Posted on 
Oct 11, 2024

Staff Security Engineer, Offensive Security

Mid-Senior ICs
Engineering, IT
CoreWeave
CoreWeave
CoreWeave
Private
101-250
Software, Security & Developer Tools

CoreWeave is a specialized cloud provider focused on GPU accelerated use cases including VFX, AI/ML, Batch Processing and Real Time Experiences. We support countless AI/ML services in the text to image, NLP and broader AI/ML space, reducing client’s infrastructure management requirements with our Kubernetes based serverless GPU cloud offerings.

Job Description

About the Role:

CoreWeave’s Cyber Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Cyber Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security.  They provide assurance to business & network partners that CoreWeave’s capabilities and technologies have been adequately hardened.

Responsibilities:

  • Perform penetration testing as well as purple- and red-team exercises
  • Conduct threat modeling, code reviews, and design reviews for development teams within the business
  • Research/stay abreast of new hacking techniques and find ways to counter them
  • Find effective solutions to cybersecurity problems
  • Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
  • Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
  • Demonstrated ability to present complex, technical information to both technical and non-technical audiences
  • Strong time management, good technical writing, presentation, and documentation skills
  • Ability to work with minimal supervision, attention to detail, and follow-through
  • Other work-related duties as assigned

Minimum Qualifications:

  • Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
  • At least five years of experience in the offensive cybersecurity industry
  • Penetration Testing experience
  • Strong technical background and experience writing and using offensive security tooling
  • Experience using Kubernetes and Kubernetes-related security measures
  • Extensive experience with Linux OS environments
  • Ability to navigate ambiguity and determine solutions to underlying problems
  • Excellent interpersonal, verbal, and written communication skills with strong attention to detail
  • Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
  • A strong desire to learn new technologies and skills

Nice-to-haves:

  • Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
  • An understanding of best practices and how to implement them at a business-wide level
  • 5+ years' experience in the cybersecurity industry or related role
  • Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member

The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $240,000-$275,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

About the Role:

CoreWeave’s Cyber Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Cyber Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security.  They provide assurance to business & network partners that CoreWeave’s capabilities and technologies have been adequately hardened.

Responsibilities:

  • Perform penetration testing as well as purple- and red-team exercises
  • Conduct threat modeling, code reviews, and design reviews for development teams within the business
  • Research/stay abreast of new hacking techniques and find ways to counter them
  • Find effective solutions to cybersecurity problems
  • Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
  • Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
  • Demonstrated ability to present complex, technical information to both technical and non-technical audiences
  • Strong time management, good technical writing, presentation, and documentation skills
  • Ability to work with minimal supervision, attention to detail, and follow-through
  • Other work-related duties as assigned

Minimum Qualifications:

  • Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
  • At least five years of experience in the offensive cybersecurity industry
  • Penetration Testing experience
  • Strong technical background and experience writing and using offensive security tooling
  • Experience using Kubernetes and Kubernetes-related security measures
  • Extensive experience with Linux OS environments
  • Ability to navigate ambiguity and determine solutions to underlying problems
  • Excellent interpersonal, verbal, and written communication skills with strong attention to detail
  • Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
  • A strong desire to learn new technologies and skills

Nice-to-haves:

  • Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
  • An understanding of best practices and how to implement them at a business-wide level
  • 5+ years' experience in the cybersecurity industry or related role
  • Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member

The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $240,000-$275,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

Receive Tech Ladies'
newest jobs in your inbox,
every week.

Join Tech Ladies for full-access to the job board, member-only events, and more!

If you're already a member, we haven't forgotten you. We promise. It's a new system. If you fill out the form once, it'll remember you going forward. Apologies for the inconvenience.

No items found.
No items found.
Engineering
Engineering
IT
IT
In-Person
In-Person