Senior Offensive Security Engineer - Internal Audit

Posted Yesterday
Easy Apply
Be an Early Applicant
Elmhurst, IL, USA
Hybrid
170K-250K Annually
Senior level
eCommerce • Hardware • Information Technology • Logistics • Mobile • Software • App development
McMaster-Carr is a one-stop shop for the materials that keep plants running.
The Role
Conduct risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments. Evaluate preventive, detective, and response controls, validate detection and incident-response effectiveness, and translate technical findings into risk-based remediation recommendations for technical teams, executives, Internal Audit, and the Audit Committee. Build an independent, continuously improving offensive-security assurance program.
Summary Generated by Built In
Who We Are

McMaster-Carr is a leading e-commerce company that industrial customers have trusted for 125 years. Our products help them get manufacturing lines back up quickly, keep operations running smoothly, and prototype the next generation of innovative solutions. We earn and keep that trust by offering the right products, making them easy to find, and delivering them fast, so customers can solve problems with greater speed, precision, and ease.

Our industry-leading e-commerce experience, indispensable product selection, and world-class service bring hundreds of thousands of customers to mcmaster.com each day. But we're never standing still. Curious, exceptional people are at the heart of our evolution. They turn new challenges and disruptive technologies into opportunities to refine our operations, expand our offering, and deliver a better experience for every customer.


What you will do

McMaster-Carr is seeking a Senior Offensive Security Engineer to build and operate an independent security assurance capability within Internal Audit. Using penetration testing, adversary emulation, and purple-team techniques, you will evaluate whether our cybersecurity controls work as intended against realistic scenarios.

This is not a conventional penetration-testing role focused only on finding vulnerabilities. As a member of McMaster-Carr’s Internal Audit team, your work will help determine whether controls prevent attacks, whether monitoring produces meaningful alerts, whether response processes work, and where security investments should be strengthened. You will translate technical findings into practical risk insight and solutions for Information Security, business leaders, executive management, and the Audit Committee.

Work is independent yet collaborative with strong governance. You will partner closely with Information Security while remaining organizationally independent from the teams responsible for designing and operating the controls you assess.

  • Design and execute risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments.
  • Test whether preventive, detective, and responsive security controls perform as expected under realistic attack Evaluate attack paths, control weaknesses, detection coverage, alert quality, and the effectiveness of incident-response procedures.
  • Collaborate with Security Operations and other technical teams during purple-team exercises to validate detection and response
  • Develop test plans, objectives, techniques, targets, safeguards, and rules of engagement for management approval before execution.
  • Translate technical findings into risk-based remediation recommendations that help leaders of technical teams, Internal Audit leadership, executive management and the Audit Committee prioritize security improvements and
  • Build a repeatable, continuously improving offensive-security assurance program informed by a growing understanding of our environment.
  • Partner with external security firms when specialist expertise or independent corroboration is
 Who You Are

We are seeking bright, curious, and ambitious individuals eager to make an impact. Ideal candidates have:

  • 5+ years of relevant offensive security experience, including at least three recent years conducting penetration tests, red team engagements adversary emulation exercises, or purple team assessments in complex military or civilian environments. 
  • A four-year college degree
  • Demonstrated ability to independently scope, plan, execute, document, and clearly communicate technically sophisticated security assessments to both engineering and executive-level audiences.
  • Broad knowledge of enterprise attack surfaces, including hands-on experience with several of the following domains: identity systems (LDAP, IAM), operating systems (Windows and Linux), network infrastructure, cloud platforms, web applications and APIs, endpoint systems, and security monitoring tools.
  • Practical experience identifying and validating exploitable attack chains, bypassing or testing security controls, and determining whether detection and response mechanisms function as intended.
  • Strong scripting or automation skills and the ability to adapt tools and techniques to assess unfamiliar environments effectively.
  • Ability to operate safely and effectively in production-sensitive environments while maintaining strict adherence to rules of engagement and approved scope.
  • Sound judgment, discretion, and a disciplined approach to handling privileged information and sensitive findings.
  • Excellent written and verbal communication skills that translate technical weaknesses into clear business impact and remediation priorities for both engineers and senior leaders.
  • A collaborative style that builds trust with Security and Systems teams while maintaining the objectivity required of an independent assurance function.
  • A track record of taking initiative, identifying high-impact areas for investigation, and driving work through remediation and retesting.

Compensation

Total cash compensation generally ranges from $170,000-$250,000 and includes profit sharing based on company performance. 


Growth & Learning

  • 100% tuition reimbursement
  • Informal and formal mentorship
  • Employee resource groups

Health & Wellbeing

  • Medical, dental, pharmacy and vision plans without monthly premiums
  • Inclusive, all-gender benefits

Family & Future

  • Paid parental leave for all new parents
  • Adoption and surrogacy assistance
  • First-time home buyer assistance
  • Industry-leading company-funded retirement accounts

Time Off

  • Paid vacation and personal time

Equal Opportunity Employer

We are proud to be an Equal Opportunity Employer and dedicated to providing employees a workplace with reasonable accommodations and free of discrimination, harassment, and retaliation. At McMaster-Carr, we do not make employment decisions based on age, ethnicity, citizenship status, military status, gender identity and expression, race, religion, disability status, marital status, sexual orientation, or any other legally protected group.

This position is not eligible for work authorization sponsorship by McMaster-Carr.

Data We Collect

We may collect professional, education and employment-related data, and any assessments made throughout the recruiting process, to evaluate candidacy for employment. To communicate with job applicants, we may collect applicant names, contact information, and other personal identifiers, including those outlined in the California customer records statute. Through voluntary disclosure, we may also collect protected classifications under federal or California law (e.g., race, gender, etc.). For additional details about the personal information we collect and its uses, please click here.

Skills Required

  • 5+ years of relevant offensive security experience
  • At least 3 recent years conducting penetration tests, red-team engagements, adversary-emulation exercises, or purple-team assessments
  • Four-year college degree
  • Ability to independently scope, plan, execute, document, and communicate sophisticated security assessments
  • Broad enterprise attack-surface knowledge, including several of LDAP/IAM, Windows, Linux, network infrastructure, cloud platforms, web applications, APIs, endpoint systems, and security monitoring tools
  • Experience identifying and validating exploitable attack chains and testing security controls, detection, and response mechanisms
  • Strong scripting or automation skills
  • Ability to work safely in production-sensitive environments and follow approved rules of engagement
  • Sound judgment, discretion, and disciplined handling of privileged information and sensitive findings
  • Excellent written and verbal communication skills for technical and executive audiences
  • Collaborative style while maintaining objectivity as an independent assurance function
  • Track record of initiative, identifying high-impact investigations, and driving remediation and retesting

McMaster-Carr Compensation & Benefits Highlights

  • Healthcare Strength Healthcare Strength: Health coverage is described as comprehensive and notably valuable, with medical, dental, pharmacy, and vision plans that do not require monthly premiums. Mental‑health and wellness options, including complimentary therapy sessions in some materials, are also highlighted.
  • Retirement Support Retirement Support: Retirement programs are portrayed as robust, featuring company‑funded retirement accounts and generous profit sharing that can materially augment total compensation. Access to financial counselors and related protections further support long‑term security.
  • Parental & Family Support Parental & Family Support: Family benefits include paid parental leave for all new parents plus adoption and surrogacy assistance. Additional supports such as college assistance for dependents and first‑time home‑buyer help are noted.

McMaster-Carr Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elmhurst, IL
Year Founded: 1901

What We Do

McMaster-Carr is trusted by industrial customers around the world to keep manufacturing lines running, operations moving, and turn new ideas into real products. Since 1901, we’ve earned that trust by offering the right products, making them easy to find, and delivering them quickly. Our industry-leading e-commerce experience, indispensable product selection, and world-class service bring hundreds of thousands of customers to our site each day. But we never stop innovating. We turn ambiguous problems, new challenges, and disruptive technologies into opportunities to refine our operations, expand our offering, and deliver the best experience for every customer. Behind it all are our people: curious, exceptional problem-solvers who take pride in getting every detail right for our customers.

Why Work With Us

Curious people thrive at McMaster-Carr. Engineers build technical knowledge through learning groups, book clubs, and one-on-one mentoring. Diverse projects offer experience with a wide range of technologies to encourage career-long learning. Great work is celebrated in an inclusive workplace dedicated to equity, growth and employee well-being.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

McMaster-Carr Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Lead Software Engineers and other technology roles benefit from a mix of onsite collaboration with teams and remote work. Other roles may be fully onsite depending on responsibilities.

Typical time on-site: 3 days a week
HQElmhurst, IL
McMaster-Carr is in a thriving suburb with easy access to city living via public transportation and highways. The local community offers a vibrant downtown full of restaurants and pubs, parks, historic homes, art museums and a university.

Similar Jobs

McMaster-Carr Logo McMaster-Carr

IT Audit Project Lead

eCommerce • Hardware • Information Technology • Logistics • Mobile • Software • App development
Easy Apply
Hybrid
Elmhurst, IL, USA
200K-259K Annually

McMaster-Carr Logo McMaster-Carr

IT Operations Technician

eCommerce • Hardware • Information Technology • Logistics • Mobile • Software • App development
Easy Apply
Hybrid
Elmhurst, IL, USA
124K-142K Annually

McMaster-Carr Logo McMaster-Carr

MBA Summer Internship: Leadership, Strategy, & Operations - Products & Publishing (MBA Class of 2028)

eCommerce • Hardware • Information Technology • Logistics • Mobile • Software • App development
Easy Apply
Hybrid
Chicago, IL, USA
185K-230K Annually

McMaster-Carr Logo McMaster-Carr

Engineering Manager

eCommerce • Hardware • Information Technology • Logistics • Mobile • Software • App development
Easy Apply
Hybrid
Elmhurst, IL, USA
230K-320K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account