Offensive Security Engineer

Lever, Inc.

España

A distancia

EUR 110.000 - 150.000

Jornada completa

hace 30 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto — currículum adaptado y carta de presentación, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

Lever, Inc. is seeking an experienced Offensive Security Engineer based in Spain to join a hands-on security team.

You will simulate sophisticated attacks across cloud compute, storage, networking, and AI infrastructure, contributing to scalable red team programs and security research. You will work with detection and security engineering teams to validate defenses, develop custom tooling, and produce actionable leadership reports.

Formación

  • 6+ years in offensive security, pentesting, red teaming, or related discipline.
  • Hands-on experience attacking cloud-native environments including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escape techniques.
  • Proven ability to develop custom security tooling and post-exploitation capabilities using Python, Go, or similar languages.
  • Experience conducting purple team exercises and collaboration with blue teams and defensive functions.
  • Ability to communicate complex technical findings via clear, senior-level reports with actionable remediation guidance.
  • Experience with ML infrastructure, model-serving pipelines, or GPU clusters is a strong advantage.
  • Reverse engineering and exploit development experience is a plus.
  • Application security experience is advantageous.

Responsabilidades

  • Validate and extend Secure SDLC threat models through continuous penetration testing and risk assessment.
  • Automate routine security validations to keep pace with platform evolution while reserving manual analysis for high-impact scenarios.
  • Plan and execute full-scope red team engagements across cloud compute, storage, inference, networking, orchestration, and tooling.
  • Identify attack paths impacting operations, customer environments, or critical assets.
  • Collaborate with detection and response teams on purple team exercises and close defensive gaps.
  • Research novel attacks against GPU infrastructure and AI platform services.
  • Investigate vulnerabilities in inference technologies and platform services, including model-serving infrastructure.
  • Assess tenant isolation and explore low-level paths that could compromise isolation.
  • Conduct targeted offensive security assessments before production changes.
  • Develop custom offensive tooling and post-exploitation capabilities for scalable testing.
  • Produce clear, actionable reports for technical teams and leadership with remediation guidance.
  • Establish and improve red team processes, tooling, and practices as the platform scales.

Conocimientos

Offensive security
Penetration testing
Red teaming
Purple team
Python
Go
Cloud-native
Kubernetes
IAM abuse
Exploit development

Descripción del empleo

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Offensive Security Engineer based in Spain.

Join a hands-on offensive security team working at the frontier of cloud infrastructure and AI. In this role, you’ll simulate sophisticated attacks against the same systems customers rely on, helping uncover weaknesses before they can become real threats. You’ll contribute across cloud compute, storage, networking, inference, orchestration, and internal tooling while helping establish a scalable penetration testing and red team program. The role combines practical adversarial operations with security research into emerging GPU and AI infrastructure attack surfaces. You’ll work closely with detection and security engineering teams to validate defenses and turn findings into measurable improvements. With substantial technical ownership, you’ll have the opportunity to influence security practices across a rapidly evolving, large-scale AI platform.

Accountabilities
  • Validate and extend Secure SDLC threat models through continuous penetration testing, assessing threat severity, mitigation status, and underlying security assumptions.
  • Automate routine security validations to keep pace with a rapidly evolving platform while reserving manual analysis for complex and high-impact scenarios.
  • Plan and execute full-scope red team engagements across cloud compute, storage, inference, networking, orchestration layers, and internal tooling.
  • Identify attack paths capable of impacting organizational operations, customer environments, or critical platform assets.
  • Collaborate with detection and response and other security engineering teams on purple team exercises, validating detection coverage and closing defensive gaps.
  • Research novel attacks against GPU infrastructure, including firmware, vendor drivers, device passthrough, SR-IOV/IOMMU configurations, and RDMA/InfiniBand environments.
  • Investigate vulnerabilities within inference technologies and AI platform services, including model-serving infrastructure and managed orchestration platforms.
  • Assess tenant-isolation boundaries and explore potential low-level attack paths that could compromise isolation.
  • Conduct targeted offensive security assessments of new products and significant infrastructure changes before they reach production.
  • Develop custom offensive tooling and post-exploitation capabilities to improve the effectiveness and scalability of security testing.
  • Produce clear, actionable reports for both technical teams and senior leadership, prioritizing findings and providing practical remediation guidance.
  • Establish and continuously improve red team processes, tooling, methodologies, and operating practices as the platform scales.
Requirements
  • 6+ years of experience in offensive security, penetration testing, red teaming, adversary simulation, or a closely related discipline.
  • Deep hands-on experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escape techniques.
  • Strong understanding of the broader attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration.
  • Proven ability to develop custom security tooling and post-exploitation capabilities using Python, Go, or similar programming languages.
  • Experience conducting purple team exercises and collaborating constructively with blue teams and defensive security functions.
  • Ability to communicate complex technical findings through clear, senior-level reports that contextualize business risk and provide actionable guidance to engineers.
  • Experience with ML infrastructure, model-serving pipelines, or GPU clusters is a strong advantage.
  • Reverse engineering and exploit development experience is a plus.
  • Application security experience is advantageous.
  • Familiarity with eBPF bypass techniques, kernel-level exploitation, vulnerability research, or CVE discovery is beneficial.
  • Understanding of cloud provider internals, including hypervisor and networking layers, is a plus.
  • Experience presenting security research at industry conferences such as Black Hat or DEF CON is advantageous.
  • Strong problem-solving skills, curiosity, technical depth, and the ability to work independently in a rapidly evolving environment.
Benefits
  • Competitive compensation with equity upside.
  • Flexible, remote-first working environment.
  • Opportunities for career growth, continuous learning, and professional development.
  • Significant ownership and flexibility in how security challenges are approached.
  • Opportunity to work on novel attack surfaces spanning GPU infrastructure, AI platforms, and large-scale multi-tenant cloud environments.
  • Collaboration with highly experienced engineers working on advanced AI infrastructure.
  • Opportunity to contribute directly to impactful AI and cloud security initiatives.
  • International environment with talented teams across multiple regions.
  • Inclusive and collaborative culture focused on innovation, trust, meaningful impact, and continuous growth.

We appreciate your interest and wish you the best!

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Offensive Security Engineer – Remote, AI/Cloud
Senior Offensive Security Engineer – Remote, AI/Cloud

Lever, Inc. • España

A distancia
EUR 110.000 - 150.000
Lead IT Security AI-Redteamer
Lead IT Security AI-Redteamer

Dkbcodefactory • España

Presencial
EUR 90.000 - 150.000
Benefits package
Senior pentester
Senior pentester

GMV Spain • Madrid

Híbrido
EUR 70.000 - 100.000
Hybrid work model
Relocation package
Wellbeing program
+1
Senior Offensive Security Researcher
Senior Offensive Security Researcher

SentinelOne • España

Presencial
EUR 70.000 - 100.000
RSUs
ESPP
Leave benefits
+7
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Tamarind Intelligence • Barcelona

Presencial
EUR 85.000 - 125.000
Hybrid work model
Barcelona, Spain based role
Pentester Senior
Pentester Senior

GMV Spain • Tres Cantos

Híbrido
EUR 65.000 - 93.000
Hybrid working model
Teleworking up to 8 weeks/year
Relocation package
+2
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Elche

Híbrido
EUR 45.000 - 67.000
Staff Security Researcher
Staff Security Researcher

Lever, Inc. • España

A distancia
EUR 110.000 - 170.000
Fully remote Europe
Health benefits
Pension
+6
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Valencia

Híbrido
EUR 45.000 - 65.000
Offensive Security Engineer - App Security & AI Tools
Offensive Security Engineer - App Security & AI Tools

Commit • Barcelona

Presencial
EUR 65.000 - 100.000