Senior Offensive Security Engineer
icebergChicago (IL)
About the role
Senior Offensive Security Engineer Chicago preferred | NYC / London | Remote considered Compensation open - scope to exceed your current packageI’m working on a talent-led search for a Senior Offensive Security Engineer to join a highly technical global financial organisation building out its offensive security capability. This isn’t a role where you’ll simply be running automated pentesting tools. They want someone who genuinely thinks like an attacker. You’ll essentially operate as an internal hacker. Continuously looking for ways into systems, identifying weaknesses and then working directly with infrastructure, development and security teams to remediate and retest them. You’ll have a lot of ownership from day one, including: Red teaming and adversary simulation Penetration testing across infrastructure, applications, APIs and cloud Exploiting vulnerabilities across Windows, Linux and macOS environments Building your own offensive tooling alongside using established tools Working closely with defensive teams on purple team exercises Owning vulnerability remediation through to resolution Testing emerging attack vectors including AI and LLM environments Helping shape the wider offensive security methodology and roadmapI’m looking for someone with 5+ years of hands-on offensive security experience who can take an engagement from reconnaissance through exploitation, privilege escalation and lateral movement. Strong communication is equally important. You need to be able to document what you find, explain the risk and work collaboratively with engineering teams to actually fix it. Consultancies, financial institutions and mature internal red teams are all relevant backgrounds. There is currently no dedicated person doing this internally, so there is significant scope to make the function your own. As the capability grows, this could also develop into a Lead position. Compensation is deliberately open. The priority is finding the right person and I have flexibility to discuss packages that exceed current compensation for exceptional profiles. If offensive security is your bread and butter and you want a role where you’ll be trusted to genuinely test what is possible, drop me a message. George Taylor
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
