review processes.
- Excellent communication skills and the ability to explain complex security concepts to both technical and non-technical stakeholders.
- Strong understanding of security standards and a commitment to keeping up with emerging security technologies and models.
- Collaborative mindset with the ability to drive security improvements through cross-functional partnerships.
- Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO are valued.
- Published CVEs, original security research, or conference presentations are a plus.
- Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing is advantageous.
- Ability to work remotely and operate effectively with a high degree of autonomy.
- This position does not offer visa sponsorship.
- Fully remote, remote-first working environment.
- EU compensation of €118,860–€169,800, plus equity.
- Flexible scheduling designed to support autonomy and work-life balance.
- Generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.
- Home office support to help create a comfortable and effective workspace.
- Technology stipend equivalent to US$100 net per month.
- Annual learning and development stipend for conferences, courses, certifications, and professional development.
- 16 weeks of paid parental leave after six months of employment.
- Equity for all full-time employees.
- Comprehensive medical, retirement, and paid holiday benefits, varying by country.
- Opportunity to work on security challenges spanning cloud infrastructure, containers, AI/ML, and large-scale developer platforms.
- Offices available in Seattle and Paris for connection and collaboration when relevant.
- Company merchandise and team perks.
Requirements:
The ideal candidate combines strong hands-on offensive security capabilities with software development expertise, cloud security knowledge, and the ability to influence security practices across technical and non-technical teams.
Benefits:
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company