Senior Offensive Security Engineer

Chime Chime · Fintech · San Francisco, CA · Security

Senior Offensive Security Engineer to build and lead the Offensive Security program, attacking Chime's services, applications, and infrastructure to discover and report security issues. Responsibilities include managing red team exercises, researching attack vectors, developing custom payloads and exploits, and collaborating with detection engineers.

What you'd actually do

  1. Independently manage complete red team exercises.
  2. Partner with Engineering, Product, IT, and other business functions to drive security improvement across the organization
  3. Research emerging attack vectors, vulnerabilities and techniques
  4. Utilize your offensive skills to identify weaknesses and build defenses against those who may point their attacks at Chime
  5. Develop custom payloads and exploits

Skills

Required

  • 4+ years of combined experience in either an offensive security, red teaming, or application security role.
  • Experience in conducting surreptitious cloud based attacks
  • Experience with developing custom tools and payloads which bypass defensive products, and remain undetected in a mature network environment
  • Ability to perform unsupervised red team engagements and experience with performing adversarial simulation
  • Ability to explain vulnerabilities and weaknesses to non-technical stakeholders

Nice to have

  • OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert) and OSEE (Offensive Security Exploitation Expert), Certified Red Team Operator (CRTO), GIAC Red Team Professional certification (GRTP)

What the JD emphasized

  • offensive cybersecurity professional
  • analyzing codebases
  • testing hypotheses
  • designing tools
  • technical leadership
  • emerging attack vectors
  • custom payloads and exploits
  • bypass defensive products
  • remain undetected