Offensive Security Engineer
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA
Full Time Mid-level / Intermediate USD 140K - 330K
CoreWeave
Discover CoreWeave’s GPU cloud, purpose-built for AI with scalable, high-performance infrastructure and 24/7 support. Learn more today.CoreWeave is the AI Hyperscaler™, delivering a cloud platform of cutting edge services powering the next wave of AI. Our technology provides enterprises and leading AI labs with the most performant, efficient and resilient solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers covering every region of the US and across Europe. CoreWeave was ranked as one of the TIME100 most influential companies of 2024.
As the leader in the industry, we thrive in an environment where adaptability and resilience are key. Our culture offers career-defining opportunities for those who excel amid change and challenge. If you’re someone who thrives in a dynamic environment, enjoys solving complex problems, and is eager to make a significant impact, CoreWeave is the place for you. Join us, and be part of a team solving some of the most exciting challenges in the industry.
CoreWeave powers the creation and delivery of the intelligence that drives innovation.
What You’ll Do
CoreWeave’s Information Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Information Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security. They provide assurance to business & network partners that CoreWeave’s capabilities and technologies have been adequately hardened.
- Perform penetration testing as well as purple and red team exercises
- Conduct threat modeling, code reviews, and design reviews for development teams within the business
- Research/stay abreast of new hacking techniques and find ways to counter them
- Find effective solutions to information security related problems
- Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
- Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
- Demonstrated ability to present complex, technical information to both technical and non-technical audiences
- Strong time management, good technical writing, presentation, and documentation skills
- Ability to work with minimal supervision, attention to detail, and follow-through
- Other work-related duties as assigned
Investing in our people is one of our top priorities, and we value candidates who can bring their diversified experiences to our teams. Here are some qualities we’ve found compatible with our team. We'd love to talk about whether this aligns with your experience and interests and what you’re excited to work on next.
Who You Are
Minimum Qualifications
- Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
- At least five years of experience in the offensive information security industry
- Penetration Testing experience
- Strong technical background and experience writing and using offensive security tooling
- Experience using Kubernetes and Kubernetes-related security measures
- Extensive experience with Linux OS environments
- Ability to navigate ambiguity and determine solutions to underlying problems
- Excellent interpersonal, verbal, and written communication skills with strong attention to detail
- Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
- A strong desire to learn new technologies and skills
Preferred Qualifications
- Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
- An understanding of best practices and how to implement them at a business-wide level
- 5+ years' experience in the information security industry or related role
- Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member
The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $140,000-$330,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
What We Offer
The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs, including:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
Our Workplace
While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration
California Consumer Privacy Act - California applicants only
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com.
Tags: Blue team C CCPA Cloud Compliance EDR Golang Kubernetes Linux Offensive security OSCP Pentesting Privacy Python Red team Scripting
Perks/benefits: 401(k) matching Career development Competitive pay Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Startup environment Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.