Jobgether
Jobgether

Offensive Security Engineer (Red Team)

engineeringfull-timeCanada
SALARY
$146k – $190k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Plan and execute red team operations, adversary simulations, penetration tests, and targeted offensive security assessments across cloud environments.

    • Evaluate the security posture of cloud infrastructure, identity architectures, CI/CD pipelines, containerized workloads, and cloud-native services.

    • Identify and validate realistic attack paths involving IAM misconfigurations, excessive privileges, exposed secrets, metadata services, insecure automation, and cloud configuration weaknesses.

    • Conduct security assessments designed to replicate relevant attacker behaviors and techniques in modern enterprise environments.

    • Validate the effectiveness of security monitoring and detection capabilities by testing logging, alerting, monitoring, and incident-response processes.

    • Partner with blue team and detection engineering functions to identify gaps in defensive coverage and improve detection and response capabilities.

    • Document vulnerabilities, attack paths, and security weaknesses in concise, actionable reports.

    • Work with software and engineering teams to communicate findings, support remediation efforts, and help reduce security risk.

    • Track emerging attacker tactics, cloud exploitation techniques, and new abuse paths that could affect cloud-native environments.

    • Map offensive security findings and adversary behaviors to established frameworks such as MITRE ATT&CK.

    • Serve as a trusted security partner to engineering teams, helping strengthen security practices through practical offensive expertise.

    • Requirements:

      • 5+ years of professional experience in offensive security, red teaming, penetration testing, detection validation, or closely related security disciplines.

      • Strong understanding of adversary tactics, techniques, and procedures, with the ability to apply them to realistic security assessments.

      • Experience conducting offensive security assessments in cloud environments and evaluating modern cloud infrastructure and services.

      • Practical understanding of cloud identity and access management, CI/CD security, containers, secrets management, and cloud-native architectures.

      • Ability to identify and validate complex attack paths involving IAM weaknesses, overprivileged identities, exposed credentials or secrets, metadata services, insecure automation, and configuration issues.

      • Experience evaluating security monitoring and detection capabilities through adversary simulation or detection-validation exercises.

      • Ability to map findings and attacker behavior to frameworks such as MITRE ATT&CK.

      • Strong written and verbal communication skills, including the ability to explain complex technical security issues to engineering teams and other stakeholders.

      • Ability to produce concise, actionable security reports that clearly communicate technical findings, business relevance, and remediation considerations.

      • Strong analytical and investigative mindset with a willingness to explore emerging attack techniques and unfamiliar technologies.

      • Relevant industry certifications such as OSCP, OSEP, GXPN, GPEN, or recognized cloud security certifications are valued.

      • Ability to work effectively in a remote environment and collaborate across technical and security teams.

      • Authorization to work in Canada and meet applicable requirements for accessing controlled technologies and commodities.

      • Benefits:

        • Competitive annual compensation range of CAD $146,000–$190,000, depending on location and factors such as education, professional experience, and certifications.

        • Potential eligibility for restricted stock units as part of total compensation.

        • Health and pharmacy benefits.

        • Optical and dental coverage.

        • Paid time off and sick time off.

        • Short-term and long-term disability coverage.

        • Life insurance.

        • Employer-supported retirement contributions, subject to eligibility.

        • Fully remote work arrangement within Canada.

        • Opportunity to work on cloud security, adversary simulation, and modern offensive security challenges.

        • Collaborative environment involving Product Security, engineering, blue team, and detection engineering professionals.

        • Opportunities to develop expertise in emerging attacker techniques and cloud exploitation trends.

        • Inclusive workplace committed to diverse backgrounds, experiences, abilities, and perspectives.

        • Potential for occasional in-person interviews or new-hire training sessions at global offices.

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Offensive Security Engineer (Red Team) at Jobgether — Remote