AWS Penetration Tester

Posted Yesterday
Be an Early Applicant
Hiring Remotely in USA
Remote
Senior level
Blockchain • Software
The Role
Conduct code audits and penetration tests across AWS cloud environments, infrastructure, backend applications, and blockchain ecosystem tools. Lead red-team exercises, collaborate with detection engineering and incident response teams, develop offensive security automation, support investigations, research emerging threats, and mentor junior staff. The role requires expertise in AWS attack techniques, binary exploitation, web application security, adversary frameworks, and offensive tooling, with Web3 and blockchain security experience preferred.
Summary Generated by Built In
At Offchain, we aren’t just building products: we’re leading a movement. 
 
As pioneers in blockchain scalability and security, we're at the forefront of transforming how the world interacts with decentralized applications. We're laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency. 
 
At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you. 
 
Why Offchain?
 
Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today.
 
Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack.
 
Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what's possible on Ethereum and advancing its core infrastructure.
 
To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly.

The Role

  • As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.
  • You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.
  • Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.

What you'll do:

  • Conduct comprehensive code audits across a variety of internal applications and infrastructure.
  • Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.
  • Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.
  • Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.
  • Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.
  • Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.
  • Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange.

What you'll need:

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Extensive experience with conducting code audits to identify and remediate security issues.
  • Experience with binary exploitation.
  • Mastery of AWS & specific attack techniques and configuration weaknesses.
  • Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
  • In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
  • Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.
  • Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
  • A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.

Nice-to-haves

  • Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.
  • Familiarity with Ethereum L1 / L2 node architecture and security risks.
  • Experience in blockchain infrastructure penetration testing.

Perks:

  • Remote-first global workforce + NY office
  • Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
  • Medical, dental & vision coverage (US + some other countries)
  • 401k retirement plan + company match (US only)
  • Wellness stipend
  • Home office set up / ergonomic equipment program

Attention Offchain Job Seekers:
 
This role cannot be performed in California, or Colorado.
 
Please be advised that there has been a rise in fraudulent recruiter activities, particularly within the Web3 space. If you would like to confirm whether someone is an Offchain employee or the legitimacy of an offer you received, please email [email protected]
 
At Offchain, we are committed to building a welcoming and supportive workplace for all employees, regardless of their background or identity. We strive to create an environment where everyone feels valued and has an equal opportunity to succeed and thrive. We encourage candidates from all walks of life to apply and join our team.

Skills Required

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field
  • Extensive experience conducting code audits to identify and remediate security issues
  • Experience with binary exploitation
  • Mastery of AWS and specific attack techniques and configuration weaknesses
  • Strong understanding of adversary tactics and MITRE ATT&CK
  • In-depth knowledge of web application security, OWASP Top 10, ASVS, and common vulnerability categories
  • Proficiency with offensive security tools such as Burp Suite and nuclei
  • Strong programming skills in Python, Go, or similar languages, including developing tools or automation
  • Excellent written and verbal communication skills, including presenting technical details as risk-focused recommendations
  • Creative and determined attacker mindset with the ability to assess risk across complex systems
  • Web3 or blockchain security exposure, such as smart contract auditing, bug bounty hunting, or DeFi protocol review
  • Familiarity with Ethereum L1/L2 node architecture and security risks
  • Experience in blockchain infrastructure penetration testing
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Princeton, NJ
81 Employees
Year Founded: 2018

What We Do

Offchain Labs is a venture-backed, Princeton-founded company that has dedicated over 8 years to blockchain research and development. As the original developers of Arbitrum, Offchain has been instrumental in revolutionizing the industry through this leading network scaling solutions. The team continues to build upon this foundation by innovating and enhancing products such as Arbitrum Orbit, Stylus, and Arbitrum Nitro. In October 2022, Offchain Labs acquired Prysmatic Labs, the leading consensus client for Ethereum, further cementing Offchain Labs alignment with Ethereum.

Similar Jobs

Coursera + Udemy  Logo Coursera + Udemy

Counsel

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
152K-190K Annually

Circle Logo Circle

Senior Accountant

Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
In-Office or Remote
2 Locations
1050 Employees
113K-148K Annually

Motive Logo Motive

Executive Assistant

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
Remote
United States
4000 Employees
69K-95K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account