New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Twilio

Staff Engineer - Offensive Security

Twilio
Apply →
remote staff full-time $155,520.00 - $194,400.00 Remote - US

First indexed 9 Jul 2026

Description

Job Overview

As a Staff Engineer - Offensive Security at Twilio, you will act as a Technical Lead, designing complex attack chains that demonstrate systemic risk. You will spend as much time writing custom code and researching new bypasses as you do executing tests.

Responsibilities

In this role, you'll:

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps (iOS/Android)
  • Conduct internal/external network audits with various tooling
  • Validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives
  • Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs)
  • Draft high-quality reports detailing the 'path to compromise' with clear, reproducible steps for developers
  • Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners)
  • Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR
  • Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities
  • Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth
  • Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage
  • Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes
  • Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on techniques used during engagements
  • Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes

Qualifications

Required:

  • 7-10 years of experience in offensive security, penetration testing, high-volume bug bounty background, AppSec, or vulnerability exploitation
  • Expert knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs
  • Proficiency in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark, etc.
  • Ability to write functional scripts in Python or Bash to automate repetitive testing tasks
  • Proficiency in coding and scripting like Python, C++
  • Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable

Desired:

  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with all levels of the organization
  • Proficiency in multiple languages applicable to the region
  • Familiarity with localization tactics

Location

This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more.

Compensation

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $155,520.00 - $194,400.00
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00
  • Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/twilio/jobs/8048657