# Staff Engineer - Offensive Security

**Company**: Twilio
**Location**: Remote - US
**Work arrangement**: remote
**Experience**: staff
**Job type**: full-time
**Salary**: $155,520.00 - $194,400.00
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/twilio/jobs/8048657?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_20a5ae81-253

## Description

### Job Overview

As a Staff Engineer - Offensive Security at Twilio, you will act as a Technical Lead, designing complex attack chains that demonstrate systemic risk. You will spend as much time writing custom code and researching new bypasses as you do executing tests.

### Responsibilities

In this role, you'll:

- Perform full-stack penetration testing of web applications, APIs, and mobile apps (iOS/Android)

- Conduct internal/external network audits with various tooling

- Validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives

- Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs)

- Draft high-quality reports detailing the 'path to compromise' with clear, reproducible steps for developers

- Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners)

- Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR

- Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities

- Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth

- Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage

- Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes

- Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on techniques used during engagements

- Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes

### Qualifications

*Required:*

- 7-10 years of experience in offensive security, penetration testing, high-volume bug bounty background, AppSec, or vulnerability exploitation

- Expert knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs

- Proficiency in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark, etc.

- Ability to write functional scripts in Python or Bash to automate repetitive testing tasks

- Proficiency in coding and scripting like Python, C++

- Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable

*Desired:*

- Excellent written and verbal communication skills

- Ability to influence and build effective working relationships with all levels of the organization

- Proficiency in multiple languages applicable to the region

- Familiarity with localization tactics

### Location

This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

### What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more.

### Compensation

The estimated pay ranges for this role are as follows:

- Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $155,520.00 - $194,400.00

- Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00

- Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00

## Skills

### Required
- MITRE ATT&CK matrix
- OWASP Top 10
- Burp Suite
- Nmap
- Metasploit
- Wireshark
- Python
- Bash
- C++
- OSCP
- OSEP
- OSWE
- GXPN

### Nice to have
- Excellent written and verbal communication skills
- Ability to influence and build effective working relationships
- Proficiency in multiple languages
- Familiarity with localization tactics

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/twilio/jobs/8048657?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
