Twilio

Staff Engineer - Offensive Security

Twilio
Apply
2 months ago
Remote, United StatesStaff+
H1B Sponsor

Base Salary

$156k - $229k/yr

Responsibilities

  • Perform manual and automated penetration testing of web applications, APIs, and iOS/Android mobile apps.
  • Conduct internal and external network, cloud, and infrastructure assessments, including attacks against AWS, Azure, and Kubernetes environments.
  • Triage and validate automated scanner and bug bounty reports, distinguishing false positives from real vulnerabilities.
  • Test AI prototypes, services, and applications for prompt injection and jailbreak vulnerabilities using established LLM security checklists.
  • Write technical reports describing paths to compromise with clear, reproducible remediation steps.
  • Maintain testing infrastructure, including Burp Suite and basic C2 listeners.
  • Advise engineering teams on remediating XSS, SQL injection, IDOR, and other vulnerabilities.
  • Design and lead multi-week red-team operations that emulate specified threat actors and assess SIRT detection capabilities.
  • Develop custom payloads, droppers, and obfuscated scripts to bypass EDR/AV controls and maintain stealth.
  • Build automated AI security testing frameworks using tools such as PyRIT, Promptfoo, or Garak.
  • Execute sophisticated cloud and infrastructure attacks focused on IAM misconfigurations and container escapes.
  • Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on engagement techniques.
  • Oversee the bug bounty program and identify submission trends that support broader architectural security improvements.

Requirements

  • 7-10 years of experience in offensive security, penetration testing, high-volume bug bounty work, AppSec, or vulnerability exploitation, with a record of finding high- or critical-severity vulnerabilities in complex environments.
  • Expertise in MITRE ATT&CK, OWASP Top 10 for web applications and LLMs, post-exploitation techniques, and adversarial machine learning.
  • Proficiency with Burp Suite Professional, Nmap, Metasploit, Wireshark, AI security tooling, and C2 frameworks such as Cobalt Strike, Sliver, or Havoc.
  • Ability to write Python or Bash scripts and code in Python and C++ for custom offensive exploits and automated testing.
  • Advanced industry certifications such as OSCP, OSEP, OSWE, or GXPN are highly desirable.
  • Telecom expertise is preferred.
  • Strong written and verbal communication, relationship-building, regional language proficiency, and familiarity with localization tactics are desired.

Benefits

  • Remote-first work arrangement, with occasional travel for project or team in-person meetings.
  • Healthcare insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave, wellness leave, and generous time off.
  • Potential eligibility for equity and corporate bonus plans.
  • Role is not eligible for hiring in California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., or Washington State.
  • Applications are intended to be accepted until August 31, 2026, subject to change based on business needs.

Tech Stack

Categories