Lead Offensive Security Engineer

Ecolab Inc.Naperville, IL
$120,500 - $180,700

About The Position

The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Lead Offensive Security Engineer will actively perform security testing for most of their time while also leading a small internal team, helping define engagement scope, testing methods, reporting standards, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab’s commercial offerings.

Requirements

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
  • 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
  • Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
  • Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
  • Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.
  • Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
  • Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.
  • Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.
  • Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.
  • Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.
  • Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.
  • Strong interpersonal, analytical, problem-solving, organizational, and written/verbal communication skills.
  • Ability to communicate technical findings clearly to software engineers, architects, cybersecurity leaders, product owners, and non-technical business stakeholders.
  • Ability to accommodate a flexible work schedule for supporting global activities.

Nice To Haves

  • Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications.
  • Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.
  • Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.
  • Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.
  • Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.
  • Experience developing testing playbooks, reporting templates, engagement standards, risk-rating models, and remediation validation procedures.
  • Experience with AI-enabled products, AI integrations, or the security implications of AI/ML capabilities in commercial software environments.
  • Ability to influence without authority and drive security improvements across globally distributed engineering, product, and technology teams.

Responsibilities

  • Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
  • Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
  • Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
  • Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
  • Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
  • Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
  • Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
  • Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
  • Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
  • Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
  • Help improve Ecolab’s vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
  • Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
  • Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
  • Act as an advocate and champion for practical, risk-based product security across Ecolab’s commercial digital product teams.

Benefits

  • Annual bonus pay based on performance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service