Offensive Security Engineer (Red Team) in Haciendas del Canada, Nuevo León at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Offensive Security Engineer (Red Team) based in Canada.
This remote role sits within a Product Security team and focuses on strengthening security through hands-on offensive testing and adversary emulation. You will assess modern cloud environments, infrastructure, identity architectures, CI/CD pipelines, containers, and cloud-native services. The role combines technical investigation with close collaboration across security, engineering, blue team, and detection functions. You will simulate realistic attacker behavior to uncover vulnerabilities, validate security controls, and identify practical attack paths. Your findings will help engineering teams prioritize remediation and improve organizational resilience. The position is suited to an experienced offensive security professional who enjoys exploring emerging cloud attack techniques and translating complex findings into actionable improvements.
Plan and execute red team operations, adversary simulations, penetration tests, and targeted offensive security assessments across cloud environments.
Evaluate the security posture of cloud infrastructure, identity architectures, CI/CD pipelines, containerized workloads, and cloud-native services.
Identify and validate realistic attack paths involving IAM misconfigurations, excessive privileges, exposed secrets, metadata services, insecure automation, and cloud configuration weaknesses.
Conduct security assessments designed to replicate relevant attacker behaviors and techniques in modern enterprise environments.
Validate the effectiveness of security monitoring and detection capabilities by testing logging, alerting, monitoring, and incident-response processes.
Partner with blue team and detection engineering functions to identify gaps in defensive coverage and improve detection and response capabilities.
Document vulnerabilities, attack paths, and security weaknesses in concise, actionable reports.
Work with software and engineering teams to communicate findings, support remediation efforts, and help reduce security risk.
Track emerging attacker tactics, cloud exploitation techniques, and new abuse paths that could affect cloud-native environments.
Map offensive security findings and adversary behaviors to established frameworks such as MITRE ATT&CK.
Serve as a trusted security partner to engineering teams, helping strengthen security practices through practical offensive expertise.
5+ years of professional experience in offensive security, red teaming, penetration testing, detection validation, or closely related security disciplines.
Strong understanding of adversary tactics, techniques, and procedures, with the ability to apply them to realistic security assessments.
Experience conducting offensive security assessments in cloud environments and evaluating modern cloud infrastructure and services.
Practical understanding of cloud identity and access management, CI/CD security, containers, secrets management, and cloud-native architectures.
Ability to identify and validate complex attack paths involving IAM weaknesses, overprivileged identities, exposed credentials or secrets, metadata services, insecure automation, and configuration issues.
Experience evaluating security monitoring and detection capabilities through adversary simulation or detection-validation exercises.
Ability to map findings and attacker behavior to frameworks such as MITRE ATT&CK.
Strong written and verbal communication skills, including the ability to explain complex technical security issues to engineering teams and other stakeholders.
Ability to produce concise, actionable security reports that clearly communicate technical findings, business relevance, and remediation considerations.
Strong analytical and investigative mindset with a willingness to explore emerging attack techniques and unfamiliar technologies.
Relevant industry certifications such as OSCP, OSEP, GXPN, GPEN, or recognized cloud security certifications are valued.
Ability to work effectively in a remote environment and collaborate across technical and security teams.
Authorization to work in Canada and meet applicable requirements for accessing controlled technologies and commodities.
Competitive annual compensation range of CAD $146,000–$190,000, depending on location and factors such as education, professional experience, and certifications.
Potential eligibility for restricted stock units as part of total compensation.
Health and pharmacy benefits.
Optical and dental coverage.
Paid time off and sick time off.
Short-term and long-term disability coverage.
Life insurance.
Employer-supported retirement contributions, subject to eligibility.
Fully remote work arrangement within Canada.
Opportunity to work on cloud security, adversary simulation, and modern offensive security challenges.
Collaborative environment involving Product Security, engineering, blue team, and detection engineering professionals.
Opportunities to develop expertise in emerging attacker techniques and cloud exploitation trends.
Inclusive workplace committed to diverse backgrounds, experiences, abilities, and perspectives.
Potential for occasional in-person interviews or new-hire training sessions at global offices.