Senior Security Engineer (Offensive) at Offchain | Torre

Senior Security Engineer (Offensive)

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for United States residents)
Shared by
Emma of Torre.ai
8 days ago

Responsibilities


As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.The RoleAs a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.What you'll do:Conduct comprehensive code audits across a variety of internal applications and infrastructure.Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange.What you'll need:5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.Extensive experience with conducting code audits to identify and remediate security issues.Experience with binary exploitation.Mastery of AWS & specific attack techniques and configuration weaknesses.Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.Nice-to-havesWeb3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.Familiarity with Ethereum L1 / L2 node architecture and security risks.Experience in blockchain infrastructure penetration testing.Perks:Remote-first global workforce + NY officeAnnual company offsite + team onsitesProfessional reimbursement program (facilitates industry conference attendance, certifications, and more)Medical, dental & vision coverage (US + some other countries)401k retirement plan + company match (US only)Wellness stipendHome office set up / ergonomic equipment programAttention Offchain Job Seekers:This role cannot be performed in California, or Colorado.