Offensive Security Engineer

2 weeks ago


San Francisco, California, United States Block Full time

Company Description
Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.
Job Description
Block's Offensive Security team is seeking a highly skilled and motivated Senior Offensive Security Engineer to join our team. In this role, you will play a critical role in proactively identifying and exploiting vulnerabilities within our systems and infrastructure, mimicking real-world attacker tactics. Your insights will be used to improve our overall security posture and ensure we stay ahead of evolving threats.
You will:

  • Lead and execute complex Red Team engagements, simulating real-world attacker scenarios to uncover critical vulnerabilities across our network and applications.
  • Identify, research, and exploit various vulnerabilities (including zero-days) to gain unauthorized access to systems and data.
  • Develop custom tools, scripts, and exploit code.
  • Document findings in a clear, concise, and actionable manner, including detailed reports with working proofs of concept and recommendations for remediation.
  • Collaborate with the Blue Team and security leadership to prioritize vulnerabilities, develop mitigation strategies, and improve overall security posture.
  • Participate in knowledge sharing by mentoring junior team members and presenting findings, including opportunities to present at external conferences.


Qualifications
You have:

  • Minimum 5+ years of experience in offensive security engagements.
  • Proven experience leading and executing Red Team engagements.
  • Expertise in various operating systems (Mac, Linux, etc.) and scripting languages (Python, Ruby, etc.).
  • Experience with exploit development and post-exploitation techniques.
  • Excellent communication, collaboration, and problem-solving skills.
  • Ability to work independently and manage multiple projects simultaneously.
  • Strong understanding of the threat landscape and attacker motivations.


Bonus points for:

  • Experience with responsible disclosure and publicly reported CVEs.
  • Experience in a cloud environment (AWS, Azure, GCP).
  • Experience in using C2s and developing and deploying custom C2 and implants.


Additional Information
Block takes a market-based approach to pay, and pay may vary depending on your location. U.S locations are categorized into one of four zones based on a cost of labor index for that geographic area. The successful candidate's starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.
Zone A: USD $163,600 - USD $245,400
Zone B: USD $155,400 - USD $233,200
Zone C: USD $147,300 - USD $220,900
Zone D: USD $139,000 - USD $208,600
To find a location's zone designation, please refer to this resource . If a location of interest is not listed, please speak with a recruiter for additional information.
Full-time employee benefits include the following:

  • Healthcare coverage (Medical, Vision and Dental insurance)
  • Health Savings Account and Flexible Spending Account
  • Retirement Plans including company match
  • Employee Stock Purchase Program
  • Wellness programs, including access to mental health, 1:1 financial planners, and a monthly wellness allowance
  • Paid parental and caregiving leave
  • Paid time off (including 12 paid holidays)
  • Paid sick leave (1 hour per 26 hours worked (max 80 hours per calendar year to the extent legally permissible) for non-exempt employees and covered by our Flexible Time Off policy for exempt employees)
  • Learning and Development resources
  • Paid Life insurance, AD&D, and disability benefits


These benefits are further detailed in Block's policies. This role is also eligible to participate in Block's equity plan subject to the terms of the applicable plans and policies, and may be eligible for a sign-on bonus. Sales roles may be eligible to participate in a commission plan subject to the terms of the applicable plans and policies. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is a proud equal opportunity employer. We work hard to evaluate all employees and job applicants consistently, without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.
We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we're doing to build a workplace that is fair and square? Check out our I+D page .
Additionally, we consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.
We've noticed a rise in recruiting impersonations across the industry, where individuals are sending fake job offer emails. Contact from any of our recruiters or employees will always come from an email address ending with @ , @ , @ , or , @ .
Block, Inc. (NYSE: SQ) is a global technology company with a focus on financial services. Made up of Square, Cash App, Spiral, TIDAL, and TBD, we build tools to help more people access the economy. Square helps sellers run and grow their businesses with its integrated ecosystem of commerce solutions, business software, and banking services. With Cash App, anyone can easily send, spend, or invest their money in stocks or Bitcoin. Spiral (formerly Square Crypto) builds and funds free, open-source Bitcoin projects. Artists use TIDAL to help them succeed as entrepreneurs and connect more deeply with fans. TBD is building an open developer platform to make it easier to access Bitcoin and other blockchain technologies without having to go through an institution.
While there is no specific deadline to apply for this role, on average, U.S. open roles are posted for 70 days before being filled by a successful candidate.



  • San Francisco, California, United States Crusoe Energy Systems Full time

    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do - We aim to align the long term interests of the climate with the future of global computing infrastructure. As data centers consume an exponentially growing power footprint to deliver technology to all connected devices, we...


  • San Francisco, California, United States Crusoe Energy Systems Full time

    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do - We aim to align the long term interests of the climate with the future of global computing infrastructure. As data centers consume an exponentially growing power footprint to deliver technology to all connected devices, we...

  • ForgeRock Engineer

    3 weeks ago


    San Francisco, California, United States Cloud Security Services Full time

    Cloud Security Services is seeking experienced ForgeRock Engineers to join our team for a 6+ month assignment. The selected candidates will work closely with ForgeRock Professional Services on projects related to Identity Governance and Administration (IGA), Access Management (AM), and Cloud integrations. This is an excellent opportunity for individuals with...


  • San Francisco, California, United States Block Full time

    Company DescriptionBlock is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups...


  • San Francisco, California, United States Zetachain Full time

    About ZetaChainZetaChain aims to be the only blockchain you'll ever need. It is a layer 1 blockchain and developer platform that connects any L1 and L2, from Ethereum to Bitcoin and beyond. Access all of crypto in one place, as a developer or user.ZetaChain prides itself on its vibrant and active community, a testament to our growing impact and relevance in...


  • San Francisco, California, United States Discord Full time

    Discord is about giving people the power to create space to find belonging in their lives. Trusted by millions of people to keep their communications secure, private, and out of the hands of evildoers, security and privacy are necessary to Discord's success.We are looking for a Senior Security Engineer, Platform Security reporting to the Platform Security...


  • San Francisco, California, United States Gusto Full time

    About GustoGusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide. Our mission is to create a world...

  • Software Engineer

    2 months ago


    San Francisco, California, United States Abnormal Security Full time

    About Abnormal Abnormal Security is defining the next generation of email security defense. Our platform uses machine learning and artificial intelligence to baseline communication content, user identity, and behavioral signals in real-time and at scale in order to detect the abnormalities of email attacks.Customers love us because we consistently detect and...


  • San Francisco, California, United States Hybrid Pathways Full time

    About the Opportunity:Hybrid Pathways, a New Era Company, is seeking a Security Threat Detection Engineer Consultant to support client's Threat Management objectives to build, maintain and improve threat detections and alerting infrastructure and to ensure the right data collection and detections are in place to discover threats against infrastructure, data,...


  • San Francisco, California, United States Block Full time

    Company DescriptionBlock is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups...


  • San Francisco, California, United States Block Full time

    Company DescriptionIt all started with an idea at Block in 2013. Initially built to take the pain out of peer-to-peer payments, Cash App has gone from a simple product with a single purpose to a dynamic ecosystem, developing unique financial products, including Afterpay/Clearpay, to provide a better way to send, spend, invest, borrow and save to our 47...


  • San Francisco, California, United States Stripe Full time

    About StripeStripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead....


  • San Jose, California, United States QData Full time

    Hi Hope you are doing good... We have an urgent requirement below please go through Job description and send your updated profile and expected rate ASAP. Please reach me at .comJob Title GCP Security engineer Location San Jose CA Duration 6+ monthsSkills needed GCP Infra certified. Must have work with GCP Security controls with GCP for 1+ years. Strong...


  • San Diego, California, United States BAE Systems Full time

    Job Description BAE Systems is looking for a Cybersecurity/Information Assurance Engineer. The qualified candidate will be working on the security engineering team supporting engineering activities in a rapid development environment to support the specification, development, and application of computer security technologies, cybersecurity and information...


  • San Diego, California, United States BAE Systems Full time

    Job Description BAE Systems is looking for a Cybersecurity/Information Assurance Engineer. The qualified candidate will be working on the security engineering team supporting engineering activities in a rapid development environment to support the specification, development, and application of computer security technologies, cybersecurity and information...


  • San Jose, California, United States Cisco Full time

    Who We Are Cisco's Trust Transformation Office (TTO) plays a leading role in understanding customer needs for security, privacy, data protection, and customer data management.TTO advises, supports and collaborates with customers, Cisco Sales, Engineering, Government Affairs and Legal to build industry leading trust and visibility.On this team you will help...


  • San Francisco, California, United States Robust Intelligence Full time

    Robust Intelligence's mission is to eliminate AI Risk. As the world increasingly adopts AI into automated decision processes, we inherit great risk. Our flagship product is built to be integrated with existing AI systems to enumerate and eliminate risks caused by unintentional and intentional (adversarial) failure modes. With Generative AI becoming...


  • San Francisco, California, United States Quid Full time

    Senior DevOps EngineerAs a Senior DevOps engineer for the Quid product you will build software and processes to enable engineers to self-service the operation of NetBase Quid at scale and support 24x7 operations. Our developers are your customers. Your goal is to continuously assess and ease pain points of fellow engineers and of our Cloud infrastructure. We...


  • San Francisco, California, United States Robust Intelligence Full time

    About Robust Intelligence Robust Intelligence's mission is to eliminate AI Risk. As we transition into a world that is adopting AI into automated decision processes, we inherit a great deal of risk. Data drift, misclassified data, prediction biases and adversarial input easily distort AI outputs and can have detrimental effects. In addition, with viral...

  • Remote Data Engineer

    2 weeks ago


    San Francisco, California, United States Archipelo Full time

    CompanyArchipelo is building a code security platform that gives organizations the ability to verify the authenticity and provenance of code within their software development lifecycle. They are solving a painful problem that affects every software developer on the planet: ensuring software security, authenticity, integrity, and compliance - by providing the...