Senior Security Engineer
Job description
Senior Security Engineer at Menlo Security.
About the role
You will own the security validation of new product features and the underlying multi-cloud infrastructure before every release, operating at the intersection of offensive testing and cloud architecture. This role requires you to be fanatical about seeing things through to completion while staying humble enough to absorb feedback and coach peers when needed. You will partner closely with fellow Penetration Testing and Cloud Security engineers to run targeted assessments in the short testing window immediately preceding each release. A strong service orientation will drive how you communicate risk and remediation guidance to product teams so that security becomes an accelerator rather than a bottleneck. You will apply ethical judgment and critical thinking to solve complex problems, balancing speed with precision in a fast-moving environment. AI and large language models are core to how this team works day to day, and you will help shape how these tools are used responsibly to improve security outcomes.
Key facts
What you'll do
Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.
Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.
Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI) to uncover weaknesses in authentication, authorization, and input validation.
Assess the security posture of hybrid infrastructure spanning containers and virtual machines, including managed and unmanaged workloads.
Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.
Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.
Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication with professionalism and empathy.
Collaborate with cross-functional stakeholders to translate business requirements into security testing objectives and success criteria.
Measure and report on the effectiveness of security testing activities using defined KPIs, highlighting trends, process gaps, and improvement opportunities.
Continuously refine testing playbooks and tooling to keep pace with evolving cloud services, attack techniques, and release cadence.
Requirements
You must possess multi-cloud fluency with deep architectural understanding of GCP and AWS, enabling you to pivot seamlessly between providers and perform manual configuration reviews of complex IAM and resource hierarchies.
You have proven experience auditing and hardening managed container services such as GKE Autopilot and Standard, EKS, and ECS, as well as self-hosted or unmanaged workloads running Kubernetes and similar container runtimes.
You demonstrate the ability to integrate AI and large language model tools, such as Gemini and Claude, into the penetration testing lifecycle to increase speed and coverage without sacrificing rigor.
You hold expert-level knowledge of web application security principles and offensive testing methodologies, including deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation techniques, and API security for both REST and WebSockets.
You have hands-on experience with cloud-native security controls, including identity and access management, logging, monitoring, and configuration validation against established security baselines.
You are comfortable working in a fast-paced environment where release velocity is high, and you can triage vulnerabilities, validate findings, and communicate risk clearly and quickly to both technical and non-technical audiences.
You apply ethical reasoning in all security activities, respecting data privacy, legal boundaries, and responsible disclosure practices when handling bug bounty submissions and external vulnerability reports.
You communicate effectively in writing and speaking, producing concise, actionable vulnerability reports and proof-of-concept demonstrations that enable product teams to remediate efficiently.
Practical notes
The role is based in the AMER region in Canada, and candidates must be eligible to work in this location without sponsorship.
There is no compensation information provided in the SOURCE material, so pay details are omitted from this job page.
The team operates on a full-time engagement basis with a standard working schedule aligned with business hours.
No visa sponsorship is offered, and candidates must already have the right to work in Canada.
The hiring process is aligned with release cadence and operational needs, so candidates should expect timely decision-making to support fast-paced delivery.