Senior Offensive Product Security Engineer

Job Locations US-Remote
ID
2024-3596
Category
IT Operations
Type
Full Time

Overview

As an Offensive Product Security Engineer, you will play a critical role in safeguarding our products by identifying and mitigating security vulnerabilities. You will conduct comprehensive security assessments, including penetration testing, threat modeling, and code reviews, to ensure our products are resilient against potential attacks. Your expertise will help shape our security strategy, enhance our security posture, and protect our customers’ data.

 

Starting base pay for this role is between $140,000 and $175,000. The actual base pay is dependent upon many factors, such as transferable skills, work experience, business needs, training, location, and market demands. The base pay range is subject to change and may be modified in the future. This role will be eligible for a bonus as well as competitive medical, dental, and vision benefits, wellness reimbursement, life insurance, and a 401(k) with company match. We offer vacation and sick leave benefits (under a flexible time off policy in most states). 

Responsibilities

  • Lead and conduct advanced penetration testing and vulnerability assessments on our products and infrastructure.
  • Lead, develop and deploy realistic attacks to test security defenses.
  • Develop and maintain security documentation, including policies, procedures, and guidelines.
  • Carry out controlled attacks to evade detection, simulate real-world attacks to exploit potential weaknesses.
  • Prepare and deliver technical reports to internal stakeholders
  • Perform vulnerability assessments, triage and provide prescriptive remediation for identified vulnerabilities
  • Assist in incident response and forensic analysis when security incidents occur.
  • Collaborate with development teams to integrate security best practices into the software development lifecycle.
  • Assist in developing and executing threat models to identify potential security risks
  • Stay current on exploitation and post-exploitation techniques and incorporate them into the penetration testing
  • Other duties as assigned

Qualifications

  • Bachelor’s or master's degree in computer science, Information Security, or a related field.
  • 6+ years of experience in information security with focus on application and cloud security
  • 4+ years of hands-on experience in offensive security, including exploit development, vulnerability research, and penetration testing
  • Strong knowledge of penetration testing methodologies and tools (e.g., Metasploit, Burp Suite, Nmap, MITRE).
  • Proficient in performing adversary simulation attacks, red team experience
  • Proficient in active directory, OSINT, networking technologies
  • Proficiency in scripting and programming languages (e.g., Python, Java, C++).
  • Familiarity with cloud security (e.g., AWS, Azure, GCP) and container security (e.g., Docker, Kubernetes).
  • Excellent problem-solving skills and attention to detail.
  • Strong communication and collaboration skills.

Additional Qualifications:

  • Relevant certifications such as OSCP, OSWE, CISSP, GPEN or CEH.
  • Experience with DevSecOps practices and tools.
  • Knowledge of regulatory requirements and industry standards (e.g., GDPR, ISO 27001)
  • Dynamic technical leadership acumen, both cross-functionally and directly supporting highly technical staff in our Product Security function and partner teams such as Development, IT, Compliance, DevOps
  • Project management experience, including direct teams and external partners
  • Excellent verbal and written communication skills
  • Excellent team player

Who We Are

Origami Risk provides integrated SaaS solutions to organizations across the risk and insurance ecosystem — from insured corporate and public entities to brokers and risk consultants, insurers, third party claims administrators (TPAs), and risk pools. We deliver our risk management and insurance core system solutions from a cloud-based platform that is highly configurable, completely scalable, and accessible via web browser and mobile app. 

 

Dais Technology, a subsidiary of Origami Risk, provides a no-code platform that revolutionizes insurance product creation for MGAs, insurers, and reinsurers. Dais’ event-based architecture enables AI-driven bundling, automation, and real-time deployment. 

 

Solutions from Origami Risk and Dais Technology are backed by a best-in-class service team of experienced risk and insurance professionals who possess a balance of industry knowledge and technological expertise. A singular focus on helping clients achieve their business objectives underlies our approach to developing, implementing, and supporting our risk management, safety, compliance, and insurance core system technology solutions. 

 

Origami Risk is proud to be an equal opportunity employer. We thrive and benefit from diversity and are committed to creating an inclusive and equitable environment for all employees. We do not discriminate against any individual based upon race, religion, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, color, sex, national origin, age, marital status, military or veteran status, disability, or any other characteristic protected by applicable law.

 

Caution: Be alert to recruiting scams. We have received reports of individuals impersonating Origami Risk recruiters to deceive candidates into disclosing personal information. These impostors use fake Origami Risk domain names and email addresses. Please double-check that any email address from an Origami Risk recruiter ends with origamirisk.com or talent.icims.com. And to confirm the legitimacy of any recruiting communication, feel free to email transparencycheck@origamirisk.com.

 
 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed