Sr. Offensive Security Engineer
Listed on 2026-03-02
-
Security
Cybersecurity
General Information
# 21788
Remote? Yes
Ally and Your CareerAlly Financial only succeeds when its people do - and that’s more than some cliché people put on job postings. We live this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion.
From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You’re constantly evolving, so shouldn’t your opportunities be, too?
At Ally, you get a startup feel, but experience the benefits of a company that has worked out the kinks and is fulfilling its purpose. We are always evolving and see that as a good thing. From owning our work to seeing its impact in the real world, our team is relentless in finding new ways technology can help make experiences better and help people.
We are problem solvers, we value diverse thinking, we support one another, and we challenge ourselves to think bigger in the journey to deliver customer-obsessed tech solutions. To read more about what our tech team does, be sure to visit our tech blog h
We are seeking a highly skilled and passionate Sr. Offensive Security Engineer to join the Threat Emulation and Offensive Security (TEOS) team in our CD3R organization. As a Sr. Offensive Security Engineer, you will perform PCI, network, cloud, external, Wi‑Fi, and miscellaneous penetration tests. You will work closely with cross‑functional teams, including cybersecurity analysts, engineers, and stakeholders, to enhance the organization's security posture.
At this time, Ally will not sponsor a new applicant for employment authorization for this position.
The Work Itself- PCI, network, cloud, external, Wi‑Fi, and miscellaneous penetration tests.
- Perform Active Directory audits using enterprise tooling.
- Work with cross‑functional teams to report identified vulnerabilities.
- Produce professional grade reports based on the penetration tests you perform.
- Conduct scoping calls with internal clients to determine penetration test needs.
- Training junior engineers may be required.
- Potential of travel up to two times a year.
Minimum Qualifications
- 3+ years of experience
- High School Diploma or GED equivalent
- Minimum of 2 years of experience in cyber security.
- Minimum of 2 years of experience in offensive security.
- Ability and qualifications to perform PCI penetration tests.
- Excellent communication and presentation skills, with the ability to effectively convey complex concepts to technical and non-technical audiences.
- Strong analytical and problem‑solving abilities.
- Ability to work independently and collaboratively in a fast‑paced environment.
- Relevant certifications or ability to obtain within a year: OSCP, OSEP, CRTO, CRTL, CPTS, CAPE, etc.
- Experience performing adversary emulations.
- Experience working with financial institutions.
- Experience performing Directory Audits.
- Experience performing physical penetration tests.
- Experience performing social engineering.
- Experience with PoC development or having CVEs published.
#LI-Remote
How We’ll Have Your BackAlly’s compensation program offers market‑competitive base pay and pay‑for‑performance incentives (bonuses) based on achieving personal and company goals. But Ally’s total compensation – or total rewards – extends beyond your paycheck and is designed to support and enrich your personal and professional life, including:
* Time Away: competitive holiday and flexible paid‑time‑off, including time off for volunteering and voting.
* Planning for the Future: plan for the near and long term with an industry‑leading 401K retirement savings plan with matching and company contributions, student loan and 529 educational assistance programs, tuition reimbursement, and other financial well‑being programs.
* Supporting your Health & Well‑being: flexible health and insurance options including dental and vision, pre‑tax Health…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).