SPAN

Security

Sr.OffensiveSecurityEngineer

$138–184k San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Sr. Offensive Security Engineer at SPAN. Skills: Offensive security, Incident response, Cloud security, Application security. Execute adversary emulations. Lead Technical Incident Response operations”

Industry & Context.

Security
Problems you'll solve

Root cause analysis; Digital forensics

What They're Looking For.

Must Have

6+ years offensive security experience, 6+ years technical incident response experience, Experience executing full IR lifecycle, Experience managing critical security breaches, Capability in parsing complex log data, Capability in analyzing system telemetry, Capability in forensics techniques, Advanced hands-on cloud security experience, Advanced hands-on containerized environments experience, Advanced hands-on IAM policies experience, Deep technical expertise web application security, Deep technical expertise API security, Masterful understanding OWASP Top 10, Masterful understanding complex business logic flaws, Decent programming proficiency Python, Decent programming proficiency Go, Decent programming proficiency Bash, Proven track record finding critical vulnerabilities

Nice to Have

NIST SP 800-61 framework knowledge, SANS frameworks knowledge, Docker experience a plus, Kubernetes experience a plus

What You'll Do.

Execute adversary emulations

Lead Technical Incident Response operations

Provide feedback loop

Translate findings into detection rules

Translate findings into hardening requirements

Manage public vulnerability disclosure channel

Manage communications with researchers

Validate incoming reports

Build automated scripts

Build automated tools

Streamline security testing

Streamline vulnerability scanning

Streamline VDP triage

Design red team scenarios

Test detection capabilities

Develop Incident Response playbooks

Maintain Incident Response playbooks

Develop Incident Response runbooks

Maintain Incident Response runbooks

Conduct root-cause analysis

Conduct digital forensics

Reconstruct attacker timelines

Identify Indicators of Compromise

Perform post-incident reviews

How You'll Work.

Team & Collaboration

Cloud Infrastructure teams; Software Engineering teams

Full Job Description

OUR MISSION   SPAN is enabling electrification for all ⚡ WE ARE A MISSION-DRIVEN COMPANY DESIGNING, BUILDING, AND DEPLOYING PRODUCTS THAT ELECTRIFY THE BUILT ENVIRONMENT, REDUCE CARBON EMISSIONS, AND SLOW THE EFFECTS OF CLIMATE CHANGE. - Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere. - Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives. AT SPAN, WE BELIEVE IN: - Enabling homes and vehicles powered by clean energy - Making electrification upgrades possible - Building more resilient homes with reliable backup - Designing a flexible and distributed electrical grid THE ROLE We are looking for a hands-on individual with an offensive security engineering mindset to join us as a Senior Offensive Security Engineer (Threat & Response) as part of the Security team at SPAN. In this role, you will act as our internal ethical hacker, conducting full-scope, threat intelligence-informed adversary emulations across our cloud infrastructure, proprietary applications, and corporate IT assets. We are looking for someone who can continuously simulate real-world cyber attacks to identify vulnerabilities before malicious actors do, while seamlessly leading the full Technical Incident Response (IR) lifecycle, from initial triage and containment through to eradication and post-incident recovery, when security events occur. WHAT YOU’LL DO (RESPONSIBILITIES) - Execute full-scope adversary emulations against any valuable objectives across SPAN's cloud environments , proprietary web/mobile applications, APIs, and corporate IT infrastructure. - Lead Technical Incident Response operations during live security events, leveraging your understanding of attacker TTPs to direct rapid containment, threat eradication, and system recovery. - Provide a crucial feedback loop to our Cloud Infrastructure and Software Eng

Free ATS check

Applying for this Sr. Offensive Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about SPAN?

Real rants from real employees. Read before you apply.

Read Company Rants →