Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer - Pentester

$158k - $237k per year
Full-time

Menlo Security

Menlo Security is the leader in Browser Security for human and agentic workforces. Our mission is to enable humans and agents to connect, communicate, and collaborate securely, without compromise. The Menlo Browser Security Platform protects organizations from cyberattacks by stopping threats across the web, documents, and email before they reach the user. With Menlo Agent Runtime Security (MARS), that protection now extends to the AI agents working alongside every employee. Menlo Security is trusted by major global businesses, including Fortune 500 companies and government agencies, to protect their most valuable asset, their data, and is backed by top-tier investors.

Summary

We're looking for a forward-thinking Security Engineer to join our security team, focused on offensive and defensive testing, penetration testing of product features, and the cloud architecture behind the product. You'll operate across a complex multi-cloud environment (AWS & GCP) spanning traditional VMs and modern managed and unmanaged container-based architectures, partnering with fellow Penetration Testing and Cloud Security engineers to run targeted assessments during the testing window immediately before each release. The role reaches beyond the application layer into the Control Plane, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and extends to the frontline of external defense by triaging bug bounty submissions and outside vulnerability reports. AI and large language models are core to how this team works day to day — you'll use them to accelerate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, while applying human judgment to validate findings and communicate risk clearly to product teams. Speed matters here: the team's operating cadence is built around identifying, validating, and reporting vulnerabilities quickly enough to keep pace with release velocity.

Outcomes & KPIs

Key Outcome(s) Owned:

  • Ensure new product features and the underlying multi-cloud (AWS/GCP) infrastructure are rigorously security-tested before release, and that vulnerabilities surfaced internally or via bug bounty are triaged and communicated with speed and precision.

Success Metrics / KPIs :

  • Percentage of roadmap features assessed within the pre-release testing window.

  • Mean time to triage and validate bug bounty / external vulnerability reports.

  • Reduction in critical/high-severity vulnerabilities escaping to production post-release.

  • Time saved per assessment cycle through AI-assisted tooling and automation.

  • Quality and actionability of vulnerability reports and PoCs, as rated by product teams.

What You'll Do

  • Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.

  • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.

  • Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).

  • Assess the security posture of hybrid infrastructure spanning containers and virtual machines.

  • Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.

  • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.

  • Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.

Functional Competencies

Required:

  • Multi-Cloud Fluency: Deep architectural understanding of GCP and AWS. Capable of pivoting seamlessly between providers, performing manual configuration reviews of complex IAM/Resource hierarchies, and leveraging native APIs or modern CSPM frameworks to validate security controls.

  • Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).

  • AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage.

  • Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets). Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling. Strong understanding of browser security mechanisms (CSP, CORS, SameSite cookies, Subresource Integrity), secure authentication/authorization patterns (OAuth 2.0, OIDC, JWT), and security header configurations (HSTS, X-Frame-Options, Permissions-Policy). Proven ability to identify complex security flaws beyond automated scanner detection, validate findings through proof-of-concept development, and provide actionable remediation guidance to engineering teams.

  • Security Automation: Proficiency in Python, Go, or Bash to eliminate 'toil' — writing custom scripts and tooling to automate vulnerability discovery, validate security controls, and streamline testing workflows.

  • Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns; able to interpret and audit complex HCL files to identify misconfigurations before they are provisioned.

  • Communication: Ability to write high-quality technical reports that Product Teams can easily understand and act upon.

Preferred / Nice to Have:

  • Experience with Gatekeeper policies and Binary Authorization.

Our Compensation and Benefits

At Menlo Security, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is 158,000 CAD - 237,000 CAD.

In accordance with Canadian law, the range provided is Menlo Security’s reasonable estimate of the base compensation for this role. The actual amount may be higher or lower, based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance.

Menlo Security does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Menlo Security.

Menlo Security is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

MSGL-I4

Follow us on LinkedIn !

Why Menlo?

At Menlo, we don't settle for the status quo — in our technology or our culture. How we think and act is just as important as what we build. Our culture is defined by five core mindsets: Proactive Leadership , Straight Talk , United Impact , Elevated Talent , and Customer-Compelled . We take ownership and drive outcomes without waiting to be told. We communicate directly and seek hard truths. We break down silos and win together. We hold a high bar for ourselves and the people around us. And we treat every customer interaction as mission-critical. If you're someone who sees it, owns it, solves it, and does it — you'll thrive here.

All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability .

TO ALL AGENCIES: Please, no phone calls or emails to any employee of Menlo Security outside of the Talent organization. Menlo Security’s policy is to only accept resumes from agencies via Ashby (ATS). Agencies must have a valid services agreement executed and must have been assigned by the Talent team to a specific requisition. Any resume submitted outside of this process will be deemed the sole property of Menlo Security. In the event a candidate submitted outside of this policy is hired, no fee or payment will be paid.

Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer - Pentester in Remote vacancy
  • $136.8k - $171k per year

     ...investigation, escalation, and response for complex security alerts and incidents in North American time zones. Participate in a 24x7x365 on-call rotation as a senior incident response escalation resource. Engineer and optimize detection logic, detection coverage mapping... 
    Senior
    Full time
    Remote work
    Flexible hours

    Marqeta

    Remote
    1 day ago
  •  ...lead IAM strategies aligned with cloud-native architecture and security principles. Build and operationalize IGA, PAM, SSO, MFA, access...  ...access controls and policy automation. Mentor junior engineers and serve as technical lead for IAM-related projects. Collaborate... 
    Senior
    Full time
    Remote work
    Flexible hours

    Marqeta

    Remote
    5 days ago
  • $104k - $139k per year

     ...Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus...  ...of Reviewer tools and automated moderation systems.  As a Senior Software Engineer - Operations, you’ll bring a passion for crafting resilient... 
    Senior
    Full time
    Immediate start
    Remote work
    Home office

    Mozilla

    Remote
    10 days ago
  •  ...time zones. Join us on our mission to transform lives by simplifying money, together. The Role: Monarch is hiring a Senior Security Engineer, Detection and Response to join our Security team within Foundations — the first dedicated hire for this function. Reporting... 
    Senior
    Full time
    Internship
    Work at office
    Immediate start
    Remote work
    Work from home
    Weekend work

    Monarch Money

    Remote
    14 days ago
  •  ...Back to jobs New Senior Security Engineer Remote, Canada Apply At Shakepay, we’re on a mission to usher in the Bitcoin golden age. We’re reimagining financial services to give every Canadian their fair shake. Our culture is built around doing work that matters, winning as a... 
    Senior
    Long term contract
    Full time
    Remote work

    Shakepay

    Remote
    13 days ago
  •  ...simplifying money, together. The Role: Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of...  ...is critical in ensuring our application layer remains secure and resilient as we handle increasingly sensitive... 

    Monarch Money

    Remote
    3 hours ago
  •  ...improve operational efficiency, reduce security and compliance risk, and accelerate...  ...100* trust GitLab to ship better, more secure software faster. The same principles built...  ...of security findings. As a Senior Security Risk Engineer, you'll take ownership of risk identification... 
    Senior
    Full time

    Gitlab

    Remote
    8 days ago
  •  ...a real impact. This position is for an existing vacancy. As Senior Security Engineer, you'll report to the VP of Engineering and work closely with...  ...that detect and stop threats, partner with engineering on secure-by-design practices, and act as the front-line responder when... 
    Senior
    Full time

    Roofr

    Remote
    23 days ago
  • $159k - $219k per year

     ...Responsibilities Architect and enforce security controls for AI/ML systems, including...  ...integrity, and auditability controls for secure AI operations. Embed security, privacy...  ...collateral to support enterprise deals. Mentor engineering teams and promote a security-first... 
    Senior
    Full time

    AlphaSense

    Remote
    14 days ago
  •  ...software features in collaboration with the engineering team. Triage, prioritize, investigate,...  ...Threat-model new features and review security-sensitive designs to identify risks early...  ...reviews, and technical discussions. Improve secure defaults and security practices across... 
    Senior
    Full time
    Internship
    Remote work
    Flexible hours

    vCluster Labs

    Remote
    8 days ago
  •  ...focused on two new major product lines coming to market in the next few months. Join us!! The Role  We're hiring a Staff/Senior Security Engineer to lead our signing and treasury security program across wallets and custodian accounts. This is a high-impact, mission-... 
    Senior
    Contract work
    Remote work
    Flexible hours

    Ethena Labs

    Remote
    12 days ago
  •  ...transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands...  ...us at Zscaler. We are looking for a Principal Specialist Sales Engineer for Data Security serving our customers in Canada. This reports... 
    Senior
    Full time
    Remote work

    Zscaler

    Remote
    7 days ago
  •  ...people who want to help us build something truly special. About the security team Security at Shakepay is a company-wide responsibility,...  ..., and emerging areas such as AI security. We work closely with Engineering, Platform, Risk, Compliance, and Product to build pragmatic... 
    Long term contract
    Full time

    Shakepay

    Remote
    3 days ago
  •  ...Responsibilities Run security assessments and threat models for cloud-native and SaaS products...  ...application architectures and promote secure-by-default controls. Build and...  ...-technical stakeholders. Partner with engineering teams, share security knowledge, and improve... 
    Full time
    Work at office
    Work from home
    Flexible hours

    Atlassian

    Remote
    6 days ago
  •  ...If you’re this person, we’d love to talk to you. THE ROLE Secure BJAK’s AI-enabled products and agent workflows using third-party...  ...links, and other untrusted inputs. – Partner with Product and Engineering on safe document ingestion, content handling, output validation,... 
    Remote work

    Bjak

    Remote
    5 days ago
  •  ...distribution, Ubuntu underpins the security of the entire internet. The role of Security Engineering Manager directly impacts the...  ...to emerging threats and aim to secure the open source ecosystem for community...  ..., ranging from graduate to senior Provide technical guidance on... 
    Senior
    Full time
    Local area
    Remote work
    Worldwide

    Canonical

    Remote
    9 days ago
  •  ...surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role We're hiring a Senior Product Security Engineer to build and operate the modern security tooling pipeline that underpins everything our Product Security team does. You'll... 
    Senior
    Full time

    Beyondtrust

    Remote
    10 days ago
  •  ...enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading...  ...profitable, and growing. Canonical is looking for exceptional security-focused software engineers to be integrated across product... 
    Long term contract
    Full time
    Work at office
    Local area
    Remote work
    Worldwide

    Canonical

    Remote
    10 days ago
  •  ...Job Overview We are looking for an experienced Network Security Engineer to design, implement, monitor, and support enterprise security infrastructure...  ...and hybrid infrastructure Configure and support SD-WAN and Secure Access Service Edge (SASE) solutions Conduct vulnerability... 
    Remote work

    Uvation

    Remote
    13 days ago
  • $225k - $275k per year

     ...individual contributor position embedded in the Security Engineering organization, focused on Wirespeed’s...  ...and code reviews. Mentor and guide senior engineers, helping them navigate complex...  ...decisions and develop scalable, secure solutions. Skills and Qualifications... 
    Senior
    Long term contract
    Fixed term contract
    Work at office
    Remote work
    Home office
    Flexible hours

    Coalition, Inc.

    Remote
    13 days ago
  •  ...using Pantheon's collaborative workflows. The Role Pantheon's Security Engineering team is responsible for safeguarding, auditing, and testing...  ...Performance: Help engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based... 
    Full time

    Pantheon

    Remote
    14 days ago
  • $160.32k - $200.4k per year

     ...That said, every hiring decision is made by real Twilions! . See yourself at Twilio Join the team as Twilio’s next Staff Engineer, Security Engineering Partners. About the job We are actively recruiting for this role to fill an existing vacancy. This position is... 
    Full time
    Local area
    Remote work
    Worldwide

    Twilio

    Remote
    1 day ago
  •  ...AI Security Researcher / Research Engineer Remote or hybrid - London preferred but North America, EU, UK accepted...  ...by default, a private search engine with a truly independent index, private...  ...this role, you'll design and implement secure-by-design architectures, audit our... 
    Full time
    Remote work

    Brave

    Remote
    6 days ago
  •  ...If you’re this person, we’d love to talk to you. THE ROLE Secure BJAK’s web applications, APIs, and backend services, coordinating...  ...integrations, and major changes. – Coordinate with mobile engineers on cross-platform findings and backend controls protecting native... 
    Full time
    Remote work

    Bjak

    Remote
    5 days ago
  •  ...third-party services. Partner with Data, Engineering, Product, Legal, and Compliance to apply...  ...– Map data flows and assess privacy and security risks across applications, analytics, integrations...  ...– Work with data engineering teams to secure pipelines, databases, warehouses, and... 
    Full time
    Remote work

    Bjak

    Remote
    5 days ago
  •  ...YOU WILL BUILD – Design and maintain security controls across AWS and GCP infrastructure...  ...encryption, key management, secrets, and secure connectivity. – Improve cloud security...  ...business continuity, and secure operations with engineering teams. WHAT WE LOOK FOR – Degree in... 
    Remote work

    Bjak

    Remote
    5 days ago
  •  ...connections to backend services. Work with mobile, backend, and security teams to build mobile security into development and release processes...  ..., test coverage, and remediation priorities. – Assess secure local storage, Keychain and Keystore use, sensitive data handling... 
    Local area
    Remote work

    Bjak

    Remote
    5 days ago
  •  ...from evolving threats. We manage security risk, monitor vulnerabilities,...  ...at Affirm. We maintain a secure, trustworthy environment so the...  ...Privacy, Compliance, IT, and Engineering to make it scalable and repeatable...  ...response playbooks as a senior escalation point. - You will lead... 
    Senior
    Full time

    Affirm

    Remote
    23 days ago
  •  ...Build, maintain, configure, and continuously improve product security tooling pipelines across the software development lifecycle....  ...Partner with Security Testers, Security Architects, the TPM, and engineering teams on findings, policies, reporting, configuration, and troubleshooting... 
    Senior
    Full time
    Flexible hours

    BeyondTrust

    Remote
    9 days ago
  •  ...improve operational efficiency, reduce security and compliance risk, and accelerate digital...  ...100* trust GitLab to ship better, more secure software faster. The same principles...  ...GitLab. An overview of this role As a Senior Software Engineer on GitLab's Authorization team, you will... 
    Senior
    Full time

    Gitlab

    Remote
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer - Pentester. Be the first to apply!