Source Job

$109,500–$142,500/yr
Canada

  • Plan and execute red team operations and adversary simulations focused on cloud environments.
  • Evaluate security of cloud infrastructure, identity architectures, CI/CD pipelines, and containerized workloads.
  • Assess detection and response coverage with blue team and detection engineering.

Offensive Security Penetration Testing Red Teaming Cloud Security

20 jobs similar to Offensive Security Engineer (Red Team)

Jobs ranked by similarity.

$108,040–$140,600/yr
Canada

  • Plan and execute red team operations, adversary simulations, and targeted security assessments focused on cloud environments.
  • Evaluate the security of cloud infrastructure, identity architectures, CI/CD pipelines, and containerized workloads.
  • Identify and validate attack paths involving IAM misconfigurations, overprivileged roles, and secrets exposure.

We empower the people who run physical operations with tools to make their work safer, more productive, and more profitable. We serve nearly 100,000 customers across industries, from Fortune 500 enterprises to small businesses, fostering a diverse and inclusive workplace.

$165,000–$200,000/yr
US Unlimited PTO

  • Lead the long-term technical strategy for offensive security, including red teaming and adversary simulations.
  • Conduct deep-dive vulnerability research and partner with DevOps to build automated security guardrails.
  • Mentor senior and mid-level engineers to foster a security-minded development culture.

Greenlight is a family technology company that helps families raise financially smart kids through its suite of products including the Greenlight app, debit card, and safety features. With over 6.5 million family members, Greenlight fosters a culture of innovation and collaboration to make family life easier.

$105,100–$231,100/yr
US

  • Serve as the senior technical authority for penetration testing and red-team delivery across federal programs.
  • Define and improve assessment standards, rules of engagement, and technical methodologies.
  • Guide technical teams, mentor staff, and communicate findings to government customers.

The company provides offensive security assessments and red-team services for sensitive federal cyber environments. The team is remote and focuses on high-impact national cybersecurity missions.

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Plan and execute realistic adversary simulations using threat intelligence to assess security and detection capabilities.
  • Hunt for vulnerabilities across AI systems, payment infrastructure, autonomous delivery hardware, and emerging technologies.
  • Build custom tools, exploits, and payloads tailored to DoorDash's tech stack and partner with Blue Teams.

DoorDash is a technology and logistics company that empowers local economies by enabling door-to-door delivery for consumers, merchants, and Dashers. The company is growing rapidly and constantly changing, with a culture focused on empathy, diversity, and employee well-being.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

$110,000–$145,000/yr
US

  • Design, deploy, and maintain Microsoft cloud security technologies including Purview, Defender for Cloud, and Entra ID.
  • Apply a red-team mindset to identify weaknesses and improve security posture.
  • Act as a trusted security advisor to internal teams and customers on governance and data protection.

Patch My PC provides an enterprise solution for automating and managing third-party updates in Microsoft ConfigMgr, Intune, and WSUS. The fully remote crew of 150 GIF-loving humans supports over 10,000 customers and more than 32 million devices.

$110,095–$156,603/yr
US

  • Design and oversee cloud computing strategy, including adoption plans, application architecture, and system management.
  • Lead cloud implementation projects on IaaS and PaaS, collaborating with Cloud Service Providers like CloudOne and DAF CloudWorks.
  • Optimize cloud performance, enforce security compliance, and serve as a customer liaison for technical requirements.

Defense technology platform delivering high-impact technologies, technology-enabled services, and advanced manufacturing to U.S. national security customers. Backed by Falfurrias Management Partners, it combines deep domain expertise across military programs into a scalable aerospace and defense enterprise.

$116,019–$145,024/yr
US 4w PTO 4w maternity 4w paternity

  • Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
  • Perform security assessments, vulnerability remediation, and lead key security programs.
  • Automate security processes and integrate DevSec practices into the software development lifecycle.

Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.

US

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
  • Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.

Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

Canada

  • Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
  • Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.

LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.

$135,000–$155,000/yr
US

  • Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
  • Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
  • Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.

The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.

$175,000–$200,000/yr
US Canada Unlimited PTO

  • Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
  • Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
  • Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.

Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.

US

  • Design adversarial prompts to test AI models for offensive security capabilities.
  • Evaluate model-generated code for functional correctness and real-world exploitability.
  • Test model behavior across cybersecurity categories like malware, exploitation, and social engineering.

Handshake is a career platform that helps everyone find a path to a great career. They support 25 million job seekers, over 1 million employers, and 1,600 educational institutions.

United States

  • Design and build security for future infrastructure, partnering with engineering and compliance teams.
  • Lead AI-native security initiatives, designing autonomous agents for threat detection and incident response.
  • Devise defense-in-depth frameworks, research threats, and maintain KPIs for a healthy cloud security program.

WeightWatchers is a global digital health company that blends science and community to help millions build sustainable healthy habits. The engineering team drives transformative change through technology, with a culture that thrives on urgency, collaboration, and passion for impactful work.

$160,000–$180,000/yr
US

  • Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
  • Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
  • Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.

Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.

US Unlimited PTO

  • Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
  • Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
  • Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.

DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.

$115,000–$150,000/yr

  • Manage day-to-day security operational availability and supportability of a 24x7x365 infrastructure.
  • Make recommendations on enhancements to security hardware, software, and tools, and perform risk analysis.
  • Configure, implement, monitor, and support security software/systems including firewalls, VPNs, IDS/IPS, DLP, etc.

eMoney Advisor is a wealth management system that offers transparency, security, mobile access, and superior organization. We serve more than 109,000 financial professionals and support over 6 million end clients, fostering a culture that values diversity and inclusion.

US

  • Own security of the software build and release pipeline, cloud environments, and AWS identity and access.
  • Operationalize a 15-domain cloud security framework and CrowdStrike CSPM across all AWS estates.
  • Mentor a junior cloud security engineer and build paved-road patterns for engineering teams.

Vermont Information Processing is a leading beverage industry technology provider trusted by over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security with executive sponsorship and a funded roadmap.