Lead Offensive Security Engineer

ecolab

United States

On-site

USD 150,000 - 230,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Ecolab seeks a Lead Offensive Security Engineer to drive hands-on testing across commercial digital products, including web, mobile, APIs, cloud services, and IoT devices.

You will lead a small internal team, define engagement scope, testing methods, reporting standards, and remediation validation while collaborating with product security, engineering, and business stakeholders to reduce risk in Ecolab's offerings.

Qualifications

  • Bachelor's degree in cybersecurity, CS, IT, engineering or related field.
  • 8+ years in cybersecurity, application security or related technical field.
  • Hands-on testing of web, mobile, APIs, cloud and IoT products with authorization.
  • Experience leading offensive security engagements and teams.
  • Experience with Azure; familiarity with AWS/GCP security concepts.
  • Experience with applications

Responsibilities

  • Lead and perform hands-on offensive security testing across products.
  • Plan, scope, and execute technical security assessments for vulnerabilities.
  • Lead a small internal offensive security team and provide day-to-day testing.
  • Develop repeatable red team methods and testing engagement rules.
  • Translate results into remediation actions with risk-based priorities.
  • Conduct safe testing of IoT and industrial equipment where appropriate.
  • Use security tools to identify, validate, and document issues.
  • Prepare clear reports with impact, remediation guidance and validation.
  • Present findings to engineers and non-technical stakeholders.
  • Support threat modeling, secure architecture reviews, and cloud security discussions.

Skills

Offensive security
Penetration testing
Security testing
Threat modeling
Reporting / communication
Team leadership
Cloud security
IoT security

Education

Bachelor's Degree in Cybersecurity
Bachelor's Degree in Computer Science
Bachelor's Degree in Information Technology
Bachelor's Degree in Engineering

Tools

Snyk
Wiz
Burp Suite
OWASP ZAP
GitHub Advanced Security
Nmap
Horizon3 NodeZero
DAST tooling

Job description

The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Lead Offensive Security Engineer will actively perform security testing for most of their time while also leading a small internal team, helping define engagement scope, testing methods, reporting standards, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab's commercial offerings.

What you will do:
  • Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
  • Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
  • Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
  • Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
  • Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
  • Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
  • Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
  • Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
  • Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
  • Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
  • Help improve Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
  • Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
  • Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
  • Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.
Minimum Qualifications:
  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
  • 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
  • Demonstrated hands‑on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
  • Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
  • Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.
  • Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
  • Experience with application
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer
Senior Offensive Security Engineer

ecolab • United States

On-site
USD 150,000 - 210,000
Lead Offensive Security Engineer – Product & IoT Security
Lead Offensive Security Engineer – Product & IoT Security

ecolab • United States

On-site
USD 150,000 - 230,000
Senior Offensive Security Lead for Web, Cloud & IoT Tests
Senior Offensive Security Lead for Web, Cloud & IoT Tests

RXinsider LTD. • Naperville (IL)

On-site
USD 121,000 - 181,000
Lead Offensive Security Engineer: Web, Cloud & IoT Security
Lead Offensive Security Engineer: Web, Cloud & IoT Security

ECOLAB • Naperville (IL)

On-site
USD 121,000 - 181,000
Senior Offensive Security Engineer, Commercial Products
Senior Offensive Security Engineer, Commercial Products

ecolab • United States

On-site
USD 150,000 - 210,000
Senior Offensive Security Engineer – Commercial Apps
Senior Offensive Security Engineer – Commercial Apps

ECOLAB • Naperville (IL)

On-site
USD 101,000 - 152,000
Senior Offensive Security Engineer: Hands-on Red Team
Senior Offensive Security Engineer: Hands-on Red Team

RXinsider LTD. • Naperville (IL), Northern (KY)

Hybrid
USD 101,000 - 152,000
Lead Offensive Security Engineer
Lead Offensive Security Engineer

RXinsider LTD. • Naperville (IL)

On-site
USD 121,000 - 181,000
Lead Offensive Security Engineer
Lead Offensive Security Engineer

ECOLAB • Naperville (IL)

On-site
USD 121,000 - 181,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

ECOLAB • Naperville (IL)

On-site
USD 101,000 - 152,000