Senior Penetration Tester (AWS)

Offchain

United States

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote‑first workforce
Conference reimbursement
Medical, dental & vision coverage
401k retirement plan + company match
Wellness stipend
Home office setup

Job summary

Offchain is building a movement in blockchain security, shaping scalable and secure infrastructure for millions of users and applications. We seek a Senior Security Engineer to lead offensive testing, build tools, and mentor teammates as we strengthen detection and response across our ecosystem.

You will run audits, conduct cloud and backend pentests, and collaborate across incident response to reduce risk and improve SOC2 readiness. Join a remote-first team with a strong security culture.

Qualifications

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Experience with binary exploitation.
  • Mastery of AWS & specific attack techniques and configuration weaknesses.
  • Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
  • In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
  • Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.
  • Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
  • A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.

Responsibilities

  • Conduct code audits across a variety of internal applications and infrastructure.
  • Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.
  • Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.
  • Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.
  • Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.
  • Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.
  • Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange.

Skills

Offensive security
Penetration testing
Red teaming
AWS security
Code audits
Python
Go
Threat modeling
MITRE ATT&CK
Web app security

Tools

Burp Suite
Nuclei
OWASP ZAP

Job description

At Offchain, we aren’t just building products: we’re leading a movement.

As pioneers in blockchain scalability and security, we're at the forefront of transforming how the world interacts with decentralized applications. We're laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency.

At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you.

Why Offchain?

Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today.

Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack.

Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what's possible on Ethereum and advancing its core infrastructure.

To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly.

The Role
  • As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.
  • You’ll run hands‑on penetration tests, lead red team exercises, and work side‑by‑side with blue team partners to test, refine, and strengthen detection and response capabilities.
  • Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.
What you’ll do:
  • Conduct comprehensive code audits across a variety of internal applications and infrastructure.
  • Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.
  • Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.
  • Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.
  • Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.
  • Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.
  • Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange.
What you’ll need:
  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Extensive experience with conducting code audits to identify and remediate security issues.
  • Experience with binary exploitation.
  • Mastery of AWS & specific attack techniques and configuration weaknesses.
  • Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
  • In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
  • Proficiency using offensive security tools such as Burp Suite, nucleiand similar frameworks.
  • Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
  • A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.
Nice-to-haves
  • Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.
  • Familiarity with Ethereum L1 / L2 node architecture and security risks.
  • Experience in blockchain infrastructure penetration testing.
Perks:
  • Remote‑first global workforce + NY office
  • Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
  • Medical, dental & vision coverage (US + some other countries)
  • 401k retirement plan + company match (US only)
  • Wellness stipend
  • Home office set up / ergonomic equipment program
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester (AWS)
Senior Penetration Tester (AWS)

cyber • Northern (KY)

Hybrid
USD 140,000 - 190,000
Remote-first global workforce
NY office access
Professional reimbursement program
+4
Senior Penetration Tester (AWS)
Senior Penetration Tester (AWS)

Arbitrum • Northern (KY)

Hybrid
USD 140,000 - 210,000
Remote-first global workforce
NY office access
Security Engineer
Security Engineer

cyber • Northern (KY)

Hybrid
USD 130,000 - 200,000
Remote-first + NY office
Reimbursement program
Health, dental & vision coverage
+3
Security Engineer
Security Engineer

Arbitrum • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote-first global workforce
NY office access
Professional reimbursement
+4
Site Reliability Engineer
Site Reliability Engineer

cyber • Northern (KY)

Hybrid
USD 140,000 - 190,000
Remote-first global workforce
Professional reimbursement program
Medical, dental & vision coverage (US)
+3
Site Reliability Engineer
Site Reliability Engineer

Arbitrum • Northern (KY)

Hybrid
USD 100,000 - 140,000
Remote-first global workforce
Professional reimbursement program
Medical, dental & vision coverage
+3
Site Reliability Engineer
Site Reliability Engineer

Embedded Shishya • United States

Remote
USD 150,000 - 210,000
Remote‑first global workforce
Professional reimbursement program
Medical, dental & vision coverage
+3
Senior Backend Engineer
Senior Backend Engineer

Arbitrum • Northern (KY)

Hybrid
USD 140,000 - 190,000
Remote-first global workforce
Professional reimbursement program
Medical, dental & vision coverage
+3
Head of Enterprise
Head of Enterprise

Offchain Labs • United States

Remote
USD 150,000 - 200,000
Remote-first global workforce + NY office
Annual company offsite + team onsites
Professional reimbursement program
+4
Business Operations Manager
Business Operations Manager

Arbitrum • Northern (KY)

Hybrid
USD 95,000 - 150,000
Remote-first global workforce
Conference attendance support
Medical, dental & vision coverage
+3