Senior Security Engineer - Pentester
$158k - $237k per yearMenlo Security
Menlo Security is the leader in Browser Security for human and agentic workforces. Our mission is to enable humans and agents to connect, communicate, and collaborate securely, without compromise. The Menlo Browser Security Platform protects organizations from cyberattacks by stopping threats across the web, documents, and email before they reach the user. With Menlo Agent Runtime Security (MARS), that protection now extends to the AI agents working alongside every employee. Menlo Security is trusted by major global businesses, including Fortune 500 companies and government agencies, to protect their most valuable asset, their data, and is backed by top-tier investors.
Summary
We're looking for a forward-thinking Security Engineer to join our security team, focused on offensive and defensive testing, penetration testing of product features, and the cloud architecture behind the product. You'll operate across a complex multi-cloud environment (AWS & GCP) spanning traditional VMs and modern managed and unmanaged container-based architectures, partnering with fellow Penetration Testing and Cloud Security engineers to run targeted assessments during the testing window immediately before each release. The role reaches beyond the application layer into the Control Plane, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and extends to the frontline of external defense by triaging bug bounty submissions and outside vulnerability reports. AI and large language models are core to how this team works day to day — you'll use them to accelerate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, while applying human judgment to validate findings and communicate risk clearly to product teams. Speed matters here: the team's operating cadence is built around identifying, validating, and reporting vulnerabilities quickly enough to keep pace with release velocity.
Outcomes & KPIs
Key Outcome(s) Owned:
Ensure new product features and the underlying multi-cloud (AWS/GCP) infrastructure are rigorously security-tested before release, and that vulnerabilities surfaced internally or via bug bounty are triaged and communicated with speed and precision.
Success Metrics / KPIs :
Percentage of roadmap features assessed within the pre-release testing window.
Mean time to triage and validate bug bounty / external vulnerability reports.
Reduction in critical/high-severity vulnerabilities escaping to production post-release.
Time saved per assessment cycle through AI-assisted tooling and automation.
Quality and actionability of vulnerability reports and PoCs, as rated by product teams.
What You'll Do
Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.
Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.
Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).
Assess the security posture of hybrid infrastructure spanning containers and virtual machines.
Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.
Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.
Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.
Functional Competencies
Required:
Multi-Cloud Fluency: Deep architectural understanding of GCP and AWS. Capable of pivoting seamlessly between providers, performing manual configuration reviews of complex IAM/Resource hierarchies, and leveraging native APIs or modern CSPM frameworks to validate security controls.
Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).
AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage.
Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets). Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling. Strong understanding of browser security mechanisms (CSP, CORS, SameSite cookies, Subresource Integrity), secure authentication/authorization patterns (OAuth 2.0, OIDC, JWT), and security header configurations (HSTS, X-Frame-Options, Permissions-Policy). Proven ability to identify complex security flaws beyond automated scanner detection, validate findings through proof-of-concept development, and provide actionable remediation guidance to engineering teams.
Security Automation: Proficiency in Python, Go, or Bash to eliminate 'toil' — writing custom scripts and tooling to automate vulnerability discovery, validate security controls, and streamline testing workflows.
Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns; able to interpret and audit complex HCL files to identify misconfigurations before they are provisioned.
Communication: Ability to write high-quality technical reports that Product Teams can easily understand and act upon.
Preferred / Nice to Have:
Experience with Gatekeeper policies and Binary Authorization.
Our Compensation and Benefits
At Menlo Security, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is 158,000 CAD - 237,000 CAD.
In accordance with Canadian law, the range provided is Menlo Security’s reasonable estimate of the base compensation for this role. The actual amount may be higher or lower, based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance.
Menlo Security does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Menlo Security.
Menlo Security is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
MSGL-I4
Follow us on LinkedIn !
Why Menlo?
At Menlo, we don't settle for the status quo — in our technology or our culture. How we think and act is just as important as what we build. Our culture is defined by five core mindsets: Proactive Leadership , Straight Talk , United Impact , Elevated Talent , and Customer-Compelled . We take ownership and drive outcomes without waiting to be told. We communicate directly and seek hard truths. We break down silos and win together. We hold a high bar for ourselves and the people around us. And we treat every customer interaction as mission-critical. If you're someone who sees it, owns it, solves it, and does it — you'll thrive here.
All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability .
TO ALL AGENCIES: Please, no phone calls or emails to any employee of Menlo Security outside of the Talent organization. Menlo Security’s policy is to only accept resumes from agencies via Ashby (ATS). Agencies must have a valid services agreement executed and must have been assigned by the Talent team to a specific requisition. Any resume submitted outside of this process will be deemed the sole property of Menlo Security. In the event a candidate submitted outside of this policy is hired, no fee or payment will be paid.
$158k - $237k per year
...Menlo Security's mission is enabling the world to connect, communicate... ...a forward-thinking Security Engineer to join our security team, focused... ...working in tandem with a peer pentester. Review IAM policies,... ...cookies, Subresource Integrity), secure authentication/authorization...SeniorFull timeLocal areaImmediate start- ...-spirited. Role summary We are seeking hands-on Pentesters to join our Offensive Security team. You will be running our maturing offensive solution... ..., cloud (AWS/GCP/Azure), CI/CD & supply chain • Senior enough to run an engagement solo from scoping to delivery...SeniorFull timeRelocation package
$130k - $150k per year
...Tigera provides Calico, a unified network security and observability platform to prevent,... ...About Your Role Tigera is hiring a Senior Security Engineer to own product and cloud security... ...compliance requirements while building secure-by-default patterns and self-service guardrails...SeniorFull timeFlexible hours$120k - $130k per year
...connection. Reports to: Information Security Manager Location: Canada - Remote... ...About the Role Backcountry needs a senior security engineer to protect and harden the multi-cloud... ...tooling — with a growing mandate to govern secure AI adoption across engineering and...SeniorRemote jobFull timeInternshipWork at office$192k - $240k per year
...support you need to grow your career. Engineering at Brex Engineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy and... ...’ respective backlogs Caring about secure system design, valuing building things correctly...SeniorFull timeWork at officeRemote workWork from home- ...source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps... ...Ventures, Sequoia Capital, and Spark Capital. Senior Product Security Engineer The role in a...SeniorFull timeLocal areaRemote workFlexible hours
- ...support to make an impact as we build for the long term. About the role: As a member of our Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead...SeniorLong term contractFull timeRemote work
- ...COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product,...SeniorLong term contractFull timeWorldwide
$104k - $139k per year
...Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus... ...of Reviewer tools and automated moderation systems. As a Senior Software Engineer - Operations, you’ll bring a passion for crafting resilient...SeniorRemote jobFull timeImmediate startHome office$175k - $195k per year
...We are seeking a Senior Staff Information Security Engineer to help shape and advance security across our hybrid technology estate. Our environment spans... ...technical leadership across both environments, defining secure architecture patterns, building scalable controls, and...SeniorRemote jobFull timeWork at office- ...centric, global organization, apply below. Role Overview We are seeking a forward-thinking Senior Security Engineer, AI & DevSecOps to help shape the future of secure AI adoption across the organization. As part of the Information Security team, you will build...SeniorFull timeInternshipLocal areaFlexible hours
- ...center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default. As a Senior Security Engineer embedded in the Desktop engineering team, you will own the security posture of a...SeniorRemote jobFull timeHome officeShift work
$104k - $139k per year
...diverse areas including AI, social media, security and more. And we’re doing this while... ...community. Contribute to standards-based, secure, and interoperable implementations across... ...Collaborate on security initiatives: Partner with engineers across teams to identify, prioritize, and...SeniorRemote jobLong term contractFull timeImmediate startHome office- ...shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by... ...that makes this possible. This is not a traditional software engineering role. You'll spend most of your time working with YAML definition...SeniorFull timeRemote workHome officeShift work
- ...simplifying money, together. The Role: Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of... ...is critical in ensuring our application layer remains secure and resilient as we handle increasingly sensitive...SeniorFull timeInternshipWork at officeImmediate startRemote workWork from homeWeekend work
- ...taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic... ...experience in onboarding and managing our security product. As a Senior Software Engineer on the Security EDR Workflows team, you will help design and...Senior
$222.2k - $412.7k per year
...their data and AI are fully understood, secured, and resilient to enable the... ...posture management (DSPM) - is seeking a Senior Sales Engineer to drive technical leadership in our sales... ...the conversation shifts from “we need to secure our data” to “we need to enable safe, compliant...SeniorFull timeLocal areaRemote workWorldwideShift work- ...improve operational efficiency, reduce security and compliance risk, and accelerate... ...100* trust GitLab to ship better, more secure software faster. The same... ...An overview of this role As a Senior Corporate Security Engineer, you'll help secure the systems GitLab...SeniorFull timeRemote work
- ...improve operational efficiency, reduce security and compliance risk, and accelerate digital... ...100* trust GitLab to ship better, more secure software faster. The same principles... ...An overview of this role As a Senior Software Engineer on GitLab's Authorization team, you will...SeniorRemote jobFull time
$104k - $139k per year
...diverse areas including AI, social media, security and more. And we’re doing this while... ...open and accessible to all. As a Security Engineer, you'll protect that vision by building,... ...and influence long-term improvements in secure development practices Collaborate with...SeniorLong term contractFull timeImmediate startRemote workHome office$182.82k - $268.13k per year
...building award-winning games or crafting engine technology that enables others to make... ...'ll Do Epic Games is looking for a Senior Security Programmer focused on Game Security to develop... ...built are full-featured, resilient, and secure. This is an incredible opportunity to...SeniorLong term contractFull timeTemporary work- ...public company, you’ll have the autonomy and support to make an impact as we build for the long term. About the role: The Senior Security Engineer I - Enterprise Security is responsible for building, operating, and maintaining Samsara’s core security infrastructure. You...SeniorLong term contractFull timeRemote work
$218.42k - $302.84k per year
...building the new Internet by delivering software that makes it easy to securely interconnect people and their devices, no matter where they are.... .... Job Description We’re seeking a talented software engineer, specializing in security and infrastructure, to help grow our...Full timeInternshipWork at officeRemote workHome officeFlexible hours- ...achieve the extraordinary. Role Overview As the Manager of Security Engineering, you lead a specialized team of security engineers focused on... ...across AWS, you enable Acquia's Product teams to inherit a “secure by default” foundation. You act as the critical nexus between...Full timeLocal areaShift work
- ...the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy... ...own micro-VM sandbox. We're looking for an Engineering Manager to lead this team. It's a small, very senior group that recently came together, with strong...SeniorFull timeRemote workHome officeVisa sponsorshipShift workAfternoon shift
- ...The Security Product Management team is vital in safeguarding customer trust and making data... ...features such as Resource Policies, Secure by Default at MongoDB, and other security... ...access and risk of data loss. Partner with engineering to develop a prioritized product roadmap...SeniorFull timeInternshipWork at officeRemote workWorldwide
- ...Kraken is committed to industry-leading security , crypto education , and world-class... ...technology controls program, we are seeking a senior professional with a strong background in... ...of teams, including Finance, Technology, Engineering, and Security to inform sound, risk-based...SeniorFull timeLocal areaRemote work
- ...environment. Whether it’s building award-winning games or crafting engine technology that enables others to make visually stunning... ...utilize. What You'll Do Epic Games is looking for a Senior Game Security Programmer to join our Anti-Cheat team and work with not only...SeniorLong term contractFull timeTemporary work
- ...Responsibilities Identify and reduce security risk across AWS, Kubernetes,... ...design practical controls and secure-by-default patterns.... ...stakeholder groups. Requirements Senior-level experience in platform... ...security, or security engineering. Deep practical experience...SeniorFull timeWork at officeRemote workFlexible hours
$181k - $241k per year
...identity and authentication. This role is a hands-on engineering position inside Information Security, focused on designing and shipping core CIAM capabilities... ...signals, and downstream customer platforms. Own secure authentication and account flows end to end, including...Remote jobFull timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer - Pentester. Be the first to apply!
- product security engineer Remote
- security engineering manager Remote
- cloud security engineer Remote
- physical security engineer Remote
- aws security engineer Remote
- security engineer remote Remote
- senior manager risk management Remote
- senior electrical engineer Remote
- senior executive Remote
- senior network engineer Remote
