Senior Security Engineer - Pentester

Menlo Security
CA$158,000 - CA$237,000

About The Position

Menlo Security is seeking a forward-thinking Security Engineer to join their security team. This role focuses on offensive and defensive testing, penetration testing of product features, and the cloud architecture supporting the product. The engineer will operate within a complex multi-cloud environment (AWS & GCP), including traditional VMs and modern container-based architectures. Responsibilities include performing targeted assessments before each release, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and triaging bug bounty submissions and external vulnerability reports. The role leverages AI and large language models for tasks such as reconnaissance, generating attack vectors, analyzing configurations, and drafting vulnerability reports, with a strong emphasis on human judgment for validation and risk communication. The team's operating cadence is designed to identify, validate, and report vulnerabilities quickly to match release velocity.

Requirements

  • Deep architectural understanding of GCP and AWS. Capable of pivoting seamlessly between providers, performing manual configuration reviews of complex IAM/Resource hierarchies, and leveraging native APIs or modern CSPM frameworks to validate security controls.
  • Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).
  • Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage.
  • Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets). Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling. Strong understanding of browser security mechanisms (CSP, CORS, SameSite cookies, Subresource Integrity), secure authentication/authorization patterns (OAuth 2.0, OIDC, JWT), and security header configurations (HSTS, X-Frame-Options, Permissions-Policy). Proven ability to identify complex security flaws beyond automated scanner detection, validate findings through proof-of-concept development, and provide actionable remediation guidance to engineering teams.
  • Proficiency in Python, Go, or Bash to eliminate "toil" — writing custom scripts and tooling to automate vulnerability discovery, validate security controls, and streamline testing workflows.
  • Solid grasp of Terraform and cloud-native deployment patterns; able to interpret and audit complex HCL files to identify misconfigurations before they are provisioned.
  • Ability to write high-quality technical reports that Product Teams can easily understand and act upon.

Nice To Haves

  • Experience with Gatekeeper policies and Binary Authorization.

Responsibilities

  • Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.
  • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.
  • Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).
  • Assess the security posture of hybrid infrastructure spanning containers and virtual machines.
  • Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.
  • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.
  • Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.

Benefits

  • Competitive total compensation and benefits package
  • Eligibility for stock-based compensation grants
  • Collaborative, inclusive, and fun culture
  • Open communication
  • Support for new ideas
  • Opportunities to take initiative and implement new ideas
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service