Lead Offensive Security Engineer: Web, Cloud & IoT Security

ECOLAB

Naperville (IL)

On-site

USD 121,000 - 181,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ECOLAB invites applications for Lead Offensive Security Engineer to drive hands-on testing across our commercial digital products, including web/mobile apps, APIs, cloud services, and IoT platforms. You will lead a small internal team while staying deeply involved in testing, analysis, reporting, and remediation validation.

You will collaborate with product security, cloud, IoT, architecture, and business teams to translate findings into actionable remediation, prioritized risk, and governance

Qualifications

  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
  • 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
  • Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.

Responsibilities

  • Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
  • Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
  • Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
  • Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
  • Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
  • Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
  • Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
  • Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
  • Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
  • Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
  • Help improve Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
  • Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
  • Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
  • Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.

Skills

Offensive security testing
Team leadership
Cloud security
Secure SDLC

Education

Bachelor's Degree in Cybersecurity or related

Tools

Burp Suite
OWASP ZAP
Snyk
Nmap

Job description

ECOLAB invites applications for Lead Offensive Security Engineer to drive hands-on testing across our commercial digital products, including web/mobile apps, APIs, cloud services, and IoT platforms. You will lead a small internal team while staying deeply involved in testing, analysis, reporting, and remediation validation.

You will collaborate with product security, cloud, IoT, architecture, and business teams to translate findings into actionable remediation, prioritized risk, and governance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer – Commercial Apps
Senior Offensive Security Engineer – Commercial Apps

ECOLAB • Naperville (IL)

On-site
USD 101,000 - 152,000
Lead Penetration Tester - Cloud & App Security
Lead Penetration Tester - Cloud & App Security

S&P Global, Inc. • Princeton (NJ)

Hybrid
USD 135,000 - 200,000
Lead Offensive Security Engineer
Lead Offensive Security Engineer

ECOLAB • Naperville (IL)

On-site
USD 121,000 - 181,000
Security Engineer
Security Engineer

Horizontal Talent • Brooklyn Park (MN)

On-site
USD 120,000 - 160,000
Offensive Security Engineer: Pen-Testing & Tooling Lead
Offensive Security Engineer: Pen-Testing & Tooling Lead

Palantir Technologies • New York (NY)

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
Commuter benefits
Relocation assistance
+4
Lead Penetration Tester — Cloud & AppSec Lead
Lead Penetration Tester — Cloud & AppSec Lead

Relha LLC • Princeton (NJ), Northern (KY)

Hybrid
USD 135,000 - 200,000
Health & Wellness
Flexible downtime
Continuous learning
+3
Director of Security Engineering & CTEM
Director of Security Engineering & CTEM

ECOLAB • Saint Paul (MN)

On-site
USD 137,000 - 207,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

ECOLAB • Naperville (IL)

On-site
USD 101,000 - 152,000
Remote Staff Product Security Engineer (Offensive Testing)
Remote Staff Product Security Engineer (Offensive Testing)

Drive Capital • United States

On-site
USD 170,000 - 240,000
Comprehensive Benefits
Remote-first culture
Equity
Lead Pen Test Engineer - Hybrid, Cloud & App Security
Lead Pen Test Engineer - Hybrid, Cloud & App Security

spgi • Princeton (NJ)

Hybrid
USD 140,000 - 190,000