The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Lead Offensive Security Engineer will actively perform security testing for most of their time while also leading a small internal team, helping define engagement scope, testing methods, reporting standards, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab's commercial offerings.
What you will do:
- Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
- Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
- Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
- Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
- Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
- Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
- Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
- Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
- Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
- Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
- Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
- Help improve Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
- Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
- Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
- Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.
Minimum Qualifications:
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
- 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
- Demonstrated hands‑on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
- Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
- Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.
- Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
- Experience with application