Senior Offensive Security Engineer
$101.4k - $152.1kEcolab
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Senior Offensive Security Engineer, Commercial Products will actively perform security testing for most of their time while supporting offensive security engagements, mentoring engineers as needed, and helping improve engagement scope, testing methods, reporting quality, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab's commercial offerings.
What you will do:
Perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Contribute to repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
Support improvements to Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
Support coordination with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.
Minimum Qualifications:
Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
5+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
Experience supporting offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
Experience supporting technical workstreams, mentoring engineers, or coordinating testing activities while remaining directly involved in hands-on testing and analysis.
Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.
Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.
Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.
Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.
Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.
Strong interpersonal, analytical, problem-solving, organizational, and written/verbal communication skills.
Ability to communicate technical findings clearly to software engineers, architects, cybersecurity leaders, product owners, and non-technical business stakeholders.
Ability to accommodate a flexible work schedule for supporting global activities.
Preferred Qualifications:
One practical offensive security certification such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certification.
Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.
Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.
Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.
Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.
Experience contributing to testing playbooks, reporting templates, engagement standards, risk-rating models, and remediation validation procedures.
Experience with AI-enabled products, AI integrations, or the security implications of AI/ML capabilities in commercial software environments.
Ability to influence without authority and drive security improvements across globally distributed engineering, product, and technology teams.
Annual or Hourly Compensation Range
The pay range for this position is $101,400.00 - $152,100.00. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.Benefits
Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families.Click here to see our benefits.
If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.
Potential Customer Requirements Notice
To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:
- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.
Americans with Disabilities Act (ADA)
Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.
Our Commitment to a Culture of Inclusion & Belonging
At Ecolab, we believe the best teams are inclusive. We are on a journey to create a workplace where every associate can grow and achieve their best. We are committed to fair and equal treatment of associates and applicants and recruit, hire, promote, transfer and provide opportunities for advancement based on individual qualifications and job performance. In all matters affecting employment, compensation, benefits, working conditions, and opportunities for advancement, we will not discriminate against any associate or applicant for employment because of race, religion, color, creed, national origin, citizenship status, sex, sexual orientation, gender identity and expressions, genetic information, marital status, age, disability, or status as a covered veteran.In addition, we are committed to furthering the principles of Equal Employment Opportunity (EEO) through Affirmative Action (AA).
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.
$101.4k - $152.1k
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile...SeniorHourly payMinimum wageFull timeLocal areaFlexible hours$100k - $150k
Responsibilities Sentinel Technologies is searching for a passionate and experienced Senior Network Security Engineer who thrives in a fast-paced, solutions-driven environment. As a Senior Network Security Engineer you will design, implement, and configure secure network...SeniorFull timeTemporary workRemote workFlexible hours$110k - $150k
...Security Engineer Compensation: $110,000 – $150,000 Work Environment: Hybrid (1 Day per week in Office) Daily Schedule: 8:00am – 4:30pm CST Office Locations: Skokie, IL; Warrenville, IL; Arlington Heights, IL Benefits : M/D/V, 401K, Pet Insurance, Tuition Reimbursement...SuggestedWork experience placementWork at office1 day per week- DHJJ is seeking an experienced accountant to apply accounting knowledge to record and analyze client data as part of a collaborative team. The role offers growth toward becoming a principal in the firm and opportunities to work with clients both in person and remotely. ...SeniorRemote work
- Worker Type:EmployeeThe primary role of the Mainframe System Security Engineer is to create, modify and maintain security access on internal and external userids and security rules access for mainframe systems. All three security products, ACF2, Top Secret and RACF are...SuggestedFull timeRemote work
$137.4k - $206.2k
Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture, engineering, and exposure management... ...experience managing multi-team security functions at the Senior Manager or Director level.Demonstrated success delivering...Hourly payMinimum wageFull timeLocal area$102.17k
...across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the... ...resilient against evolving threats. You will work closely with engineering and development teams to safeguard systems that...SeniorWork experience placementH1b- ...residents and referral partners, and guide prospects from first inquiry to move-in. This leadership role blends strategic planning with hands-on relationship building and community engagement, ideal for a results-driven salesperson with a passion for senior #J-18808-Ljbffr...Senior
$85.68k - $130.9k
...with a minimum of 12 years of design experience. This role involves preparing various substation drawings and collaborating with engineers. Offering a hybrid work schedule, competitive salary range of $85,679 - $130,899, and comprehensive award-winning benefits. The ideal...Senior- ..., VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have developed our methodologies and processes based on the IT Infrastructure...
- A leading staffing agency is seeking a Senior Manager, Benefits to lead the design and administration of diverse health and wellness programs. This role focuses on enhancing employee engagement and ensuring compliance with regulations. The ideal candidate will have extensive...Senior
$65.52 - $101.56 per hour
...Enterprise Security Architect Hourly Pay Range: $65.52 - $101.56 - The hourly pay rate offered is determined by a candidate's expertise... ..., Enterprise Architecture, and technical and application engineering teams, as well as various clinical and non-clinical stakeholders...Hourly payFull timePart timeFor contractorsLocal areaMonday to Friday- Philadelphia Insurance Companies is seeking a Sr. Marketing Representative to join our sales team in Naperville/Chicago, IL or Milwaukee/Madison, WI. You will qualify leads and solicit business through agents, brokers and direct channels, while maintaining strong relationships...Senior
- ...Senior Business Analyst/Product OwnerExperience Required: 10+ YearsRoles & Responsibilities:The Product Owner is responsible for establishing a clear vision and release plan for the product(s).Must define, prioritize, and clarify requirements; work with others to understand...SeniorTemporary work
- ...CDM Smith is seeking a skilled Mechanical Engineer with HVAC and plumbing expertise to join our team. The role offers a hybrid work environment with potential offices in multiple locations and opportunities to lead projects and shape innovative, sustainable solutions....Senior
$217k - $303.9k
...internet’s largest sources of information. For more information, visit redditinc.com . Reddit is hiring a Staff Product Security Engineer to make the secure path the easiest path for engineers and AI agents. You'll lead the design and delivery of secure frameworks...For contractorsWork experience placementRemote work- GSK US is seeking a Hospital Senior Account Manager to advance formulary access, protocol readiness, discharge pathway support, and demand generation across targeted hospital accounts in Evanston, Naperville, and surrounding markets. You will engage Infectious Disease...Senior
- KeHE Distributors, LLC in Naperville, Illinois, is seeking a Director of Sales responsible for driving revenue growth and market expansion. The successful candidate will own the commercial strategy and lead a high-performing sales team. With over 10 years of experience ...Senior
- ...positive impact and growing together. The culture emphasizes development, opportunity, and a force-for-good across the organization. The Senior Manager of Accounting will own GAAP financial reporting, lead a team of accountants, and drive improvements through automation and...Senior
- Sargent Lundy in Warrenville, Illinois is looking for a Substation Physical Designer. This role offers a hybrid work schedule with responsibilities including the preparation of various substation drawings and performing site walkdowns. Candidates should have a minimum of...Senior
- Rexel USA is looking for an Order Packer - Large Parcel to join the Talley team in Woodridge, IL. You will pack customer orders and handle transfers and vendor claims with accuracy and efficiency, following Talley’s procedures. The role emphasizes high production, attention...Senior
- The Hartford is seeking a Sr Pricing Analyst to drive profitable growth for its $3 billion Auto and Home portfolio by analyzing and evaluating pricing performance at the state level, and delivering action-oriented solutions to Pricing and Product Management leadership. ...SeniorRemote job
$85k - $115k
Pinnacle Fertility is seeking an Embryologist to join our team in Naperville, IL. This full-time, on-site position offers responsibility for culture, handling, and manipulation of human embryos, with collaborative care across the ART team. Ideal candidates have a Bachelor...SeniorFull time$120k - $150k
Air Comfort in Naperville, Illinois is seeking an experienced BAS Account Executive who will serve as a liaison between Applied Controls and customers. This role requires a minimum of 10 years in a sales-driven account management position, alongside strong communication...Senior- Acrisure, a global fintech leader, is seeking a Senior Manager, Financial Planning & Analysis in the US. The role partners with the Enterprise Technology Group, driving forecasting, budgeting, and performance management. You will build driver-based models, deliver executive...Senior
- ATI Restoration is seeking a Project Director to lead complex restoration projects through design, permitting and construction. You will oversee Project Managers, manage budgets and collection efforts, and mentor estimators to ensure project success. The role emphasizes...SeniorFor subcontractor
- The U.S. Department of Energy, Office of Science, seeks a Senior Executive Service (SES) Site Office Manager for the Fermi National Accelerator Laboratory in Batavia, Illinois. This role requires ECQs and TQs, with emphasis on leadership of a large-scale national laboratory...SeniorWork at office
- CapinCrouse LLP in Naperville, Illinois, is seeking an experienced audit professional who will provide high-level service to clients and drive firm growth. Responsibilities include managing multiple engagements, building client relationships, and participating in business...Senior
- Acrisure is seeking a Senior Financial Reporting Accountant to lead the monthly and quarterly internal financial reporting lifecycle. The role utilizes Workiva Wdesk, Workday, and OfficeConnect to ensure accurate, timely reporting and data integrity across GL sources....Senior
- ...trusted tax expertise, the firm has built long-standing client relationships and a collaborative team culture. They are seeking a Tax Senior to join their growing practice and play a key role in supporting clients, mentoring staff, and delivering high-quality tax services...SeniorFor contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Offensive Security Engineer. Be the first to apply!
- senior grant accountant Naperville, IL
- senior tax Naperville, IL
- senior consulting engineer Naperville, IL
- senior dynamics crm developer Naperville, IL
- senior brand strategist Naperville, IL
- sr accountant Naperville, IL
- senior medical science liaison Naperville, IL
- senior property accountant Naperville, IL
- senior software engineer remote Naperville, IL
- senior digital account manager Naperville, IL

