Senior Offensive Security Engineer — Red Team & AI Security

Twilio

United States

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive pay
Healthcare
Retirement savings program
Parental and wellness leave

Job summary

Twilio seeks a Staff Offensive Security Engineer to lead complex penetration testing across web, mobile, cloud, and AI ecosystems. You will design attack chains, build automated testing frameworks, and guide engineering teams to remediate critical vulnerabilities.

You will perform multi‑week adversary emulation, develop custom payloads, and advance security testing capabilities using tools like Burp Suite, Nmap, Metasploit, and C2 frameworks.

Qualifications

  • 7–10 years of experience in offensive security, penetration testing, bug bounty, AppSec, or vulnerability exploitation with a proven track record of finding high‑critical vulnerabilities.
  • Expert knowledge of MITRE ATT&CK, OWASP Top 10 for web applications, OWASP Top 10 for LLMs, post‑exploitation concepts, and adversarial ML.
  • Proficiency with tools such as Burp Suite Professional, Nmap, Metasploit, Wireshark, LangChain, TensorFlow for adversarial testing, and C2 frameworks (Cobalt Strike, Sliver, Havoc).
  • Strong scripting skills in Python or Bash; ability to craft custom exploits that avoid signature‑based detection (Python, C++, Bash).
  • Advanced certifications (OSCP, OSEP, OSWE, GXPN) or equivalent OffSec tracks.
  • Preferred: telecom domain expertise.

Responsibilities

  • Full‑Stack Penetration Testing: Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android).
  • Internal/External Network Audits: Conduct network and cloud level assessments with various tooling.
  • Vulnerability Validation: Triage and validate reports from automated scanners or bug bounty hunters, eliminate false positives, and prioritize true positives.
  • AI/LLM Probing: Perform prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists.
  • Technical Reporting: Draft high‑quality reports detailing the "path to compromise," providing reproducible steps for developers.
  • Tool Maintenance: Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners).
  • Remediation Support: Provide direct technical guidance to engineering teams on patching vulnerabilities such as XSS, SQLi, and IDOR.
  • Adversary Emulation: Design and lead multi‑week Red Team operations mimicking specific threat actors to test detection capabilities.
  • Custom Exploit Development: Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth.
  • AI Red Teaming Architecture: Build automated testing frameworks for AI systems (e.g., PyRIT, Promptfoo, Garak) to test for data leakage.
  • Cloud & Infrastructure Attacks: Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes.
  • Purple Teaming: Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on engagement techniques.
  • Strategic Bug Bounty Management: Oversee the bug bounty program, identify trends, and recommend architectural security changes.

Skills

MITRE ATT&CK
OWASP Top 10
LLM Security
Burp Suite
Nmap
Metasploit
Wireshark
Python
Bash
C2 Frameworks
Adversarial ML

Education

OSCP
OSEP
OSWE
GXPN

Tools

Burp Suite Professional
Nmap
Metasploit
Wireshark
LangChain
TensorFlow
Cobalt Strike
Sliver
Havoc

Job description

Twilio seeks a Staff Offensive Security Engineer to lead complex penetration testing across web, mobile, cloud, and AI ecosystems. You will design attack chains, build automated testing frameworks, and guide engineering teams to remediate critical vulnerabilities.

You will perform multi‑week adversary emulation, develop custom payloads, and advance security testing capabilities using tools like Burp Suite, Nmap, Metasploit, and C2 frameworks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Staff Offensive Security Engineer
Remote Staff Offensive Security Engineer

Twilio • United States

On-site
USD 164,000 - 206,000
Staff Engineer - Remote Offensive Security Lead
Staff Engineer - Remote Offensive Security Lead

SendGrid • United States

On-site
USD 164,000 - 206,000
Health care insurance
401(k) retirement plan
Paid time off
Remote Senior Red Team Operator — Offensive Security Lead
Remote Senior Red Team Operator — Offensive Security Lead

Covington & Burling LLP • Washington

On-site
USD 120,000 - 189,000
Senior Red Team Security Engineer - Offensive & Cloud
Senior Red Team Security Engineer - Offensive & Cloud

WellSky Corporation • United States

On-site
USD 150,000 - 210,000
Excellent benefits package
401(k) with match
Generous paid time off
+1
Offensive Security Engineer: Red Team & AI-Driven Defenses
Offensive Security Engineer: Red Team & AI-Driven Defenses

CloudWalk, Inc. • United States

On-site
USD 120,000 - 180,000
Senior Offensive Security Engineer (Remote) | Red Team Lead
Senior Offensive Security Engineer (Remote) | Red Team Lead

Offchain • United States

On-site
USD 180,000 - 240,000
Remote-first global workforce
Professional reimbursement program
Medical, dental & vision coverage
+3
Senior Adversarial Red Team Lead | AI-Driven Pen Testing
Senior Adversarial Red Team Lead | AI-Driven Pen Testing

Jobtailor • United States

On-site
USD 170,000 - 210,000
Senior Offensive Security Engineer - Lead Red Team & Cloud
Senior Offensive Security Engineer - Lead Red Team & Cloud

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 167,000 - 272,000
AI Red Team Engineer
AI Red Team Engineer

Confidential • San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior Offensive Security Engineer: AI-Driven PenTesting
Senior Offensive Security Engineer: AI-Driven PenTesting

Synopsys Inc • Morrisville (NC)

Hybrid
USD 140,000 - 190,000