Security Engineer, Level 5, Offensive Security

Posted Yesterday
Be an Early Applicant
2 Locations
Hybrid
178K-313K Annually
Senior level
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Snap is a technology company.
The Role
Lead offensive security engagements across corporate, cloud, application, and mobile environments, including red, purple, and orange team exercises. Develop covert engagement infrastructure, custom implants, payloads, and exploits; model threats and killchains; assess detection coverage; produce remediation-focused reports; support incident response; and advise security teams on vulnerabilities, threat intelligence, and defensive improvements.
Summary Generated by Built In

Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together.


The Company operates Snapchat, a visual messaging app that enhances your relationships with friends, family, and the world, and Specs Inc., a wholly-owned subsidiary dedicated to making computing more human, in addition to Bitmoji, Saturn, and other digital services.


Snap Security teams protect the trust and safety of our global community by securing the systems and data that power Snapchat. We safeguard hundreds of millions of Snapchatters every day, ensuring that every product and service is built on a foundation of security and resilience. Our values guide everything we do - from how we anticipate and mitigate threats to how we collaborate across Snap. We move fast, with precision, and always execute with privacy at the forefront.


We’re looking for a Security Engineer to join our Offensive Security Team!

What you’ll do:


  • Design, execute, and lead offensive security and privacy engagements, including red, purple, and orange team exercises, across corporate environments, cloud projects/accounts, internal applications, and mobile client applications. 
  • Maintain a comprehensive understanding of real-world threat actors, their tools, tactics, and procedures, with a propensity to target Snap, collaborating extensively with the threat intelligence team to enumerate exhaustive killchains that seed and prioritize the future engagement roadmap.
  • Deliver detailed post-engagement reports that identify vulnerabilities, highlight strengths and weaknesses in our security posture, assess detection coverage, and provide actionable recommendations, including prioritized risk mitigation strategies and improvements to defensive measures.
  • Implement and manage offensive security engagement infrastructure and tooling to conduct covert operations and mimic the tactics of relevant adversaries, including the development of custom implants, payloads, and exploits to thoroughly test and evaluate our defenses.
  • Collaborate closely with other security and privacy teams to share insights from engagements, informing strategic roadmaps by identifying priority areas for improvement and aligning on initiatives.
  • Serve as a subject matter expert and consultant to other security and privacy teams, participating in security reviews, reproducing vulnerabilities, and contributing to high-stakes incident response efforts.
  • Explore novel research topics relevant to our tech stack to proactively improve our security posture and integrate lessons learned into future exercises.

Knowledge, Skills & Abilities:


  • Proven experience in leading offensive security engagements, coordinating multiple security engineers, and managing and executing assessments to thoroughly test and evaluate security measures.
  • Expert knowledge in four or more of the following: operating system internals, networking, application development, mobile client development, Kubernetes, cloud infrastructure (AWS/GCP), and payload/implant/exploit development.
  • Coding proficiency in one or more modern languages, including Java, Python, Go, etc.
  • Adept at threat modeling and establishing killchains
  • Proficiency in scripting languages like Bash and PowerShell to automate security tasks and improve efficiency of engagements.
  • Possess an insatiable drive for learning and the ability to thrive in new, unique, and complex technical environments, with the capability to build a foundational understanding and effectively apply it within the context of engagements.

Minimum Qualifications: 


  • Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
  • You may also provide evidence of personal security research (CVEs or blogs), public bug bounty reports, previous CTF participation, and/or code repositories on GitHub showcasing personally developed security tools
  • 6+ years of post-Bachelor’s security related experience; or Master’s degree in a technical field + 5+ year of post-grad security related experience; or PhD in a relevant technical field + 2+ years of post-grad security related experience

Preferred Qualifications:


  • Familiar with frameworks like ATT&CK to represent tools, tactics, and procedures.
  • Experience in leading or participating in incident response efforts, with a deep understanding of digital forensics, detection engineering, and threat hunting.
  • Proven ability to work effectively with cross-functional teams at all-levels, including developers, IT, and executive leadership, to align security measures with organizational goals.

"Default Together" Policy at Snap: At Snap Inc. we believe that being together in person helps us build our culture faster, reinforce our values, and serve our community, customers and partners better through dynamic collaboration. To reflect this, we practice a “default together” approach and expect our team members to work in an office 4+ days per week. 


At Snap, we believe that having a team of diverse backgrounds and voices working together will enable us to create innovative products that improve the way people live and communicate. Snap is proud to be an equal opportunity employer, and committed to providing employment opportunities regardless of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, pregnancy, childbirth and breastfeeding, age, sexual orientation, military or veteran status, or any other protected classification, in accordance with applicable federal, state, and local laws. EOE, including disability/vets.


We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, where applicable).


Our Benefits: Snap Inc. is its own community, so we’ve got your back! We do our best to make sure you and your loved ones have everything you need to be happy and healthy, on your own terms. Our benefits are built around your needs and include paid parental leave, comprehensive medical coverage, emotional and mental health support programs, and compensation packages that let you share in Snap’s long-term success!

Compensation

In the United States, work locations are assigned a pay zone which determines the salary range for the position. The successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. The starting pay may be negotiable within the salary range for the position. These pay zones may be modified in the future.

Zone A (CA, WA, NYC):

The base salary range for this position is $209,000-$313,000 annually.


 

Zone B:

The base salary range for this position is $199,000-$297,000 annually.

Zone C:

The base salary range for this position is $178,000-$266,000 annually.

This position is eligible for equity in the form of RSUs.

If you believe this job description is missing required pay transparency information, please submit a report through this form: Job Description Pay Range Disclosure.

Skills Required

  • Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent experience in a related technical field
  • 6+ years of post-Bachelor's security-related experience, or a Master's degree with 5+ years of post-graduate security experience, or a PhD with 2+ years of post-graduate security experience
  • Proven experience leading offensive security engagements and coordinating multiple security engineers
  • Expert knowledge in at least four relevant areas, including operating system internals, networking, application development, mobile development, Kubernetes, cloud infrastructure, or payload, implant, and exploit development
  • Coding proficiency in one or more modern programming languages, such as Java, Python, or Go
  • Proficiency with Bash and PowerShell scripting
  • Threat modeling and killchain development experience
  • Ability to work in an office at least four days per week under the Default Together policy
  • Personal security research, CVEs, blogs, public bug bounty reports, CTF participation, or security-tool code repositories
  • Familiarity with the MITRE ATT&CK framework
  • Experience with incident response, digital forensics, detection engineering, and threat hunting
  • Ability to collaborate with developers, IT, and executive leadership

What the Team is Saying

Xiaolin
Yvette
Matt
Jasmeet
Xueyin (Sherry)
Amir
Jung
Xu
Talia Mason
Maureen Ufomadu
Vincent Pagnard-Jourdan
Pulkit Trivedi
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Monica, CA
5,000 Employees
Year Founded: 2011

What We Do

We contribute to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together.

Gallery

Gallery

Snap Inc. Teams

Team
Product + Tech
Team
Machine Learning
Team
Sales
About our Teams

Snap Inc. Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Our “default together” approach is an 80/20 model where we are asking team members to spend 80% of the time, on average, in the office, with the remaining 20% of the time spent remote.

Typical time on-site: 4 days a week
HQSanta Monica, CA
Amsterdam, NL
Austin, TX
Bellevue, WA
Berlin, DE
Boulder, CO
Chandler, AZ
Chicago, IL
Copenhagen, DK
Dallas, TX
Eindhoven, NL
Hamburg, DE
London, GB
Mumbai, IN
New York, NY
Oslo, NO
Palo Alto, CA
Paris, FR
San Francisco, CA
Seattle, WA
Singapore
Sydney, AU
Toronto, ON
Vancouver, CA
Washington, DC
Learn more

Similar Jobs

Snap Inc. Logo Snap Inc.

Senior Manager, Compensation

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
4 Locations
5000 Employees
195K-343K Annually

Snap Inc. Logo Snap Inc.

Product Designer

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
Los Angeles, CA, USA
5000 Employees
133K-235K Annually

Snap Inc. Logo Snap Inc.

Software Engineer

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
Los Angeles, CA, USA
5000 Employees
100K-176K Annually

Snap Inc. Logo Snap Inc.

Creative Lead, SPECS Social & Content

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
2 Locations
5000 Employees
121K-214K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account