# Staff Engineer - Offensive Security

**Company**: Twilio
**Location**: Remote - US
**Work arrangement**: remote
**Experience**: staff
**Job type**: full-time
**Salary**: $155,520.00 - $194,400.00
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/twilio/jobs/8048657?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_81a5db72-3dc

## Description

## Job Overview

As a Staff Engineer - Offensive Security at Twilio, you will act as a Technical Lead, designing complex attack chains that demonstrate systemic risk. You will spend time writing custom code, researching new bypasses, and executing tests.

## Responsibilities

- Perform full-stack penetration testing of web applications, APIs, and mobile apps (iOS/Android)

- Conduct internal/external network audits with various tooling

- Validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives

- Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications

- Draft high-quality reports detailing the 'path to compromise' with clear, reproducible steps for developers

- Manage and update the team's testing infrastructure (e.g., Burp Suite, basic C2 listeners)

- Provide direct technical guidance to engineering teams on how to patch vulnerabilities

- Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities

- Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth

- Build automated testing frameworks for AI systems to test for models related to sensitive data leakage

- Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes

- Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on techniques used during an engagement

- Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes

## Qualifications

### Required

- 7-10 years of experience in offensive security, penetration testing, or vulnerability exploitation

- Expert knowledge of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs

- Proficiency in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark, etc.

- Ability to write functional scripts in Python or Bash to automate repetitive testing tasks

- Proficiency in coding and scripting like Python, C++

- Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable

### Desired

- Excellent written and verbal communication skills

- Ability to influence and build effective working relationships with all levels of the organization

- Proficiency in multiple languages applicable to the region

- Familiarity with localization tactics to ensure content is accessible and inclusive across multiple APJ countries

## What We Offer

- Competitive pay

- Generous time off

- Ample parental and wellness leave

- Healthcare

- Retirement savings program

- Much more

## Compensation

The estimated pay ranges for this role are:

- Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $155,520.00 - $194,400.00

- Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00

- Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00

## Skills

### Required
- MITRE ATT&CK matrix
- OWASP Top 10
- Burp Suite
- Nmap
- Metasploit
- Wireshark
- Python
- Bash
- C++

### Nice to have
- Excellent written and verbal communication skills
- Ability to influence and build effective working relationships
- Proficiency in multiple languages
- Familiarity with localization tactics

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/twilio/jobs/8048657?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
