Senior Penetration Tester (AWS)
Posted 479 days ago, which is unusual. The employer's own board was still carrying it when we last read it, 1 hour ago.
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 479d ago
The date the source published, not the day we noticed it (2025-05-23). Last seen at its source 1h ago.
Is it remote?
Remote
That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.
Who may apply?
Not stated
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
lever employer's own board first seen 37d ago · last seen 1h ago
The listing
The Role
- As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.
- You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.
- Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.
What you'll do:
What you'll need:
- 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
- Extensive experience with conducting code audits to identify and remediate security issues.
- Experience with binary exploitation.
- Mastery of AWS & specific attack techniques and configuration weaknesses.
- Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
- In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
- Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.
- Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
- Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
- A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.
Nice-to-haves
- Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.
- Familiarity with Ethereum L1 / L2 node architecture and security risks.
- Experience in blockchain infrastructure penetration testing.