Description
Job Overview
As a Staff Engineer - Offensive Security at Twilio, you will act as a Technical Lead, designing complex attack chains that demonstrate systemic risk. You will spend time writing custom code, researching new bypasses, and executing tests.
Responsibilities
- Perform full-stack penetration testing of web applications, APIs, and mobile apps (iOS/Android)
- Conduct internal/external network audits with various tooling
- Validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives
- Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications
- Draft high-quality reports detailing the 'path to compromise' with clear, reproducible steps for developers
- Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners)
- Provide direct technical guidance to engineering teams on how to patch vulnerabilities
- Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities
- Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth
- Build automated testing frameworks for AI systems to test for models related to sensitive data leakage
- Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes
- Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on techniques used during an engagement
- Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes
Qualifications
Required
- 7-10 years of experience in offensive security, penetration testing, or vulnerability exploitation
- Expert knowledge of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs
- Proficiency in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark, etc.
- Ability to write functional scripts in Python or Bash to automate repetitive testing tasks
- Proficiency in coding and scripting like Python, C++
- Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable
Desired
- Excellent written and verbal communication skills
- Ability to influence and build effective working relationships with all levels of the organization
- Proficiency in multiple languages applicable to the region
- Familiarity with localization tactics to ensure content is accessible and inclusive across multiple APJ countries
What We Offer
- Competitive pay
- Generous time off
- Ample parental and wellness leave
- Healthcare
- Retirement savings program
- Much more
Compensation
The estimated pay ranges for this role are:
- Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $155,520.00 - $194,400.00
- Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00
- Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/twilio/jobs/8048657