Job description
Job Description: - Conduct comprehensive penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure
- Plan and execute red team engagements emulating cyber and criminal threat actors targeting financial services
- Perform assumed-breach and objective-based assessments to test detection and response capabilities
- Partner with detection engineering, threat intelligence, and incident response teams to validate controls and improve detection fidelity
- Contribute adversary tradecraft insights to detection rules, threat hunting hypotheses, and incident response playbooks
- Support incident investigations with offensive expertise, log analysis, and root cause analysis
- Design, develop, and maintain custom offensive tools, scripts, and automation frameworks
- Build internal platforms and workflows for scalable, repeatable offensive operations
- Automate testing tasks, payload generation, and reporting workflows
- Produce reports communicating technical findings, business risk, and remediation guidance
- Act as a subject-matter expert and point of contact for offensive security initiatives
- Lead projects end-to-end, mentor junior team members, and foster continuous learning
- Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and with the security community
Requirements: - 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
- Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
- Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes
- Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
- Familiarity with MITRE ATT&CK and adversary TTPs for initial access, privilege escalation, lateral movement, and exfiltration
- Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
- Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Benefits: - Equity participation in Stripe's growth
- 401(k) plan with matching contributions from day one
- Comprehensive medical, dental, and vision coverage
- Wellness stipends
- Annual budget for training, certifications, and conference attendance
- Remote work from home within the United States
- Office visits for team meetings, on-sites, and events
first seen 2026-09-25 21:30:01 · last verified 2026-09-26 01:30:01
pentestcareers.com // breach the job market