New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Twilio

Staff Engineer - Offensive Security

Twilio
Apply →
remote staff full-time $155,520.00 - $194,400.00 Remote - US

First indexed 9 Jul 2026

Description

Job Overview

As a Staff Engineer - Offensive Security at Twilio, you will act as a Technical Lead, designing complex attack chains that demonstrate systemic risk. You will spend time writing custom code, researching new bypasses, and executing tests.

Responsibilities

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps (iOS/Android)
  • Conduct internal/external network audits with various tooling
  • Validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives
  • Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications
  • Draft high-quality reports detailing the 'path to compromise' with clear, reproducible steps for developers
  • Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners)
  • Provide direct technical guidance to engineering teams on how to patch vulnerabilities
  • Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities
  • Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth
  • Build automated testing frameworks for AI systems to test for models related to sensitive data leakage
  • Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes
  • Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on techniques used during an engagement
  • Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes

Qualifications

Required

  • 7-10 years of experience in offensive security, penetration testing, or vulnerability exploitation
  • Expert knowledge of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs
  • Proficiency in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark, etc.
  • Ability to write functional scripts in Python or Bash to automate repetitive testing tasks
  • Proficiency in coding and scripting like Python, C++
  • Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable

Desired

  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with all levels of the organization
  • Proficiency in multiple languages applicable to the region
  • Familiarity with localization tactics to ensure content is accessible and inclusive across multiple APJ countries

What We Offer

  • Competitive pay
  • Generous time off
  • Ample parental and wellness leave
  • Healthcare
  • Retirement savings program
  • Much more

Compensation

The estimated pay ranges for this role are:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $155,520.00 - $194,400.00
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00
  • Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/twilio/jobs/8048657