Senior Security Engineer focusing on offensive and defensive security at Menlo Security. Conducting penetration testing and ensuring cloud architecture security in multi-cloud environments.
Responsibilities
Collaborative Penetration Testing (AWS & GCP): Work in tandem with a peer pentester to conduct deep-dive penetration tests of our products across our multi-cloud environment.
Control Plane: Review IAM policies, service configurations, and cloud-native permission structures.
Data Plane & Web UI: Execute dynamic testing against web interfaces and API endpoints.
Infrastructure Review: Assess the security posture of a hybrid infrastructure that mixes containers and Virtual Machines (VMs) infrastructures.
AI-Augmented Security Assessments: Actively utilize AI and Large Language Models (LLMs) to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports.
Pipeline Management: Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.
Requirements
Multi-Cloud Fluency: Demonstrate a deep architectural understanding of GCP and AWS.
Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).
AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage.
Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets). Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling.
Security Automation: Proficiency in Python, Go, or Bash to eliminate "toil."
Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns.
Benefits
All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance.
Hiring QA Functional Lead in Toronto, ON (Hybrid). Requires 3+ years Test Lead experience, banking domain knowledge, and HP ALM, JIRA, Confluence skills.
Manager, QA responsible for technology services quality assurance standards and team leadership in a not - for - profit organization. Leading processes to maximize benefits in digital transformation strategy.
Quality Assurance Administrator supporting franchise quality assurance across 340 locations in North America. Ensuring compliance with insurance carrier standards and managing claims effectively.
FSQA Intern providing analytical and administrative support to Quality & Food Safety team at Sysco. Involves data collection, analysis, and reporting related to food safety and quality programs.
Linguist (UAT Tester) ensuring high - quality Canadian French content for AI systems. Responsible for localization QA and UAT testing with editing and reviewing tasks.
Quality Engineer/Specialist responsible for product quality and quality activities for new development projects at Murata Power Solutions. Focused on electronics in sustainable power conversion.
QA Specialist in manual and automated testing for Pacific Programming and Tech Inc. Ensuring product quality, collaborating with development teams, and implementing test plans and cases.
AI Quality Assurance Intern at Cresta evaluating AI behavior and quality for customer interactions. Collaborating with AI Delivery team on quality assurance processes and model validation.