Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior Security Engineer - Pentester

Menlosecurity
CompanyMenlosecurity
CategoryUncategorised
LocationAMER - Canada
RemoteRemote
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted3 Aug 2026
Last verified4 Aug 2026
SourceEmployer ATS (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Menlo Security's https://www.menlosecurity.com/ mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. The world has fundamentally changed. We are growing from 400 employees into the next phase of our journey, and we need passionate talent filled with empathy and agility. The right candidate for the job is ethical, hyper-organized, fanatical about seeing things through to completion, service-oriented, and humble enough to take feedback and coaching yet confident enough to provide feedback and coaching. Menlo is well-funded for growth and our investors are second to none. They include Vista Equity Partners (“Vista http://www.vistaequitypartners.com/?utm_source=vistapressrelease&utm_campaign=menlosecurity”), General Catalyst, JPMC, American Express, HSBC, and Ericsson Ventures. SUMMARY We're looking for a forward-thinking Security Engineer to join our security team, focused on offensive and defensive testing, penetration testing of product features, and the cloud architecture behind the product. You'll operate across a complex multi-cloud environment (AWS & GCP) spanning traditional VMs and modern managed and unmanaged container-based architectures, partnering with fellow Penetration Testing and Cloud Security engineers to run targeted assessments during the testing window immediately before each release. The role reaches beyond the application layer into the Control Plane, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and extends to the frontline of external defense by triaging bug bounty submissions and outside vulnerability reports. AI and large language models are core to how this team works day to day — you'll use them to accelerate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, while applying human judgment to validate findings and communicate risk clearly to product teams. Speed matters here: the team's operating cadence is built around identifying, validating, and reporting vulnerabilities quickly enough to keep pace with release velocity. OUTCOMES & KPIS Key Outcome(s) Owned: - Ensure new product features and the underlying multi-cloud (AWS/GCP) infrastructure are rigorously security-tested before release, and that vulnerabilities surfaced internally or via bug bounty are triaged and communicated with speed and precision. Success Metrics / KPIs: - Percentage of roadmap features assessed within the pre-release testing window. - Mean time to triage and validate bug bounty / external vulnerability reports. - Reduction in critical/high-severity vulnerabilities escaping to production post-release. - Time saved per assessment cycle through AI-assisted tooling and automation. - Quality and actionability of vulnerability reports and PoCs, as rated by product teams. WHAT YOU'LL DO - Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester. - Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines. - Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI). - Assess the security posture of hybrid infrastructure spanning containers and virtual machines. - Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation. - Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts. - Monitor bug bounty pipelines and extern
HOUSE AD2,088,683 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →