Snap Inc

Security Engineer, Level 5, Offensive Security

Snap Inc • $209K — $313K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of post-Bachelor's security-related experience, or 5+ years with a Master's, or 2+ years with a PhD.
  • Proven track record in leading offensive security engagements and coordinating multiple security engineers.
  • Expertise in at least four areas such as OS internals, networking, and cloud infrastructure (AWS/GCP).
  • Proficiency in coding with modern languages like Java, Python, or Go.
  • Experience with scripting languages like Bash and PowerShell for task automation.
  • Familiarity with threat modeling and establishing killchains.

Responsibilities

  • Design and lead offensive security engagements across various environments.
  • Understand real-world threats and collaborate with the threat intelligence team to prioritize engagements.
  • Deliver post-engagement reports that assess security posture and recommend improvements.
  • Implement and manage offensive security tools for covert operations and testing defenses.
  • Collaborate with security teams to share insights and identify areas for improvement.
  • Act as a subject matter expert for other teams in security reviews and incident responses.
  • Research novel security topics to enhance the company's security framework.

Benefits

  • Paid parental leave to support family needs.
  • Comprehensive medical coverage for physical health.
  • Emotional and mental health support programs available.
  • Compensation packages include equity through RSUs to share in company success.
  • Encouragement of a balanced work-life approach with a focus on community.
Full Job Description
We're looking for a Security Engineer to join our Offensive Security Team! What you'll do: • Design, execute, and lead offensive security and privacy engagements, including red, purple, and orange team exercises, across corporate environments, cloud projects/accounts, internal applications, and mobile client applications. • Maintain a comprehensive understanding of real-world threat actors, their tools, tactics, and procedures, with a propensity to target Snap, collaborating extensively with the threat intelligence team to enumerate exhaustive killchains that seed and prioritize the future engagement roadmap. • Deliver detailed post-engagement reports that identify vulnerabilities, highlight strengths and weaknesses in our security posture, assess detection coverage, and provide actionable recommendations, including prioritized risk mitigation strategies and improvements to defensive measures. • Implement and manage offensive security engagement infrastructure and tooling to conduct covert operations and mimic the tactics of relevant adversaries, including the development of custom implants, payloads, and exploits to thoroughly test and evaluate our defenses. • Collaborate closely with other security and privacy teams to share insights from engagements, informing strategic roadmaps by identifying priority areas for improvement and aligning on initiatives. • Serve as a subject matter expert and consultant to other security and privacy teams, participating in security reviews, reproducing vulnerabilities, and contributing to high-stakes incident response efforts. • Explore novel research topics relevant to our tech stack to proactively improve our security posture and integrate lessons learned into future exercises. Knowledge, Skills & Abilities: • Proven experience in leading offensive security engagements, coordinating multiple security engineers, and managing and executing assessments to thoroughly test and evaluate security measures. • Expert knowledge in four or more of the following: operating system internals, networking, application development, mobile client development, Kubernetes, cloud infrastructure (AWS/GCP), and payload/implant/exploit development. • Coding proficiency in one or more modern languages, including Java, Python, Go, etc. • Adept at threat modeling and establishing killchains • Proficiency in scripting languages like Bash and PowerShell to automate security tasks and improve efficiency of engagements. • Possess an insatiable drive for learning and the ability to thrive in new, unique, and complex technical environments, with the capability to build a foundational understanding and effectively apply it within the context of engagements. Minimum Qualifications: • Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field • You may also provide evidence of personal security research (CVEs or blogs), public bug bounty reports, previous CTF participation, and/or code repositories on GitHub showcasing personally developed security tools • 6+ years of post-Bachelor's security related experience; or Master's degree in a technical field + 5+ year of post-grad security related experience; or PhD in a relevant technical field + 2+ years of post-grad security related experience Preferred Qualifications: • Familiar with frameworks like ATT&CK to represent tools, tactics, and procedures. • Experience in leading or participating in incident response efforts, with a deep understanding of digital forensics, detection engineering, and threat hunting. • Proven ability to work effectively with cross-functional teams at all-levels, including developers, IT, and executive leadership, to align security measures with organizational goals. "Default Together" Policy at Snap: At Snap Inc. we believe that being together in person helps us build our culture faster, reinforce our values, and serve our community, customers and partners better through dynamic collaboration. To reflect this, we practice a "default together" approach and expect our team members to work in an office 4+ days per week. Our Benefits: Snap Inc. is its own community, so we've got your back! We do our best to make sure you and your loved ones have everything you need to be happy and healthy, on your own terms. Our benefits are built around your needs and include paid parental leave, comprehensive medical coverage, emotional and mental health support programs, and compensation packages that let you share in Snap's long-term success! Compensation In the United States, work locations are assigned a pay zone which determines the salary range for the position. The successful candidate's starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. The starting pay may be negotiable within the salary range for the position.These pay zones may be modified in the future. Zone A (CA, WA, NYC): The base salary range for this position is $209,000-$313,000 annually. Zone B: The base salary range for this position is $199,000-$297,000 annually. Zone C: The base salary range for this position is $178,000-$266,000 annually. This position is eligible for equity in the form of RSUs. If you believe this job description is missing required pay transparency information, please submit a report through this form:Job Description Pay Range Disclosure

About Snap Inc

Snap Inc. is a camera and social media company. It was founded in 2011 by Evan Spiegel, Bobby Murphy, and Reggie Brown. The company is known for its Snapchat app, which allows users to send photos and videos that disappear after being viewed. Snap Inc. is headquartered in Santa Monica, California and has offices around the world. The company went public in 2017 and is listed on the New York Stock Exchange.
Learn more about Snap Inc
Size
5,661 employees
Market Cap
$13.9 billion
Industry
Net Income
-$944.8 million
Founded
2016
5 Year Trend
+59.1%
Revenue
$2.5 billion
NASDAQ

Similar Jobs

More Jobs at Snap Inc

More Information Technology Jobs

Find similar Security Engineer, Level 5, Offensive Security jobs: