Point your AI agent at freehire and let it find you a job.

Get the CLI →

jobgether

NewBe an early applicant

Senior Security Engineer, Offensive Security

Posted Updated
Discussion

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Offensive Security based in France.

Join a remote-first security team focused on proactively identifying and eliminating threats across products, platforms, and cloud infrastructure. In this role, you will apply offensive security expertise to penetration testing, red teaming, threat modeling, exploit development, and security architecture. You will work closely with engineering, product, and leadership teams to transform security findings into durable improvements and resilient controls. The scope spans cloud environments, containerized infrastructure, SaaS applications, APIs, and emerging AI/ML products. You will also help build scalable security automation and strengthen security programs as the organization grows. This is an opportunity to make a direct impact on the security of products used by millions of developers worldwide.

Accountabilities:

As a Senior Security Engineer, you will combine hands-on offensive security work with strategic security engineering, helping teams identify risks early and embed security into product and infrastructure development.

  • Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises across products and services.
  • Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance.
  • Retest vulnerabilities to validate that remediation has been successfully implemented.
  • Conduct security reviews and threat modeling across application architecture, designs, code, and emerging AI products.
  • Build and maintain offensive security tooling, automation, security tests, and exploit capabilities to expand testing coverage.
  • Partner with engineering teams to design and implement security architecture, controls, Zero Trust practices, and least-privilege access.
  • Support security programs including automated security design reviews and vulnerability management.
  • Investigate security events, participate in incident response, and contribute to a rotating on-call schedule.
  • Collaborate with product, engineering, and other stakeholders to promote security-by-design practices.
  • Contribute to security roadmaps, monitoring improvements, anomaly detection, compliance initiatives, and security documentation.
  • Own recurring penetration tests and adversary-emulation activities while engaging with external security researchers where appropriate.
  • Help strengthen security practices for cloud infrastructure, containerized environments, and AI/ML systems.
  • Requirements:

    The ideal candidate combines strong hands-on offensive security capabilities with software development expertise, cloud security knowledge, and the ability to influence security practices across technical and non-technical teams.

    • 3+ years of experience in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
    • 2+ years of hands-on software development experience with Python or Golang.
    • Deep knowledge of authentication and authorization, including OAuth, applied cryptography, and Zero Trust principles.
    • Strong practical experience securing cloud environments such as AWS, GCP, or Azure.
    • Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.
    • Proficiency with offensive security tools and techniques, including Burp Suite and OWASP frameworks.
    • Ability to develop security tests, exploits, and proof-of-concepts that identify real-world vulnerabilities.
    • Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
    • Practical experience using LLMs and agentic tools to automate vulnerability discovery, reconnaissance, and penetration testing workflows.
    • Experience building security programs and automation from the ground up using risk-based prioritization.
    • Experience performing security reviews and developing or improving automated security review processes.
    • Excellent communication skills and the ability to explain complex security concepts to both technical and non-technical stakeholders.
    • Strong understanding of security standards and a commitment to keeping up with emerging security technologies and models.
    • Collaborative mindset with the ability to drive security improvements through cross-functional partnerships.
    • Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO are valued.
    • Published CVEs, original security research, or conference presentations are a plus.
    • Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing is advantageous.
    • Ability to work remotely and operate effectively with a high degree of autonomy.
    • This position does not offer visa sponsorship.
    • Benefits:

      • Fully remote, remote-first working environment.
      • EU compensation of €118,860–€169,800, plus equity.
      • Flexible scheduling designed to support autonomy and work-life balance.
      • Generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.
      • Home office support to help create a comfortable and effective workspace.
      • Technology stipend equivalent to US$100 net per month.
      • Annual learning and development stipend for conferences, courses, certifications, and professional development.
      • 16 weeks of paid parental leave after six months of employment.
      • Equity for all full-time employees.
      • Comprehensive medical, retirement, and paid holiday benefits, varying by country.
      • Opportunity to work on security challenges spanning cloud infrastructure, containers, AI/ML, and large-scale developer platforms.
      • Offices available in Seattle and Paris for connection and collaboration when relevant.
      • Company merchandise and team perks.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available