More jobs:
Job Description & How to Apply Below
What unites Anaplanners across teams and geographies is our collective commitment to our customers' success and to our Winning Culture.
Our customers rank among the who's who in the Fortune 50. Coca-Cola, Linked In, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values-based and disciplined in execution, you'll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let's build what's next - together!
Senior Offensive Security Engineer
About the Role
As a Senior Offensive Security Engineer , you will lead offensive security efforts and own Anaplan's vulnerability management programme. This is a dual-scope role: you'll drive adversarial testing to find what's broken, and you'll run the process that ensures vulnerabilities—from your own assessments, scanners, bug bounty, and third-party audits—are tracked, prioritised, and remediated at the right pace. You'll mentor the Offensive Security Engineer and serve as a technical authority across product and platform teams.
Individual Contributor Focus
Operates independently on complex offensive engagements and vulnerability management decisions, setting scope and priority without close supervision.
Communicates risk and remediation trade-offs to cross-functional stakeholders at the project and product-line level, influencing engineering roadmaps where security debt is material.
Mentors the Offensive Security Engineer and security champions across engineering, but carries no direct people management responsibility.
Responsibilities
Offensive Security
Advanced Penetration Testing & Red Teaming: Lead complex, multi-phase penetration tests and red team exercises against Anaplan's platform, cloud infrastructure, and AI-powered products. Define engagement scope, rules of engagement, and success criteria.
Threat Modelling & Attack Path Analysis: Conduct adversarial threat modelling for new features and architectural changes, identifying realistic attack chains that inform both offensive testing and defensive controls.
Offensive Tooling & Capability Development: Build and maintain reusable offensive tooling, automation frameworks, and testing methodologies that scale with the platform's evolution.
Mentorship & Technical Leadership: Guide the Offensive Security Engineer on methodology, scoping, and report quality. Raise the bar on how offensive findings translate into engineering action.
Vulnerability Management
Programme Ownership: Own the end-to-end vulnerability management lifecycle: intake from scanners, penetration tests, bug bounty, and third-party audits; triage and risk-rating; assignment to responsible teams; tracking through to verified remediation.
Prioritisation & Risk Calibration: Apply consistent, risk-based prioritisation that accounts for exploitability, blast radius, data sensitivity, and business context—not just CVSS scores.
Metrics & Reporting: Define and maintain vulnerability management metrics (mean time to remediate, ageing, SLA compliance) and report trends to security leadership and engineering stakeholders.
Process Improvement: Continuously improve the vulnerability management workflow: reduce noise, improve scanner accuracy, tighten integration with CI/CD and ticketing systems, and make it easier for engineering teams to act on findings.
Cross-Cutting
Incident Support: Support major security incident investigations with offensive expertise—reproducing attack paths, validating exposure scope, and advising on containment.
Stakeholder Communication: Present findings, risk assessments, and programme health…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×