Senior Offensive Security Engineer

1 week ago


Washington, United States SiriusXM Full time

Responsibilities:

Who We Are:

SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices. Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories and music they love wherever they are.

This is the place where a diverse group of emerging talent and legends alike come to share authentic and purposeful songs, stories, sounds and insights through some of the best programming and technology in the world. Our critically-acclaimed, industry-leading audio entertainment encompasses music, sports, comedy, news, talk, live events, and podcasting. No matter their individual role, each of our employees plays a vital part in bringing SiriusXMs vision to life every day.

SiriusXM is the leading audio entertainment company in North America, and the premier programmer and platform for subscription and digital advertising-supported audio products. SiriusXMs platforms collectively reach approximately 150 million listeners, the largest digital audio audience across paid and free tiers in North America, and deliver music, sports, talk, news, comedy, entertainment and podcasts. Pandora, a subsidiary of SiriusXM, is the largest ad-supported audio entertainment streaming service in the U.S. SiriusXM's subsidiaries Simplecast and AdsWizz make it a leader in podcast hosting, production, distribution, analytics and monetization. The Companys advertising sales organization, which operates as SiriusXM Media, leverages its scale, cross-platform sales organization and ad tech capabilities to deliver results for audio creators and advertisers. SiriusXM, through SiriusXM Canada Holdings, Inc., also offers satellite radio and audio entertainment in Canada. In addition to its audio entertainment businesses, SiriusXM offers connected vehicle services to automakers.

How youll make an impact:

SiriusXMs Security Operations Center is seeking an experienced Offensive Security Engineer to ensure the security of our organization's systems and applications. The successful candidate will be responsible for performing security assessments, identifying, and verifying vulnerabilities, reviewing threat intelligence, and recommending appropriate solutions. The Offensive Security Engineer will also be responsible for threat hunting, triage and management of findings from our bug bounty program and providing guidance for security best practices.

What youll do:

  • Perform or manage various types of offensive security tests to identify potential risks, including:

    • Network, Mobile, and Application Penetration Testing

    • Source Code Reviews

    • Cloud Security Assessments

    • Attack Surface Management

    • Adversarial Simulation/Red Teaming

    • Vulnerability Assessments

    • Hardware/Device Security assessments

  • Test and validate security controls protecting production systems.

  • Investigate and evaluate risks identified from threat intelligence sources.

  • Triage, prioritize and investigate findings received from our bug bounty program, and coordinate with internal stakeholders for remediation efforts.

  • Analyze and evaluate security vulnerabilities, identifying and classifying possible threats.

  • Help implement best practices to improve system and application security.

  • Develop detailed reports to document findings and recommend solutions.

  • Present findings and recommendations to stakeholders and partners.

  • Ensure compliance with applicable regulations and industry standards by conducting tests and testing procedures.

  • Help the Incident Response team to assess and respond to security events by performing threat hunting and intelligence gathering.

  • Automate repeatable security tests.

  • Research, recommend, and track security-related technology solutions.

What youll need:

  • Bachelor's degree in Computer Science, Cybersecurity or related field, or equivalent experience.

  • Five or more years of experience in penetration testing, security vulnerability assessment, and threat hunting.

  • Experience testing in a production enterprise environment.

  • Experience in network security architecture, infrastructure security, and application security.

  • Experience testing hardware devices and mobile applications.

  • Strong understanding of cryptography, information security, and industry trends.

  • Excellent problem-solving and communication skills.

  • Able to work in a fast-paced, high-pressure environment.


At SiriusXM, we carefully consider a wide range of factors when determining compensation, including your background and experience. These considerations can cause your compensation to vary. We expect the base salary for this position to be in the range of $73,600 to $150,000 and will depend on your skills, qualifications, and experience. Additionally, this role might be eligible for discretionary short-term and long-term incentives. We encourage all interested candidates to apply.

Our goal at SiriusXM is to provide and maintain a work environment that fosters mutual respect, professionalism and cooperation. SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.

The requirements and duties described above may be modified or waived by the Company in its sole discretion without notice.

#LI-RE1



  • Washington, United States Amazon Full time

    Senior Security Engineer , AWS Offensive SecurityJob ID: 2831178 | Amazon Development Center U.S., Inc.Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? Do you like challenging assumptions? On the AWS Offensive Security team, you will help ensure our devices, applications, services, and systems are designed and...


  • Washington, United States SiriusXM Full time

    Responsibilities: Who We Are: SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices....


  • Washington, United States Parallel Consulting Full time

    Job OverviewWe are seeking a highly skilled Offensive Security Professional to join our team as a Senior Red Team Operator.This is a full-time, direct hire position with mostly remote working opportunities. The ideal candidate would be based near Washington DC.The estimated salary for this role is up to $190k base salary.About the RoleThe successful...


  • Washington, DC, United States Amazon Full time

    Security Engineer II, Offensive Security Penetration Testing Job ID: 2817030 | Amazon.com Services LLC Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them...


  • Washington, United States Plaid Inc Full time

    Drive Secure Innovation as Senior Director of Security EngineeringWe are looking for a seasoned engineering leader to spearhead the development of secure products and infrastructure at Plaid Inc.Salary: $250,000 - $350,000 per yearAbout the RoleThis is a critical cross-functional role that requires strong technical expertise and leadership skills to deliver...


  • Washington, United States Cannon Security Products Full time

    About the job The Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States GLO Comms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, DC, United States Cannon Security Products Full time

    About the jobThe Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, United States Bank of America Full time

    Senior Security Engineer Location: Denver, Colorado; Washington, District of Columbia; Chicago, Illinois Job Description: The Senior Security Engineer is responsible for leading multiple security engineering efforts that deliver enterprise security capabilities. This will include serving as a subject matter expert of security technology and acting as the...


  • Washington, United States Bank of America Full time

    Senior Security EngineerLocation: Denver, Colorado; Washington, District of Columbia; Chicago, IllinoisJob Description:The Senior Security Engineer is responsible for leading multiple security engineering efforts that deliver enterprise security capabilities. This will include serving as a subject matter expert of security technology and acting as the...


  • Washington, DC, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, DC, United States GLO Comms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Micro Data Systems Full time

    Senior Security EngineerRemote - Washington DC Metro Area preferredYour ImpactWork full-time at the customer siteCommunicate with the customer(s), sales teams, peers, engineering and support teams as appropriateUnderstand the customer environment, requirements, and security roadmap to implement the appropriate security solutionConfigure, implement, and...


  • Washington, United States Bank of America Full time

    Senior Adaptive Threat Replication EngineerLocation: Denver, Colorado; Seattle, Washington; Addison, Texas; Richmond, Virginia; Jersey City, New Jersey; Boston, Massachusetts; Charlotte, North Carolina; Washington, District of Columbia; Jacksonville, Florida; Chicago, IllinoisJob Description:At Bank of America, we are guided by a common purpose to help make...