Staff Security Engineer, Offensive Security
CoreWeave is a specialized cloud provider focused on GPU accelerated use cases including VFX, AI/ML, Batch Processing and Real Time Experiences. We support countless AI/ML services in the text to image, NLP and broader AI/ML space, reducing client’s infrastructure management requirements with our Kubernetes based serverless GPU cloud offerings.
Job Description
About the Role:
CoreWeave’s Cyber Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Cyber Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security. They provide assurance to business & network partners that CoreWeave’s capabilities and technologies have been adequately hardened.
Responsibilities:
- Perform penetration testing as well as purple- and red-team exercises
- Conduct threat modeling, code reviews, and design reviews for development teams within the business
- Research/stay abreast of new hacking techniques and find ways to counter them
- Find effective solutions to cybersecurity problems
- Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
- Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
- Demonstrated ability to present complex, technical information to both technical and non-technical audiences
- Strong time management, good technical writing, presentation, and documentation skills
- Ability to work with minimal supervision, attention to detail, and follow-through
- Other work-related duties as assigned
Required Skills:
- Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
- At least five years of experience in the offensive cybersecurity industry
- Penetration Testing experience
- Strong technical background and experience writing and using offensive security tooling
- Experience using Kubernetes and Kubernetes-related security measures
- Extensive experience with Linux OS environments
- Ability to navigate ambiguity and determine solutions to underlying problems
- Excellent interpersonal, verbal, and written communication skills with strong attention to detail
- Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
- A strong desire to learn new technologies and skills
Nice-to-haves:
- Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
- An understanding of best practices and how to implement them at a business-wide level
- 5+ years' experience in the cybersecurity industry or related role
- Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member
The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $240,000-$275,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
Hybrid Workplace
Successful candidates will be expected to attend onboarding training at our NJ Headquarters within their first several weeks of employment, with subsequent quarterly travel requirements of 1 week duration.
If you reside within a 30-mile radius of our New Jersey, New York, or Philadelphia offices, we're excited for you to join us at the office at least three times a week, recognizing the significance we place on fostering connections, collaboration, and creativity within our office culture. Our commitment to operating as a hybrid workplace underscores our dedication to enabling our employees to tailor their work-life balance to their individual preferences.
About the Role:
CoreWeave’s Cyber Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Cyber Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security. They provide assurance to business & network partners that CoreWeave’s capabilities and technologies have been adequately hardened.
Responsibilities:
- Perform penetration testing as well as purple- and red-team exercises
- Conduct threat modeling, code reviews, and design reviews for development teams within the business
- Research/stay abreast of new hacking techniques and find ways to counter them
- Find effective solutions to cybersecurity problems
- Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
- Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
- Demonstrated ability to present complex, technical information to both technical and non-technical audiences
- Strong time management, good technical writing, presentation, and documentation skills
- Ability to work with minimal supervision, attention to detail, and follow-through
- Other work-related duties as assigned
Required Skills:
- Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
- At least five years of experience in the offensive cybersecurity industry
- Penetration Testing experience
- Strong technical background and experience writing and using offensive security tooling
- Experience using Kubernetes and Kubernetes-related security measures
- Extensive experience with Linux OS environments
- Ability to navigate ambiguity and determine solutions to underlying problems
- Excellent interpersonal, verbal, and written communication skills with strong attention to detail
- Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
- A strong desire to learn new technologies and skills
Nice-to-haves:
- Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
- An understanding of best practices and how to implement them at a business-wide level
- 5+ years' experience in the cybersecurity industry or related role
- Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member
The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $240,000-$275,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
Hybrid Workplace
Successful candidates will be expected to attend onboarding training at our NJ Headquarters within their first several weeks of employment, with subsequent quarterly travel requirements of 1 week duration.
If you reside within a 30-mile radius of our New Jersey, New York, or Philadelphia offices, we're excited for you to join us at the office at least three times a week, recognizing the significance we place on fostering connections, collaboration, and creativity within our office culture. Our commitment to operating as a hybrid workplace underscores our dedication to enabling our employees to tailor their work-life balance to their individual preferences.