Ecolab

Lead Offensive Security Engineer

Ecolab$120K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
  • 8+ years of hands-on experience in cybersecurity, application security, offensive security, or related technical field.
  • Hands-on experience performing technical security testing for web/mobile applications, APIs, cloud services, and IoT products.
  • Experience leading offensive security engagements and vulnerability assessments.
  • Proficient in Microsoft Azure; familiarity with AWS or GCP cloud security concepts.
  • Knowledge of secure software development and DevSecOps practices.
  • Strong communication skills for conveying technical findings to diverse stakeholders.

Responsibilities

  • Lead hands-on offensive security testing across Ecolab's commercial products.
  • Plan and execute security assessments to identify vulnerabilities and insecure configurations.
  • Manage and mentor a small internal offensive security team while staying involved in testing.
  • Develop standards and methodologies for offensive security testing and reporting.
  • Collaborate with cross-functional teams to translate testing results into actionable remediation plans.
  • Conduct authorized testing on IoT and industrially connected equipment, including physical access testing.
  • Prepare and present clear, actionable reports detailing vulnerabilities and remediation guidance.

Benefits

  • Comprehensive and market-competitive benefits for associates and their families.
  • Flexibility in work schedule to accommodate global activities.
Full Job Description

The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Lead Offensive Security Engineer will actively perform security testing for most of their time while also leading a small internal team, helping define engagement scope, testing methods, reporting standards, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab’s commercial offerings.


What you will do:

  • Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.

  • Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.

  • Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.

  • Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.

  • Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.

  • Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.

  • Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.

  • Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.

  • Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.

  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.

  • Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.

  • Help improve Ecolab’s vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.

  • Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.

  • Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.

  • Act as an advocate and champion for practical, risk-based product security across Ecolab’s commercial digital product teams.

Minimum Qualifications:

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.

  • 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.

  • Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.

  • Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.

  • Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.

  • Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.

  • Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.

  • Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.

  • Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.

  • Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.

  • Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.

  • Strong interpersonal, analytical, problem-solving, organizational, and written/verbal communication skills.

  • Ability to communicate technical findings clearly to software engineers, architects, cybersecurity leaders, product owners, and non-technical business stakeholders.

  • Ability to accommodate a flexible work schedule for supporting global activities.

Preferred Qualifications:

  • Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications.

  • Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.

  • Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.

  • Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.

  • Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.

  • Experience developing testing playbooks, reporting templates, engagement standards, risk-rating models, and remediation validation procedures.

  • Experience with AI-enabled products, AI integrations, or the security implications of AI/ML capabilities in commercial software environments.

  • Ability to influence without authority and drive security improvements across globally distributed engineering, product, and technology teams.

Annual or Hourly Compensation Range

The base salary range for this position is $120,500.00 - $180,700.00. This position is eligible for annual bonus pay based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families.  to see our benefits. 

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.


About Ecolab

Ecolab provides comprehensive solutions, data-driven insights, and personalized service to customers in the food, healthcare, hospitality, and industrial markets in more than countries to advance food safety, maintain clean and safe environments, optimize water and energy use, and improve operational efficiencies and sustainability.

Ecolab Careers

Join Ecolab's dynamic team today and be part of a global leader in water, hygiene, and infection prevention solutions. At Ecolab, we are committed to advancing technologies and driving innovation that makes the world cleaner, safer, and healthier.

Work You’ll Do

At Ecolab, you will find job opportunities that promise robust growth and development in a culture that fosters leadership, innovation, and diversity. Our team is composed of over 48,000 dedicated professionals who lead the industry in delivering efficient solutions and services to our customers worldwide.

Professional Growth and Development

Embark on a career path that empowers your ambition. Ecolab offers a myriad of career advancement opportunities supported by comprehensive training programs and professional development courses. Our commitment to your growth is paralleled by our dedication to innovation and excellence in every aspect of our business.

Inclusive and Supportive Culture

Ecolab’s culture thrives on teamwork, respect, and diversity. We believe in creating an inclusive environment that values each individual’s unique background and perspectives. Diversity training and leadership programs are integral parts of our commitment to fostering an inclusive workplace.

Internship and Employment Opportunities

Whether you're starting your career or looking to make a change, Ecolab offers a range of employment and internship opportunities that can help you harness your skills and achieve your professional goals. Our hiring process is designed to be transparent and engaging, ensuring that all candidates are given the opportunity to showcase their strengths.

Benefits and Networking

Joining Ecolab means more than just employment; it’s an opportunity to be part of a global network of industry leaders and innovators. Our employees enjoy competitive benefits, including health, life, and dental insurance, retirement plans, and paid time off. We also encourage our team to connect and collaborate through various professional networking events.

Explore Job Opportunities

Are you ready to make a significant impact? Explore the various positions available at Ecolab, from entry-level roles to executive positions. Tailor your resume and prepare for interviews with our career experts who are here to support you every step of the way.

Stay Connected

Join Our Team Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players.

SEARCH ECOLAB JOBS

Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at Ecolab. Ecolab is not just a company; it's a place where you can make a difference in the world while advancing your career in a dynamic and supportive environment. Join us in making the world a better place through dedicated service and innovative solutions.
Learn more about Ecolab
Size
47,000 employees
Market Cap
$41 billion
Industry
Net Income
-$1.2 billion
Founded
1923
5 Year Trend
-0.6%
Revenue
$11.7 billion
NASDAQ

Similar Jobs

More Jobs at Ecolab

More Information Technology Jobs

Find similar Lead Offensive Security Engineer jobs: