Senior Offensive Security Engineer

Anduril Anduril · Defense · Washington, DC · Corporate Technology : Information Security : Offensive Security

Anduril Industries is a defense technology company seeking a Senior Security Engineer, Offensive Security to join their Product Security organization. The role involves assessing the security posture of software, hardware, and firmware, providing expertise on attack vectors, and building capabilities for red team projects. The ideal candidate has a background in software or systems engineering with a pivot to product or offensive security, and experience with modern threats and exploits. The company utilizes an AI-powered operating system and focuses on autonomy, AI, computer vision, sensor fusion, and networking technology for military applications.

What you'd actually do

  1. Assesses security posture of both Anduril built software, hardware and firmware as well as the third party components used in our products
  2. Provides expertise to other Anduril teams on real-world attack vectors and works with appropriate team members to implement and test mitigations
  3. Plans for, builds and maintains capabilities needed to execute red team projects

Skills

Required

  • Experience assessing the security posture of everything from web applications to hardware and embedded systems
  • Experience leading offensive security engagements
  • Experience with assessment of cloud based and containerized environments (AWS, Azure, Kubernetes)
  • Experience assessing and improving the the security of mobile devices (Android and/or iOS)
  • Experience with one or more programming languages (e.g. Rust, C/C++, Golang, Swift)
  • Strong and professional communication skills (written and verbal)
  • Eligible to obtain and maintain an active U.S. Secret security clearance

Nice to have

  • Experience building custom tooling to assist in offensive security activities
  • Experience weaponizing vulnerabilities to provide unique capabilities
  • Familiarity with security architectures of robot platforms (consumer or otherwise), aerospace, and physical systems
  • Experience developing features for and improving security of mobile applications, networks, or embedded systems
  • Familiarity with mobile device exploitation techniques
  • Familiarity with anti-tamper and reverse engineering mechanisms
  • Regularly builds, tests, and delivers production-ready systems, especially for embedded and/or mobile

What the JD emphasized

  • Eligible to obtain and maintain an active U.S. Secret security clearance