Senior Security Engineer, Threat & Offensive Security
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Security Engineer strengthening offensive security and threat operations. Protecting Valon’s AI-native mortgage servicing platform for regulated finance.
Responsibilities:
- Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities
- Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls
- Design and implement AI-enabled workflows to scale security testing and threat-related operations
- Manage and operationalize threat intelligence to anticipate emerging threats and adjust defenses proactively
- Partner with external pentesting firms for periodic independent reviews
- Perform security reviews of new systems, features, architectures, and third-party integrations, providing actionable risk-based recommendations
- Collaborate with Engineering, IT, Product, and other teams to remediate vulnerabilities and strengthen security controls
- Develop and refine playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response
- Monitor and manage security alerts and incidents, analyze data, and respond to security events
- Support general security reviews, security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and other security processes
Requirements:
- Minimum of 5 years in a security engineering, penetration testing, threat intelligence, or similar role with relevant responsibilities and background
- Bachelor's degree in Computer Science, Information Security, Technology, or a related field
- Relevant security certifications (e.g., CISSP, CEH, OSCP, GPEN, GCIH or similar)
- Knowledge of cloud environments
- Experience with security testing, monitoring, and response technologies (threat intelligence platforms, vulnerability scanners, SIEM, EDR, or similar)
- Hands-on experience with security testing tools and frameworks such as Burp Suite, Metasploit, Nmap, Cobalt Strike, or similar
- Demonstrated experience leveraging AI and automation to improve threat detection, testing, and response operations
- Proficiency in manual and automated testing techniques
- Strong understanding of common attack techniques, exploitation methods, and MITRE ATT&CK or related frameworks
- Experience with SIEM, EDR, and other detection/monitoring platforms
- Experience with cloud security and environments including GCP and AWS
- Applied knowledge of OWASP, NIST, MITRE ATT&CK, CIS, SOC 2/ISO 27001 concepts
- Ability to work autonomously, lead projects, and navigate complex, ambiguous security investigations
- Excellent communication and collaboration skills, including explaining technical findings and risk to technical and non-technical stakeholders
- Experience or exposure to startup environments is a plus
Benefits:
- Competitive salary with a meaningful stake in the company via equity
- 401k plan
- Comprehensive medical, dental, & vision benefits
- Pre-tax commuter benefits for public transportation, rideshare services, and parking expenses
- Company-wide orientation and learning & development opportunities
- Regular review cycles featuring 360 degree feedback
- Quarterly budgets for team and company outings
- Flexible paid time off
- Sick days
- 11 company holidays
- 12 weeks fully paid baby bonding time for birthing and non-birthing parents



















