Skip to main content
Twilio
Twilio

Staff Engineer - Offensive Security

RemoteUnited States, Brazil only
Published
Role
Security
Experience
Staff
$155.5k–$194.4k/yr
Check eligibility

Open to US, BR only. Set where you work from to check your eligibility.

No BS summary

Staff Offensive Security Engineer with 7-10 years of experience in offensive security or penetration testing. Must have expert knowledge of MITRE ATT&CK and OWASP Top 10, proficiency with OffSec tools, and ability to write custom exploits in Python or C++.

Core skills

Penetration TestingOffensive SecurityAI Security

Required skills

Burp SuiteNmapMetasploitWiresharkLangChain/TensorFlowCobalt Strike/Sliver/HavocPythonBashC++

What you'll do

  • Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android).
  • Conduct network and cloud level assessments with various tooling
  • Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives
  • Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs).
  • Draft high-quality reports that detail the "path to compromise" with clear, reproducible steps for developers.
  • Manage and update the team's testing infrastructure (e.g., Burp Suite, and basic C2 listeners).
  • Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR.
  • Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities.
  • Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth.
  • Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage.
  • Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes.
  • Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on the techniques used during an engagement.
  • Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes.

What they require

  • 7-10 years in offensive security, penetration testing, a high-volume bug bounty background, AppSec, or vulnerability exploitation, and track record of finding high/critical vulnerabilities in complex environments using pentesting commercial or custom tools.
  • Expert Knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs, post exploitation (lateral movement, persistence, data exfiltration) and Adversarial ML.
  • Ability to write functional scripts in Python or Bash to automate repetitive testing tasks and proficiency in coding and scripting like Python, C++, and scripting for creating custom offensive exploits that avoids signature-based detection.
  • Preferred: Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable
  • Preferred: Telecom expertise is preferred
  • Preferred: Excellent written and verbal communication skills.
  • Preferred: Ability to influence and build effective working relationships with all levels of the organization.
  • Preferred: Proficiency in multiple languages applicable to the region.
  • Preferred: Familiarity with localization tactics to ensure our content is accessible and inclusive across multiple APJ countries.

Benefits

  • competitive pay
  • generous time off
  • ample parental and wellness leave
  • healthcare
  • a retirement savings program
  • eligible to participate in Twilio’s equity plan and corporate bonus plan
  • health care insurance
  • 401(k) retirement account
  • paid sick time
  • paid personal time off
  • paid parental leave

Communication APIs for SMS, Voice, Video & Authentication

🇺🇸 United StatesTelecommunicationsEnterprisetwilio.com/en-us

What people say about this company

3.6/ 5

$155.5k–$194.4k/yr