Source Job

$116,920–$175,380/yr
Canada

  • Conduct comprehensive penetration tests across applications, APIs, cloud environments, and infrastructure to identify vulnerabilities.
  • Assess security controls in multi-cloud environments (AWS, GCP) and review Infrastructure as Code configurations.
  • Collaborate with engineering teams to improve security practices and create high-quality technical documentation.

Penetration Testing Cloud Security Web Application Security Python Vulnerability Analysis

20 jobs similar to Senior Security Engineer - Pentester

Jobs ranked by similarity.

India

  • Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
  • Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
  • Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.

The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.

$152,000–$175,000/yr
US Unlimited PTO

  • Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
  • Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.

RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.

$141,000–$221,000/yr
US Unlimited PTO

  • Review system designs and implementations to identify security issues and align with best practices.
  • Develop cloud security architecture and implement automated security testing tools.
  • Promote DevSecOps principles through CI pipeline integration and Infrastructure as Code scanning.

Iterable is the leading AI-powered customer engagement platform that helps brands like Redfin and SeatGeek create dynamic experiences. With nearly 1,200 clients globally and a diverse workforce, we foster a culture of innovation and inclusion, recognized as one of Inc's Best Workplaces.

Germany

  • Perform penetration tests of IT infrastructures, web applications, and web services.
  • Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
  • Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.

SITS Deutschland GmbH is part of the SITS Group, a leading IT security provider offering holistic security solutions. The company has over 700 employees and fosters a culture of appreciation, team spirit, and work-life blending.

$100,000–$150,000/yr
US

  • Design and implement security architectures for Oracle Cloud Infrastructure (OCI) including security zones and access controls.
  • Configure OCI Identity Domains, RBAC, encryption, and key management services.
  • Monitor and respond to security threats using OCI Cloud Guard, SIEM integrations, and vulnerability management.

Oracle is a global technology company specializing in cloud computing and enterprise software. The company employs thousands of professionals worldwide and fosters a collaborative, security-focused culture.

US Unlimited PTO

  • Lead end-to-end penetration testing and red team engagements for customer environments including internal networks, web applications, and cloud infrastructure.
  • Perform in-depth testing with manual techniques to find business-logic flaws and high-impact attack chains that automated tools miss.
  • Deliver high-quality client-ready reports with clear risk ratings, business impact, and practical remediation guidance.

Horizon3 is a fast-growing cybersecurity company whose NodeZero platform delivers autonomous pentests and assessment operations for organizations of all sizes. The team is a fusion of former U.S. Special Operations cyber operators, startup engineers, and cybersecurity practitioners, committed to a culture of respect, collaboration, ownership, and results.

North America Unlimited PTO

  • Identify and validate realistic attack paths across applications and infrastructure.
  • Develop safe proof-of-concept exploits to demonstrate security risks.
  • Partner with engineering teams to validate fixes and improve security posture.

A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.

$155,520–$228,700/yr
US

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps.
  • Conduct internal/external network audits and vulnerability validation.
  • Develop custom exploits, adversary emulation, and AI/LLM security testing.

Twilio is shaping the future of communications by delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide. The company values a remote-first work culture, global inclusion, and diverse experiences.

UK

  • Lead and mentor an internal red team, establishing scalable offensive security practices.
  • Conduct advanced penetration testing and adversarial simulations across cloud infrastructure and AI environments.
  • Research emerging attack techniques and collaborate with detection teams during purple team exercises.

They operate a cutting-edge cloud platform that supports advanced AI workloads. The company is remote-first, emphasizes innovation and continuous improvement, and has a collaborative international team.

$111,155–$150,385/yr
US

  • Design and implement security solutions across AWS, Azure, Google Cloud Platform, and Oracle Cloud Infrastructure.
  • Manage cloud security automation, IAM, compliance frameworks, and vulnerability remediation.
  • Collaborate with DevOps and engineering teams to integrate security into CI/CD pipelines.

This partner company manages applications and next steps for hiring clients. It is a mission-driven technology organization offering collaborative opportunities with AI-powered learning tools and internal development resources.

$140,000–$160,000/yr
US

  • Drive cloud-centric architecture approach for managed services, ensuring security and operational efficiency.
  • Collaborate with stakeholders to design, implement, and automate infrastructure services on Azure/AWS.
  • Document standardized patterns, conduct proof of concepts, and lead executive presentations.

Smile Digital Health provides a FHIR-based data liberation platform for healthcare stakeholders to collect and exchange data. They were #19 on Deloitte's Technology Fast 50 Ranking for 2024 and foster a diverse, inclusive culture.

Global

  • Conduct advanced offensive security research across cloud infrastructure (AWS, GCP), production services, internal tooling, and AI platforms.
  • Design and execute realistic adversary simulations targeting identity systems, cloud control planes, supply chains, and distributed architectures.
  • Research emerging attack vectors against LLMs, AI agents, retrieval systems, MCP integrations, prompt orchestration, and autonomous workflows.

This venture-backed AI company combines world-class human expertise with advanced machine learning workflows to help leading AI organizations build and improve cutting-edge models. Backed by over $40 million in funding and a rapidly expanding international network, it operates as a distributed, remote-first team.

$105,000–$115,000/yr
US

  • Design, deploy, and manage scalable cloud infrastructure across AWS and Azure, including EC2, S3, RDS, and Kubernetes.
  • Automate cloud resources using Terraform, CloudFormation, and PowerShell, while implementing security controls and monitoring.
  • Collaborate with development teams to integrate CI/CD pipelines and support containerized workloads with Docker and Kubernetes.

Mind Computing supports the Department of Veterans Affairs by providing cloud engineering and DevOps solutions. The company fosters a collaborative culture with a focus on security, reliability, and innovation, though the team size is not specified.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

Poland

  • Monitor and investigate security alerts in AWS infrastructure, respond to incidents affecting the product platform.
  • Automate security operations using Python or Go, and configure tools like WAF, GuardDuty, and Security Hub.
  • Collaborate with engineering teams to prioritize vulnerabilities, conduct threat modeling, and guide secure coding practices.

Tripadvisor connects global travelers to experiences worth sharing through its brands, technology, and marketplaces. As a publicly traded company with a portfolio including Viator and TheFork, it fosters a culture of collaboration, trust, and remote-friendly flexibility.

$105,000–$115,000/yr
United States

  • Design, deploy, and manage highly available and secure cloud infrastructure across AWS and Azure.
  • Automate infrastructure provisioning using Terraform, CloudFormation, and ARM templates while implementing CI/CD pipelines.
  • Collaborate with development teams to build cloud-native solutions and ensure operational excellence through monitoring and improvements.

Jobgether is a job matching platform that uses AI-powered technology to connect candidates with employers. They facilitate remote hiring processes and support large-scale technology initiatives with a focus on efficiency and objectivity.

$130,000–$190,000/yr
US

  • Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
  • Partner with engineering teams to validate fixes and implement long-term security improvements.
  • Define and maintain secure SDLC processes, including security reviews and threat modeling.

The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.

$130,000–$160,000/yr
US Unlimited PTO

  • Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
  • Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
  • Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.

Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.