Senior Security Engineer – Pentester

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Menlo Security Inc.

Menlo Security Inc.

201 - 500 employees

🔒 Cybersecurity

🏢 Enterprise

💰 $100M Series E on 2020-11

Cybersecurity • Enterprise

Menlo Security Inc. is a cybersecurity company focused on providing advanced internet security solutions for enterprises. They specialize in securing browsers across hybrid enterprise environments to prevent phishing and malware attacks. Menlo Security offers a cloud-based browser security solution that transforms any browser into a secure enterprise browser, helping organizations protect against highly evasive adaptive threats, zero-hour phishing, and ransomware. Their zero-trust access architecture enables safe internet use and secure application access, supporting over 800 customers globally, including financial institutions and government agencies.

📋 Description

• Conduct deep-dive penetration tests of products across AWS and GCP environments, working with a peer pentester • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane against security baselines • Execute dynamic testing against web interfaces and API endpoints across the Data Plane and Web UI • Assess the security posture of hybrid infrastructure spanning containers and virtual machines • Triage findings and create clear, reproducible proofs of concept • Partner with product teams to explain risk and drive remediation • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports • Monitor bug bounty pipelines and external reports, validate findings, and manage researcher communication • Ensure product features and multi-cloud infrastructure are rigorously security-tested before release • Track assessment coverage, triage speed, vulnerability escape rates, AI-assisted time savings, and report quality

🎯 Requirements

• Deep architectural understanding of GCP and AWS • Ability to perform manual reviews of complex IAM and resource hierarchies • Experience with native cloud APIs or CSPM frameworks • Proven experience auditing and hardening GKE Autopilot/Standard, EKS, ECS, Kubernetes, k3s, and OCI-runc workloads • Demonstrated ability to integrate AI/LLM tools such as Gemini and Claude into the pentesting lifecycle • Expert knowledge of web application security and offensive testing methodologies • Deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and REST/WebSocket API security • Extensive hands-on experience with Burp Suite Professional, OWASP ZAP, or similar tools • Understanding of CSP, CORS, SameSite cookies, Subresource Integrity, OAuth 2.0, OIDC, JWT, HSTS, X-Frame-Options, and Permissions-Policy • Ability to identify complex flaws beyond automated scanners and validate them with proofs of concept • Proficiency in Python, Go, or Bash • Solid grasp of Terraform, cloud-native deployment patterns, and HCL auditing • Ability to write high-quality technical reports for product teams • Experience with Gatekeeper policies and Binary Authorization is preferred

🏖️ Benefits

• Base salary range of 158,000 CAD - 237,000 CAD • Eligibility for stock-based compensation grants based on company and individual performance • Collaborative, inclusive, and fun culture • Opportunities to take initiative and implement new ideas • Open communication and support for new ideas

Apply Now

Similar Jobs

🕒 3 days ago

BMO U.S.

5001 - 10000

🛡️ Insurance

💼 Consulting

📦 Logistics

Senior Network and Cloud Penetration Tester responsible for executing security testing and overseeing vulnerabilities. Engaging across the full lifecycle with a focus on high-quality engagements.

🕒 4 days ago

Sedgwick

10,000+ employees

🏗️ Construction

💼 Consulting

🏥 Healthcare

Quality Assurance Specialist assessing data quality and performance of investigative service partners. Collaborating with stakeholders to ensure compliance and optimal service delivery.

🇨🇦 Canada – Remote

💵 $47.1k - $75.4k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔧 QA Engineer (Quality Assurance)

🕒 5 days ago

Push Operations

51 - 200

🏥 Healthcare

🏨 Hospitality

🍽️ Food & Beverage

Software Engineer in Testing at Push Operations responsible for quality assurance and test automation. Collaborating with teams to enhance QA workflows and improve product quality.

🕒 6 days ago

Symphony Talent

201 - 500

👥 HR Tech

🎯 Recruiter

☁️ SaaS

Dev Tester role at a company focused on testing. Engaging in various testing tasks as defined.

🕒 6 days ago

1VALET

51 - 200

🛍️ eCommerce

🔧 Hardware

🏠 Real Estate

Quality Assurance Engineer at 1VALET ensuring quality and performance of hardware and software products. Collaborating with engineering and operations teams to validate new products and troubleshoot issues.