Staff Offensive Security Engineer

Cloaked

• $150K — $180K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in offensive security, vulnerability discovery, or application security.
  • Expertise in custom exploit development and creating innovative offensive security tools.
  • Strong coding skills with fluency in at least one programming language, ideally Python or Go.
  • Deep understanding of cloud environments and SaaS architecture, with hands-on experience in multi-cloud setups.
  • Ability to communicate complex security concepts to engineers without condescension.
  • Demonstrated experience in leveraging non-linear career paths to enhance security practices.

Responsibilities

  • Design and execute targeted offensive security campaigns against critical assets.
  • Build advanced exploit tools tailored for specific vulnerabilities.
  • Prioritize security testing based on potential business impact rather than superficial wins.
  • Collaborate with product and engineering teams to understand core business logic for exploitation.
  • Educate engineering teams on security best practices by debriefing after security assessments.
  • Provide comprehensive security audits and architecture reviews across business units.
  • Engage in offensive security activities that span various systems and technologies without limitations.

Benefits

  • Flexible work arrangements with remote work options available.
  • 401K plan along with top-tier health, dental, and vision coverage.
  • Generous paid time off policy encouraging minimum vacation take.
  • Monthly health stipend for physical, mental, or emotional care.
  • Company-sponsored late-night meal stipend to support work-life balance.
  • Unlimited professional development fund for career growth and conference attendance.
  • Access to a hybrid workspace with amenities including a café and rooftop area.
Full Job Description
// THE MANDATE

Most security roles are compliance disguised as engineering. This is not.

We are looking for a Staff Offensive Security Engineer to operate as a persistent, advanced threat against our own infrastructure. We do not want automated reports. We want custom exploit development, logical subversion, and a strategic mindset.

If you measure your success by the sheer volume of vulnerabilities you find, look elsewhere. If you measure it by your ability to map business risk, execute highly targeted campaigns, and elevate the engineers around you, keep reading.

// THE SCOPE

You are not a vulnerability scanner; you are a strategic adversary. Your directive is to compromise our most critical assets before actual adversaries do.
  • Absolute Autonomy: There is no daily task list. You are handed the Rules of Engagement. From there, it is on you to design, dictate, and execute campaigns that provide uncompromising coverage of our attack surface, backed by thorough, rigorous test cases.
  • Beyond the Tooling: Off-the-shelf scanners will not find what you are looking for here. We need you for the complex logical flaws and chained vectors that require human intuition. Furthermore, you aren't just using tools - you are building them. You will engineer complex, future-forward offensive systems that redefine how we test our own defenses at scale.
  • Ruthless Prioritization: You have an infinite attack surface and finite time. You must be able to cut through the noise and prioritize your targets based on catastrophic business risk rather than easy, low-impact wins.
  • Business Subversion: You do not operate in a vacuum. You will partner directly with product and engineering leaders to deeply understand the core business logic of our platforms - and then weaponize that logic against them.
  • Force Multiplier: Breaking in is only half the mandate. When the operation concludes, you teach. You will deconstruct your attack paths and help engineering eradicate entire attack classifications at the root. By driving foundational system hardening and secure development standards, you ensure whole categories of vulnerabilities never see production again.
  • Ubiquitous Ownership: Despite the advanced mandate, our ultimate bottom line is protecting our customers, which means finding flaws early across every single part of the business. You will cross business units to provide hands-on security guidance, rigorous architecture review, and audit support. One day you might be red-teaming a physical system, and the next you are tearing apart our flagship product. We demand apex-level hacking, but we have zero tolerance for a "that's not my job" mentality.


// THE PROFILE

We don't screen for certifications or a linear cybersecurity career path. We screen for multi-disciplinary scars, coding fluency, and a deep understanding of modern architecture.
  • You are a Builder First: You write code. You don't just find vulnerabilities after the fact; you anticipate them. You know exactly where the architectural fractures will be before a system is even built or deployed.
  • Non-Linear Background: You have seen the tech stack from every angle. We value a diverse background - whether you've spent time in customer support, QA/test, development, blue team, red team, or all of the above. You know how users break things accidentally, which fuels how you break them intentionally.
  • Cloud & SaaS Mastery: Your playground is modern infrastructure. You are fluent in multi-cloud environments and complex SaaS architectures. You know exactly how to abuse IAM trust boundaries, tenant isolation flaws, and API misconfigurations.
  • No Ego: You have the communication skills to translate a highly complex exploit into actionable engineering requirements without talking down to the engineers who built it.


What we offer

Cloaked is a well-funded Series B startup based out of NYC.

Although we are a distributed team, the NYC team operates with a hybrid model. The office building is home to several amenities, including a gourmet cafe, cocktail bar, and a rooftop work area.

We have a fully built out kitchen packed with drinks and snacks. The Cloaked team has diverse interests and so we frequently embark on team outings and go out for socials!

Compensation and Benefits

We offer above market rate pay and equity based off of the market's best commercially available data. Your compensation will be a combination of salary, bonus and equity.

Cloaked employees have 401K, as well as top of the line Health, Dental, and Vision benefits.

We offer flexible work arrangements and the ability to work remotely as needed. Cloaked provides a home office stipend in addition to a new company laptop (and other tech depending on the role).

Perks

Competitive PTO: We encourage employees to take a minimum # of vacation per quarter. We see PTO as a preventative burnout measure and are committed to changing the industry standard.

Monthly health stipend: Used for any kind of physical, mental or emotional care you'd like to take for yourself, be it a gym membership, a meditation app, or time with a personal trainer.

🥗 Late Night Meals: We understand that sometimes work can get in the way of meal prep. In response to that, we offer employees a monthly meal stipend to be used when they don't have time to get a home cooked meal going!

Professional Growth: Opportunities for career development and personal growth are provided to all employees who seek to further their knowledge and capabilities through an unlimited professional development fund. Additionally team members are encouraged to regularly attend conferences and industry events.

We are really excited about having you join our mission-driven team and help us build the future of online privacy!

Similar Jobs

More Jobs at Cloaked

More Information Technology Jobs

Find similar Staff Offensive Security Engineer jobs: