Security Engineer (red Team)

Glean Glean · Enterprise · Engineering

This role is for a Security Engineer (Red Team) at Glean, an AI-powered knowledge management platform. The engineer will focus on ethical hacking, penetration testing, and social engineering to identify and expose security weaknesses within the company's systems. Responsibilities include conducting penetration tests, designing social engineering attacks, developing assumed breach scenarios, and collaborating with blue teams to recommend remediation strategies. The role requires experience in scripting, penetration testing frameworks, and a strong understanding of security principles. While the company is AI-focused, this specific role is not directly involved in building or deploying AI models.

What you'd actually do

  1. Conduct network penetration testing, employing various techniques like exploiting vulnerabilities, bypassing defenses, and escalating privileges.
  2. Design and execute targeted social engineering attacks to test human vulnerabilities and security awareness.
  3. Develop assumed breach scenarios that mimic real-world attacks, testing our incident response procedures and readiness.
  4. Utilize penetration testing frameworks like Metasploit, Kali Linux, and Burp Suite, constantly updating your knowledge and exploring new tools.
  5. Collaborate with blue teams, developers, and stakeholders to communicate findings, prioritize vulnerabilities, and recommend remediation strategies.

Skills

Required

  • Experience with social engineering techniques and methodologies.
  • Proficiency in scripting languages like Python and Bash.
  • Excellent communication and teamwork skills, able to explain complex technical concepts to both technical and non-technical audiences.

Nice to have

  • Familiarity with cloud native development practices in GCP/AWS/Azure is a plus
  • Bonus points for experience with cloud security, web application security, and post-exploitation frameworks.
  • Masters in Information Security a big plus.

What the JD emphasized

  • ethical adversary
  • expose our weaknesses
  • customer-focused, tight-nit and cross-functional environment - being a team player and willing to take on whatever is most impactful for the company is a must