World Wide Technology

Senior Offensive Security Engineer

World Wide Technology$116K — $145K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7+ years of hands-on offensive security or penetration testing, particularly in web, network, and cloud settings.
  • Experience in designing and leading an offensive security program or methodology.
  • Proficient in scoping and managing internal and third-party engagements, ensuring rules of engagement and authorizations are adhered to.
  • Expertise in offensive security tools such as Burp Suite and Kali Linux, along with advanced exploitation techniques.
  • Hands-on experience with Active Directory exploitation and internal network techniques, including privilege escalation and lateral movement.
  • Familiarity with cloud security concerns, including IAM misconfigurations and CI/CD pipeline vulnerabilities.
  • Demonstrated ability to use AI tools to streamline offensive security processes.

Responsibilities

  • Plan and conduct offensive testing across web applications, APIs, and cloud infrastructures.
  • Retest and verify the effectiveness of remediated security findings.
  • Oversee internal and external security testing engagements.
  • Draft clear, actionable reports for both technical teams and leadership.
  • Analyze trends from security engagements to inform program priorities.
  • Collaborate with engineering and security teams to validate findings and drive remediation efforts.
  • Maintain and improve internal testing playbooks as the program evolves.

Benefits

  • Comprehensive health benefits including medical, dental, and vision coverage.
  • 401(k) plan with company matching and profit-sharing opportunities.
  • Generous paid time off policy, encompassing various leave types.
  • Support for employee education through tuition reimbursement.
  • Family planning support and additional perks such as pet insurance and employee discounts.
Full Job Description
Required Qualifications
  • 5-7+ years hands-on offensive security or penetration testing experience in web application, network, and cloud environments
  • Demonstrated experience designing, leading, or maturing an offensive security program or methodology
  • Experience scoping and overseeing internal and third-party offensive security engagements including rules of engagement, authorization, and scope management
  • Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses
  • Hands-on Active Directory and internal network exploitation experience (e.g., Kerberoasting, delegation abuse, lateral movement, privilege escalation)
  • Working knowledge of cloud attack surfaces, including IAM misconfigurations, container security, and CI/CD pipeline attacks
  • Experience using AI tools to accelerate offensive security workflows
  • Deep understanding of OWASP Top 10, MITRE ATT&CK, CVSS and other severity scoring frameworks, and full attack-chain thinking
  • Scripting and automation ability to build or extend custom tooling (e.g., Python, Bash, Powershell)
  • Hands-on threat modeling experience (STRIDE, PASTA, or equivalent)
  • Understanding of secure handling, storage, and reporting of sensitive engagement data and findings
  • Excellent interpersonal, written, and verbal communication - able to explain and document security risk and remediation credibly to both technical and non-technical stakeholders
  • Self-starter, team player, and enthusiasm for learning
  • Applicants must be authorized to work in the United States without sponsorship. We are unable to provide sponsorship now or in the future for this position.


Preferred Qualifications
  • Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related field - or equivalent hands-on experience.
  • OSCP, OSWE, OSEP, or equivalent red-team oriented certification
  • Cloud security certification (AWS, Azure, GCP)
  • Experience with C2 frameworks or interest in growing adversary emulation capabilities
  • Familiarity with SIEM/EDR or detection engineering from a defender's perspective
  • Programming experience beyond scripting for exploit development or evasion tooling (C/C++, JavaScript, Go, Python)
  • Working knowledge of SAST, DAST, SCA, and vulnerability management tooling
  • Experience building or maintaining offensive security testing playbooks
  • Familiarity with compliance frameworks and compliance-driven testing requirements (SOC 2, ISO 27001, etc.)
  • Track record of mentoring team members

Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay.

The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
  • Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
  • Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
  • Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
  • Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program

Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US Benefits Website

About the Role

World Wide Technology's Information Security organization is hiring a Senior Offensive Security Engineer to help build and mature an offensive security capability that identifies and validates real-world risk across the organization's applications, networks, and cloud infrastructure. While this role sits within the Application Security team, your scope extends well beyond applications. You'll plan and execute offensive engagements across organization-owned web applications and APIs, internal and external networks, and cloud environments, thinking like an adversary to find what automated tooling misses. Your focus is hands-on testing, retesting, and validation paired with clear, actionable reporting that helps both engineers and leadership understand and close real risk. You'll partner closely with multiple teams to drive remediation, strengthen detection, and inform testing priorities across the business. This is a role for an offensive security practitioner who wants to build a program, not just execute within one.

Key Responsibilities

Testing Execution
  • Plan and execute offensive tests across WWT owned web applications, APIs, internal and external networks, and cloud infrastructure
  • Retest and validate remediated findings to confirm the fixes resolve the gaps
  • Support scoping, oversight, and execution of internal and third-party engagements

Reporting & Metrics
  • Write clear, actionable reports for technical teams and leadership with reproducible steps and remediation guidance
  • Track and report on trends across engagements, such as recurring finding types, time-to-remediate, and risk exposure, to inform leadership and program prioritization

Collaboration & Compliance
  • Collaborate across engineering, security, and GRC to drive remediation, validate findings, and inform testing prioritities
  • Support compliance-driven testing requirements
  • Contribute adversary-perspective input into threat modeling, architecture/design reviews, secure coding standards, and vulnerability management program

Program & Tooling
  • Maintain and evolve internal testing playbooks as the program matures
  • Leverage AI tools to accelerate testing workflows, analysis, and reporting
  • Build, adapt, or evaluate offensive security tooling and third-party vendors to support testing and reduce manual overhead

People & Knowledge
  • Mentor team members on offensive techniques, tools, and adversarial mindset
  • Stay current on emerging attack techniques, CVEs, and adversary TTPs relevant to WWT's technology stack

About World Wide Technology

World Wide Technology (WWT) is a technology solution provider that offers a wide range of services to businesses and organizations. The company was founded in 1990 and is headquartered in Maryland Heights, Missouri. WWT provides a variety of services, including consulting, design, integration, and managed services. The company has a strong focus on innovation and has been recognized for its efforts in this area. WWT has partnerships with many leading technology companies, including Cisco, Dell, and Microsoft. The company has a global presence, with offices in the United States, Europe, and Asia.
Learn more about World Wide Technology
Size
7,000 employees
Industry
Founded
1990

Similar Jobs

More Jobs at World Wide Technology

More Information Technology Jobs

Find similar Senior Offensive Security Engineer jobs: