Jobiba hiring network

Offensive Security Manager Jobs

35 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current offensive security manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.

T
Twilio
📍 - US• Full-time• Remote• From $155.5K/yr
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Staff Offensive Security Engineer. About the job The Staff Engineer acts as a Technical Lead. You don't just find bugs; you design complex attack chains that demonstrate systemic risk. You spend as much time writing custom code and researching new bypasses as you do executing tests. Responsibilities In this role, you’ll: Full-Stack Penetration Testing: Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android). Internal/External Network Audits: Conduct network and cloud level assessments with various tooling Vulnerability Validation: Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives AI/LLM Probing: Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs). Technical Reporting: Draft high-quality reports that detail

REMOTEpythonsqlaws
View job →
D
Datadog
📍 New York• Full-time• From $195K/yr
1mo ago

Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations continuously across a massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking for a Senior Security Engineer who can execute sophisticated red team operations, write the code that scales them, and take an AI-first approach to offensive security engineering. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Plan and execute red team engagements end-to-end, simulating real-world threat actors across cloud infrastructure (AWS, GCP), Kubernetes, CI/CD pipelines, and corporate environments Build and maintain custom offensive tooling, automation frameworks, and engagement infrastructure, treating offensive operations as a software engineering problem Develop custom payloads and evasion capabilities tailored to Datadog's environment and modern defensive controls (EDR, SIEM, network monitoring) Improve the efficiency of offensive operations through thoughtful use of automation and AI, accelerating reconnaissance, vulnerability analysis, and reporting workflows Partner with the Detection & Response team on purple team exercises to validate detection logic, improve alert fidelity, and influence threat models Translate offensive findings into concrete improvements by working directly with defensive security and engineering teams to close gaps Who You Are: You have 5+ years of hands-on experience in offensive security (red teaming, penetration testing, or adversary simulation) with a track record of operating against mature, well-defended environments You write production-quality code (Python, Go, or similar), can build your own tools, and automate your w

pythonawsazure
View job →

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Director of Engineering for the Application, Cloud and Offensive security teams in the Security Engineering organization. Snowflake is the AI Data Cloud powering enterprises worldwide to store, process, and build intelligent applications on their most sensitive data. As AI has become more deeply embedded in what Snowflake and its customers do, the threat landscape has evolved at the same pace. This Director role was created directly in response to that convergence: a wide mandate with real influence across three security pillars and the visibility to shape how one of the most consequential technology platforms in the world stays ahead of emerging threats. AS A DIRECTOR OF ENGINEERING AT SNOWFLAKE, YOU WILL: Define and execute the security strategy across three core pillars: application security, cloud security assurance, and offensive security (including the red team program), setting direction and driving measurable outcomes across all three pillars. Build and develop a high-performing security engineering organization, hiring top talent and creating a culture of rigor, ownership, and continuous improvement Drive the offensive security program including red team operations, adversarial simulations, and proactive threat modeling to stay ahead of emerging att

awsazuregcp
View job →
S
15 days ago

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture. We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer. The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia. What you'll do As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships,

pythonawsazure
View job →
F
Figma
📍 Ca New York• Full-time• From $153K/yr
1mo ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are hiring for multiple teams within Security Engineering: AI Security, Platform Security, Product Security, and Anti-Abuse. This is a remote first role. You will partner closely with teams across the company and focus on systemic security improvements and risk reduction. You will also participate in operational security responsibilities like security reviews, consulting, vulnerability triage, and security incident response. Examples of what you may work on across teams: AI Security Perform technical security assessments, code audits, and design reviews for new AI infrastructure, platforms, and products. Design and develop technical solutions to secure AI models, tooling, debugging workflows, and data pipelines. Advocate for secure practices across Figma’s AI infrastructure, platforms, and data systems. Build the next generation of internal AI-powered access insights and security tooling. Help run penetration testing and offensive security exercises against Figma’s AI infrastructure, platforms, and products. Platform Security Perform technical security assessments, code audits, and design reviews for changes to Figma’s cloud and corporate infrastructure. Design and develop solutions to prevent or mitigate cloud and corporate security risks. Advocate for secure practices within Figma’s cloud and corporate infrastructure. Build platforms and tooling t

I
Instacart
📍 Canada - Remote (ON, BC• Full-time• Remote• From C$196K/yr
1mo ago

We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers. Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table. Instacart is a Flex First team There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work. Overview About the Role - You will be a key member of the Security Engineering team that is tasked with researching, developing, and conducting offensive security techniques for a suite of Instacart products. We are looking for a breaker mindset security engineer who can scale out the discovery of security defects and anti-patterns to mature the security posture of Instacart product lines.. About the Team -The security team at Instacart is tasked with ensuring the security and privacy of Instacart’s suite of products and the company as a whole. We believe that with the right mixture of tools and engineering prowess, we can secure our most important assets without negatively impacting productivity. We pride ourselves on fostering a collaborative and inclusive environment where continuous learning and growth are encouraged. About the Job Design and conduct offe

REMOTEaigo
View job →
I
Instacart
📍 United States - Remote• Full-time• Remote• From $230K/yr
1mo ago

We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers. Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table. Instacart is a Flex First team There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work. Overview About the Role - You will be a key member of the Security Engineering team that is tasked with researching, developing, and conducting offensive security techniques for a suite of Instacart products. We are looking for a breaker mindset security engineer who can scale out the discovery of security defects and anti-patterns to mature the security posture of Instacart product lines.. About the Team -The security team at Instacart is tasked with ensuring the security and privacy of Instacart’s suite of products and the company as a whole. We believe that with the right mixture of tools and engineering prowess, we can secure our most important assets without negatively impacting productivity. We pride ourselves on fostering a collaborative and inclusive environment where continuous learning and growth are encouraged. About the Job Design and conduct offe

REMOTEaigo
View job →
A
1mo ago

At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations. We are looking for a collaborative, innovative Group Tech Lead to join our security organization in Warsaw. This is a senior technical leadership role that sits at the intersection of offensive and defensive security — a true purple team visionary who will design and drive Asana's threat operations strategy from the ground up. You will set the long-term technical direction for how we detect, emulate, respond to, and continuously improve our defences against real-world adversaries. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve Purple Team Strategy & Technical Leadership: Define and own the technical strategy for a fully integrated purple team function, bridging offensive (red team) and defensive (blue team) capabilities into a cohesive, intelligence-driven program. Adversary Emulation: Design and implement a structured adversary emulation programme based on real threat intelligence, ensuring red team exercises directly improve blue team detection and response playbooks while establishing continuous feedback loops. Security Maturity & Industry Standards: Lead Asana's security maturity journey, defining a roadmap that progressively advances capabilities toward frameworks and standards such as NIST CSF, ISO 27001, SOC 2, and MITRE ATT&CK maturity l

pythonrestmachine learning
View job →
O
Okta
📍 Washington• Full-time• From $180K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. The Security Team Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences. Join our team! We're building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale. This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOT

typescriptpythonjava
View job →

Senior Offensive Cybersecurity Test Analyst Company: The Boeing Company The Boeing Company is seeking a Senior Offensive Cybersecurity Test Analyst to support the Boeing Test & Evaluation (BT&E) cyber test capability. The selected applicant will join a highly technical Test & Evaluation team building an offensive cyber test capability in Berkeley, MO . This position will be providing testing services to Boeing Defense Space & Security (BDS) portfolio. The primary responsibilities will include Product Security (Cyber) test planning, integration, and execution, mission-based risk assessments, vulnerability assessments, and penetration tests. The selected applicant will become a Berkeley team member trained across the broader BT&E Product Security Capability team. Position Responsibilities: Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner on embedded systems and IP-based networks Subject Matter Expert for emulating advanced cyber adversary (advanced persistent threats) tactics, techniques and procedures (TTPs) Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches</span

pythonlinuxrecruitment
View job →
O
OpenAI
📍 San Francisco• Full-time
1mo ago

About the Team Our Safety Systems team is at the forefront of OpenAI's mission to build and deploy safe AGI, driving our commitment to AI safety and fostering a culture of trust and transparency. Within Safety Systems, the Model Policy team aligns model behavior with desired human values and norms. We co-design policy with models and for models by driving rapid policy taxonomy iteration based on data and defining evaluation criteria for foundational models’ ability to reason about safety. About the Role Frontier AI systems are rapidly expanding what is possible in cybersecurity and software engineering. These capabilities create major defensive opportunities, but they also raise serious dual-use and misuse risks across areas such as malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations. In this role, you will help define how OpenAI’s models should behave in high-risk cybersecurity contexts. You will develop policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications that guide model behavior across training, deployment, and monitoring systems. This role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation. You will work closely with research, engineering, safety training, preparedness, and product teams to build policies that are technically grounded, measurable, enforceable, and responsive to real-world cyber risk. Your Responsibilities: Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities. Translate cybersecurity threat models into clear behavioral specifications, evaluation criteria, grading guidance, and system-level mitigations. Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity. Build policy artifacts that support i

awsgitrest
View job →
SI
SixGen, Inc.
📍 Ft Meade• Full-time• $185K – $196K/yr
14 days ago

Principal Targeting Analyst Target development for cyber operations, red-team engagements, and applied R&D Position Overview: Position: Principal Targeting Analyst Job Type: Full-time Location: Ft. Meade, MD (Hybrid) Clearance Requirements: US Citizen &TS/SCI Experience: 8+ years What You'll Do SIXGEN is seeking a Principal Targeting Analyst to build and lead an organic targeting and collection capability that strengthens our offensive cyber, red-team, and adversary-emulation missions. This is a hands-on technical leadership role for an analyst-engineer hybrid who enjoys solving hard collection problems, developing targets from a cold start, and turning operational experience into automated, mission-ready capability. As a Principal Targeting Analyst, you'll pair deep OSINT and managed-attribution tradecraft with professional foreign-language proficiency, applied AI engineering, and real software-development ability. You'll partner with operators, engineers, and program teams to deliver timely targeting and access intelligence, mature SIXGEN's collection methodologies and tooling, and mentor analysts as the capability grows. Whether you're developing a target for a critical customer mission, automating collection at scale, or shaping the technical direction of a new capability, your operational credibility and technical judgment will help drive mission success across the organization. Key Responsibilities Target Development and Key Operations Conduct end-to-end target development against threat actors, and adversary infrastructure — from initial requirement through finished, decision-ready intelligence. Direct collection across the surface, deep, and dark web, closed forums, encrypted messaging platforms, and regional ecosystems beyond the coverage of commercial data sources. Perform authorized threat-actor engagement and elicitation; track initial-access brokers, exploit sellers, and access markets relevant to mission objectives. Conduct

javascripttypescriptpython
View job →

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. Roblox’s Safety Operations team is dedicated to protecting our users from bad actors. The Critical Harms Investigations & Incident Management (CHIIMS) team applies subject matter expertise to our highest-level risks, working closely with cross-functional partners. As part of our commitment to safety, we are looking for a Junior Specialist with an investigator’s mindset, skills, and curiosity to investigate and respond to some of our highest-risk escalations. You will work with teams and leaders across the company to quickly and professionally respond to urgent requests for support, and balance competing priorities to get the job done. You will share findings with internal partners to help identify and mitigate risks across the platform. Please Note: This role may review graphic, controversial, and sometimes offensive content in line with Roblox’s content moderation practices. You Will: Incident Investigation and Triage Support, then lead, rapid investigations into critical and complex incidents, including but not limited to threats against child safety, violent extremism, and other high-severity harms. Utilize internal tools, data analysis, and open-source inte

project management
View job →

Senior Malware Analyst (Media, Malware, and Analysis – MMA) US CITIZEN ONLY Job Type Full-time Location Annopolis Junction, MD Clearance Requirement TS/SCI with CI polygraph Position Description The Senior Malware Analyst provides advanced technical expertise in malware analysis, digital forensics, and cyber threat intelligence in support of USCYBERCOM cyberspace operations. This role directly supports operations across USCYBERCOM J3, Cyber National Mission Force (CNMF), and Joint Task Force-Ares (JTF-ARES), delivering critical insights into adversary tactics, techniques, and procedures (TTPs) targeting the Department of Defense Information Network (DODIN) and associated mission systems. The analyst performs deep technical analysis of malicious code, compromised systems, and digital media to identify threats, develop mitigation strategies, and enhance operational situational awareness. This position contributes to mission assurance, defensive cyberspace operations (DCO), and offensive cyberspace operations (OCO) by enabling timely, actionable intelligence and supporting enterprise cyber defense and exploitation capabilities. Key Responsibilities Conduct static and dynamic malware analysis , reverse engineering, and forensic examination of compromised systems and digital media to identify adversary TTPs and intrusion artifacts. Perform media exploitation and forensic analysis , including extraction and analysis of malicious files, logs, and system artifacts across Windows, UNIX/Linux, and network environments. Develop and disseminate technical intelligence reports, threat briefs, and executive summaries to support operational decision-making and leadership awareness. Identify and develop indicators of compromise (IOCs) , signatures, heuristics, and MD5 hash repositories to support detection and mitigation strategies. Analyze and correlate cyber threat intelligence (all-source, SIGINT, and technical data) to identify patterns, anomalies, and emerging thr

gitlinuxai
View job →
🔔

Get new offensive security manager jobs by email

Daily job updates · Unsubscribe anytime