
Senior Security Engineer, Threat & Offensive Security
Valon Tech5 days ago
San Francisco, CA, USA or New York, NY, USASenior
Base Salary
$180k - $230k/yr
Responsibilities
- Conduct security testing and penetration tests across applications, infrastructure, and networks.
- Manage security testing tools and frameworks that simulate real-world attacks and validate security controls.
- Design and implement AI-enabled workflows to scale security testing and threat operations.
- Manage threat intelligence and adjust defenses proactively in response to emerging threats.
- Partner with external penetration-testing firms and perform security reviews of systems, features, architectures, and third-party integrations.
- Collaborate with Engineering, IT, Product, and other teams to remediate vulnerabilities and strengthen security controls.
- Develop playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response.
- Monitor security alerts and incidents, analyze data, and respond to security events.
- Support security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and general security reviews.
Requirements
- At least 5 years of experience in security engineering, penetration testing, threat intelligence, or similar roles.
- Bachelor's degree in Computer Science, Information Security, Technology, or a related field.
- Relevant security certification such as CISSP, CEH, OSCP, GPEN, or GCIH.
- Hands-on experience with security testing tools and frameworks such as Burp Suite, Metasploit, Nmap, or Cobalt Strike.
- Experience using AI and automation to improve threat detection, testing, and response operations.
- Proficiency with manual and automated testing techniques and understanding of common attack and exploitation methods.
- Knowledge of MITRE ATT&CK or related frameworks and experience with SIEM, EDR, detection, and monitoring platforms.
- Experience with cloud security and cloud environments, including GCP or AWS.
- Applied knowledge of OWASP, NIST, MITRE ATT&CK, CIS, and SOC 2/ISO 27001 concepts.
- Ability to work autonomously, lead projects, investigate complex security issues, communicate findings to technical and non-technical stakeholders, and partner effectively with stakeholders.
- Startup experience is a plus.
Benefits
- Base salary range of $180K-$230K for New York City staff, varying by location.
- Meaningful equity stake and 401(k) plan.
- Comprehensive medical, dental, and vision benefits plus physical and mental well-being support.
- Pre-tax commuter benefits for public transportation, rideshare services, and parking.
- Company orientation, learning and development opportunities, and regular 360-degree feedback reviews.
- Quarterly budgets for team and company outings.
- Flexible paid time off, sick days, and 11 company holidays.
- 12 weeks of fully paid bonding leave for birthing and non-birthing parents.
- Remote work is fully supported; offices are located in New York City and San Francisco.