Required Qualifications- 5-7+ years hands-on offensive security or penetration testing experience in web application, network, and cloud environments
- Demonstrated experience designing, leading, or maturing an offensive security program or methodology
- Experience scoping and overseeing internal and third-party offensive security engagements including rules of engagement, authorization, and scope management
- Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses
- Hands-on Active Directory and internal network exploitation experience (e.g., Kerberoasting, delegation abuse, lateral movement, privilege escalation)
- Working knowledge of cloud attack surfaces, including IAM misconfigurations, container security, and CI/CD pipeline attacks
- Experience using AI tools to accelerate offensive security workflows
- Deep understanding of OWASP Top 10, MITRE ATT&CK, CVSS and other severity scoring frameworks, and full attack-chain thinking
- Scripting and automation ability to build or extend custom tooling (e.g., Python, Bash, Powershell)
- Hands-on threat modeling experience (STRIDE, PASTA, or equivalent)
- Understanding of secure handling, storage, and reporting of sensitive engagement data and findings
- Excellent interpersonal, written, and verbal communication - able to explain and document security risk and remediation credibly to both technical and non-technical stakeholders
- Self-starter, team player, and enthusiasm for learning
- Applicants must be authorized to work in the United States without sponsorship. We are unable to provide sponsorship now or in the future for this position.
Preferred Qualifications- Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related field - or equivalent hands-on experience.
- OSCP, OSWE, OSEP, or equivalent red-team oriented certification
- Cloud security certification (AWS, Azure, GCP)
- Experience with C2 frameworks or interest in growing adversary emulation capabilities
- Familiarity with SIEM/EDR or detection engineering from a defender's perspective
- Programming experience beyond scripting for exploit development or evasion tooling (C/C++, JavaScript, Go, Python)
- Working knowledge of SAST, DAST, SCA, and vulnerability management tooling
- Experience building or maintaining offensive security testing playbooks
- Familiarity with compliance frameworks and compliance-driven testing requirements (SOC 2, ISO 27001, etc.)
- Track record of mentoring team members
Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay.
The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
- Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
- Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
- Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
- Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program
Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US Benefits Website
About the RoleWorld Wide Technology's Information Security organization is hiring a Senior Offensive Security Engineer to help build and mature an offensive security capability that identifies and validates real-world risk across the organization's applications, networks, and cloud infrastructure. While this role sits within the Application Security team, your scope extends well beyond applications. You'll plan and execute offensive engagements across organization-owned web applications and APIs, internal and external networks, and cloud environments, thinking like an adversary to find what automated tooling misses. Your focus is hands-on testing, retesting, and validation paired with clear, actionable reporting that helps both engineers and leadership understand and close real risk. You'll partner closely with multiple teams to drive remediation, strengthen detection, and inform testing priorities across the business. This is a role for an offensive security practitioner who wants to build a program, not just execute within one.
Key ResponsibilitiesTesting Execution- Plan and execute offensive tests across WWT owned web applications, APIs, internal and external networks, and cloud infrastructure
- Retest and validate remediated findings to confirm the fixes resolve the gaps
- Support scoping, oversight, and execution of internal and third-party engagements
Reporting & Metrics- Write clear, actionable reports for technical teams and leadership with reproducible steps and remediation guidance
- Track and report on trends across engagements, such as recurring finding types, time-to-remediate, and risk exposure, to inform leadership and program prioritization
Collaboration & Compliance- Collaborate across engineering, security, and GRC to drive remediation, validate findings, and inform testing prioritities
- Support compliance-driven testing requirements
- Contribute adversary-perspective input into threat modeling, architecture/design reviews, secure coding standards, and vulnerability management program
Program & Tooling- Maintain and evolve internal testing playbooks as the program matures
- Leverage AI tools to accelerate testing workflows, analysis, and reporting
- Build, adapt, or evaluate offensive security tooling and third-party vendors to support testing and reduce manual overhead
People & Knowledge- Mentor team members on offensive techniques, tools, and adversarial mindset
- Stay current on emerging attack techniques, CVEs, and adversary TTPs relevant to WWT's technology stack