What you will doMcMaster-Carr is seeking a
Senior Offensive Security Engineer to build and operate an independent security assurance capability within Internal Audit. Using penetration testing, adversary emulation, and purple-team techniques, you will evaluate whether our cybersecurity controls work as intended against realistic scenarios.
This is not a conventional penetration-testing role focused only on finding vulnerabilities. As a member of McMaster-Carr's Internal Audit team, your work will help determine whether controls prevent attacks, whether monitoring produces meaningful alerts, whether response processes work, and where security investments should be strengthened. You will translate technical findings into practical risk insight and solutions for Information Security, business leaders, executive management, and the Audit Committee.
Work is independent yet collaborative with strong governance. You will partner closely with Information Security while remaining organizationally independent from the teams responsible for designing and operating the controls you assess.
- Design and execute risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments.
- Test whether preventive, detective, and responsive security controls perform as expected under realistic attack Evaluate attack paths, control weaknesses, detection coverage, alert quality, and the effectiveness of incident-response procedures.
- Collaborate with Security Operations and other technical teams during purple-team exercises to validate detection and response
- Develop test plans, objectives, techniques, targets, safeguards, and rules of engagement for management approval before execution.
- Translate technical findings into risk-based remediation recommendations that help leaders of technical teams, Internal Audit leadership, executive management and the Audit Committee prioritize security improvements and
- Build a repeatable, continuously improving offensive-security assurance program informed by a growing understanding of our environment.
- Partner with external security firms when specialist expertise or independent corroboration is
Who You AreWe are seeking bright, curious, and ambitious individuals eager to make an impact. Ideal candidates have:
- 5+ years of relevant offensive security experience, including at least three recent years conducting penetration tests, red team engagements adversary emulation exercises, or purple team assessments in complex military or civilian environments.
- A four-year college degree
- Demonstrated ability to independently scope, plan, execute, document, and clearly communicate technically sophisticated security assessments to both engineering and executive-level audiences.
- Broad knowledge of enterprise attack surfaces, including hands-on experience with several of the following domains: identity systems (LDAP, IAM), operating systems (Windows and Linux), network infrastructure, cloud platforms, web applications and APIs, endpoint systems, and security monitoring tools.
- Practical experience identifying and validating exploitable attack chains, bypassing or testing security controls, and determining whether detection and response mechanisms function as intended.
- Strong scripting or automation skills and the ability to adapt tools and techniques to assess unfamiliar environments effectively.
- Ability to operate safely and effectively in production-sensitive environments while maintaining strict adherence to rules of engagement and approved scope.
- Sound judgment, discretion, and a disciplined approach to handling privileged information and sensitive findings.
- Excellent written and verbal communication skills that translate technical weaknesses into clear business impact and remediation priorities for both engineers and senior leaders.
- A collaborative style that builds trust with Security and Systems teams while maintaining the objectivity required of an independent assurance function.
- A track record of taking initiative, identifying high-impact areas for investigation, and driving work through remediation and retesting.
CompensationTotal cash compensation generally ranges from $170,000-$250,000 and includes profit sharing based on company performance.
Growth & Learning- 100% tuition reimbursement
- Informal and formal mentorship
- Employee resource groups
Health & Wellbeing- Medical, dental, pharmacy and vision plans without monthly premiums
- Inclusive, all-gender benefits
Family & Future- Paid parental leave for all new parents
- Adoption and surrogacy assistance
- First-time home buyer assistance
- Industry-leading company-funded retirement accounts
Time Off- Paid vacation and personal time