Security Engineer II Offensive Track
Listed on 2026-09-18
-
IT/Tech
Cybersecurity
Job Description
Role FocusAt this level, your focus sits within Offensive Penetration Testing and Security Operations, supporting the wider Active Operational Defender track under the guidance of senior engineers. You will assist with manual testing engagements, help tune SIEM detection rules, and support the team during live security incidents, building the operational depth needed to work independently over time.
Job SummaryAs a Security Engineer II on the Active Operational Defender track, you will build hands-on experience across penetration testing, threat detection, and incident response working under the direction of senior and lead engineers. You will support live operational work within a high-velocity fintech environment, developing the manual testing and detection engineering skills needed to take on more independent responsibility over time.
Key Responsibilities & Tasks (by Priority) Offensive Penetration Testing & Red Teaming- Support penetration testing engagements across financial platforms and product architectures under senior guidance, building practical exploit research experience.
- Assist with manual security reviews including source code audits, API testing, and cloud configuration checks, working towards independent delivery of smaller engagements.
- Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM-specific weaknesses.
- Help design and tune detection rules and alert workflows within the enterprise SIEM, leveraging senior guidance and established detection frameworks.
- Support Sec Ops in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK.
- Act as a first-line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.
- Support post-incident analysis by pulling together logs, timelines, and technical findings for senior review.
- Participate in security operations and engineering planning to build a practical understanding of detection and response capabilities.
- Communicate testing findings and incident metrics clearly to immediate team members and stakeholders.
- Actively seek mentorship from senior and lead security engineers across offensive tooling, detection engineering, and incident response practices.
Minimum Requirements (Education & Experience)
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, a related technical discipline, or equivalent practical experience.
- Core
Experience:
1 to 3 years of hands-on experience in penetration testing, security operations, or a closely related technical role.
- Foundational Offensive
Skills:
Hands-on exposure to manual web application testing, CTF-style exploitation, or vulnerability research (via work experience, personal projects, or study). - Sec Ops & Forensics: Working knowledge of SIEM concepts, EDR tooling, or network packet analysis, alongside familiarity with frameworks such as MITRE ATT&CK.
- Scripting / Automation: Proficiency in reading and writing scripts (e.g., Python) to support security testing and automation workflows.
- AI Security Awareness: Basic working interest in the OWASP Top 10 for LLMs and understanding of how adversarial AI testing differs from traditional app security.
- Regulatory Context: General understanding of compliance frameworks such as PCI-DSS, SOC 2, or DORA, with a willingness to expand practical knowledge on the job.
- Offensive & Red Team: OSCP, OSCE, or SANS GXPN.
- Incident Response & Defense: GCIH, GCFA, or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).