Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Offensive Security Engineer

SPAN Inc

Our Mission

SPAN is enabling electrification for all

We are a mission-driven company designing, building, and deploying products that electrify the built environment, reduce carbon emissions, and slow the effects of climate change.
  • Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere.
  • Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives.
At SPAN, we believe in:
  • Enabling homes and vehicles powered by clean energy
  • Making electrification upgrades possible
  • Building more resilient homes with reliable backup
  • Designing a flexible and distributed electrical grid
The Role

We are looking for a hands-on individual with an offensive security engineering mindset to join us as a Senior Offensive Security Engineer (Threat & Response) as part of the Security team at SPAN. In this role, you will act as our internal ethical hacker, conducting full-scope, threat intelligence-informed adversary emulations across our cloud infrastructure, proprietary applications, and corporate IT assets. We are looking for someone who can continuously simulate real-world cyber attacks to identify vulnerabilities before malicious actors do, while seamlessly leading the full Technical Incident Response (IR) lifecycle , from initial triage and containment through to eradication and post-incident recovery, when security events occur.
What You'll Do (Responsibilities)
  • Execute full-scope adversary emulations against any valuable objectives across SPAN's cloud environments , proprietary web/mobile applications, APIs, and corporate IT infrastructure.
  • Lead Technical Incident Response operations during live security events, leveraging your understanding of attacker TTPs to direct rapid containment, threat eradication, and system recovery.
  • Provide a crucial feedback loop to our Cloud Infrastructure and Software Engineering teams by translating offensive findings into proactive detection rules and actionable hardening requirements.
  • Own the end-to-end VDP pipeline , serving as the primary internal owner for our public vulnerability disclosure channel, managing communications with external researchers, and validating incoming reports.
  • Build automated scripts and tools to streamline continuous internal security testing, vulnerability scanning, and VDP triage workflows
  • Utilize frameworks like MITRE ATT&CK to design and execute red team scenarios that rigorously test the organization's live detection capabilities, defense evasion thresholds, and IR readiness.
  • Develop and maintain Incident Response playbooks and runbooks to standardize our technical response to cloud, application, and infrastructure breaches.
  • Conduct root-cause analysis and digital forensics post-incident to reconstruct attacker timelines, identify Indicators of Compromise (IoCs), and perform comprehensive post-incident reviews.
What You'll Bring (Qualifications)
  • Experience: 6+ years of professional experience in offensive security (penetration testing, red teaming), dedicated technical incident response, or a closely related field.
  • Incident Response (IR) Mastery: Demonstrated experience executing the full IR lifecycle (e.g., NIST SP 800-61 or SANS frameworks) and managing critical security breaches under high-pressure conditions.
  • DFIR & Log Analysis: Strong capability in parsing complex log data, analyzing system telemetry, and leveraging forensics techniques to track adversarial movement across a network.
  • Cloud Security: Advanced hands-on experience exploiting and securing modern cloud infrastructure , containerized environments ( Docker/Kubernetes ), and complex IAM policies.
  • Application Hacking: Deep technical expertise in web application and API security, including a masterful understanding of the OWASP Top 10 and complex business logic flaws.
  • Automation & Scripting: Decent programming proficiency in Python , Go , or Bash for developing custom exploitation tools, automating proofs-of-concept, and parsing security logs.
  • Breaker Mindset: A proven track record of finding critical vulnerabilities (via bug bounties, VDPs, or professional engagements) paired with the analytical, defensive mindset required to hunt threats and isolate incidents.
Life at SPAN

Headquartered in San Francisco's vibrant SoMa neighborhood, we are an eclectic group of creative thinkers who value open communication, teamwork, and a 'make it happen' approach to addressing complex challenges.


SPAN embraces diversity and equal opportunity in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills.


We're hiring talented individuals who are driven by success and are passionate about shaping the future of renewable energy. If that sounds like you, we'd love for you to consider joining the rapidly growing team at SPAN.

The Perks:

Competitive compensation + equity grants at a well-funded, venture-backed company

Comprehensive benefits: 100% employee premiums for base plans on medical, dental, vision with options for additional coverage. Parental leave up to twenty four (24) weeks depending on eligibility

Comfortable, sunny office space located near BART and Caltrain public transit

Strong focus on team building and company culture: Employee Resource Groups, monthly social events, SPANcakes recognition breakfast, lunch, and learns

Flexible hours, one holiday per month, and flexible time off

Interested in joining our team? Apply today and we'll be in touch with the next steps!
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. Offensive Security Engineer in San Francisco, CA vacancy
  • $160k - $230k

     ...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers...  ...Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs, builds...  ...in Northern California, USA. SENIOR OFFENSIVE SECURITY ENGINEER As a Senior... 
    Senior
    Permanent employment
    Flexible hours

    Astranis

    San Francisco, CA
    8 days ago
  • $181k

     ...Senior Offensive Security Engineer San Francisco, CA, USA About the Role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services, applications, and infrastructure to discover security... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Chime

    San Francisco, CA
    26 days ago
  • $180k - $250k

     ...Senior Offensive Security Engineer San Francisco, CA HP IQ is HP's new AI innovation lab. Combining startup agility with HP's global scale, we're building intelligent technologies that redefine how the world works, creates, and collaborates. We're assembling a... 
    Senior
    Full time
    Temporary work
    Local area
    Flexible hours

    HP IQ

    San Francisco, CA
    4 days ago
  • A leading AI research firm in San Francisco seeks a Principal-level Offensive Security Engineer to enhance its security posture. This role involves hunting for vulnerabilities, conducting red team operations, and collaborating with defensive teams to secure AI-powered products... 
    Suggested

    OpenAI

    San Francisco, CA
    1 day ago
  • $135k - $236.25k

     ...official communication will only be sent from @Rippling.com addresses. About The Role Rippling is looking for a hands‑on Security Engineer - Offensive Security to join our growing security team. In this role, you’ll design and execute offensive security initiatives that... 
    Suggested
    Work at office
    3 days per week

    Rippling

    San Francisco, CA
    5 days ago
  • $293k

     ...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits...  ...the Role We're seeking an exceptional Principal-level Offensive Security Engineer to challenge and strengthen OpenAI's security posture.... 

    OpenAI

    San Francisco, CA
    1 day ago
  • A leading technology firm in San Francisco is seeking a hands-on Security Engineer specializing in Offensive Security. This role involves designing and executing Red Team operations to assess readiness against advanced threats. Candidates should have over 2 years of experience... 
    Work at office
    3 days per week

    Rippling

    San Francisco, CA
    5 days ago
  • $135.48k - $204.93k

     ...Sr. Security Engineer I - Enterprise SecurityRemote - AustinWho we areSamsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop... 
    Senior
    Remote work
    Relocation package
    Flexible hours

    Samsara

    San Francisco, CA
    4 days ago
  • $183k - $247.6k

     ...by revolutionizing home WiFi, we now create comprehensive and secure solutions that serve both wireless and wired connectivity needs...  ...Key job responsibilities We are seeking a Senior Security Engineer to be embedded within the eero organization, providing security... 
    Senior
    Local area
    Worldwide
    Flexible hours

    Amazon

    San Francisco, CA
    4 days ago
  •  ...Sr. N/w Security Engineer (CrowdStrike Expert) Duration: 6+ Months Location: SFO, CA (Hybrid) Exp. Level: 10+ Years We are seeking a highly experienced Senior Network Security Engineer with deep expertise in CrowdStrike Falcon to lead and enhance our endpoint and... 
    Senior

    myIT.com

    San Francisco, CA
    1 day ago
  • $182k - $202k

     ...ingenuity of the world's largest community of security researchers to continuously discover,...  ...point in the security industry. Offensive security is no longer optional - it is the...  ...and accountability. Senior Security Engineer, Detection and ResponseRemote Location:... 
    Senior
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    1 day ago
  • Early Warning is seeking a Senior Red Team Engineer in San Francisco. The role focuses on identifying threats and creating...  .... Candidates should have 6+ years in information security and at least 2 years in offensive security, plus proficiency in scripting languages like... 
    Senior

    Early Warning

    San Francisco, CA
    3 days ago
  • $180k - $240k

     ...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers...  ...and Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs,...  ...assessments, with commensurate ability in offensive security. ~ Expert proficiency in software... 
    Senior
    Permanent employment
    Flexible hours

    Astranis

    San Francisco, CA
    2 days ago
  • $162k - $260k

     ...follow us on LinkedIn. Aurora's Product Security team's mission is to discover, mitigate...  ...contributing and documenting security engineering processes and the resulting product...  ...vulnerability management, pentesting, offensive security or cryptographic protocols and... 
    Senior
    Work experience placement
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    San Francisco, CA
    1 day ago
  • $194.25k - $214.25k

     ...Sr. DevOps Security Engineer (ALT-SM) Cloud Infrastructure Security Engineering: Design & maintain secure, highly available AWS environments using services such as EKS, IAM, KMS, GuardDuty and VPC for network isolation. Location: San Francisco, CA (telecommuting... 
    Senior
    Remote work

    Stryker

    San Francisco, CA
    13 days ago
  • $180k - $200k

     ...Senior Information Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and...  ...with both a strong defensive foundation and familiarity with offensive techniques ~ Genuine curiosity about how systems work and... 
    Senior
    Work at office
    Remote work
    Flexible hours

    Qualia

    San Francisco, CA
    5 days ago
  • $172.5k - $260.1k

     ...you are not duplicating efforts. Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI...  ...Slack, we are committed to making people's working lives more secure. We are serious about protecting our infrastructure, operations... 
    Senior
    Permanent employment

    Salesforce.Com Inc

    San Francisco, CA
    5 days ago
  • Salesforce is seeking an experienced AI Security professional to lead offensive security initiatives across their AI systems. The ideal candidate will have over 6 years in offensive security, with specific experience in AI/ML systems and a strong proficiency in Python.... 
    Senior

    Salesforce

    San Francisco, CA
    2 days ago
  •  ...Our client, a technology solutions provider company located in San Francisco, CA, needs a hybrid or remote Sr. Cloud Security Engineer for a full-time position. This is a critical, highly visible role responsible for defining, implementing, and enforcing security best... 
    Senior
    Full time
    Remote work

    ClearBridge Technology Group

    San Francisco, CA
    3 days ago
  •  ...We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the...  ...and mitigations. Those who are eager to apply their offensive security skills to proactively identify and address vulnerabilities... 
    Senior
    Contract work
    Remote work
    Flexible hours

    ZetaChain

    San Francisco, CA
    2 days ago
  • $160k - $240k

     ...with the help of AI agents, companies can secure the resources they need to innovate...  ...data. As our first Application Security Engineer , you will take on a dynamic and high impact...  ..., and FedRAMP Hands-on experience in offensive security (eg, through bug bounty... 
    Senior
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    4 days ago
  •  ...reliable backup Designing a flexible and distributed electrical grid The Role We are looking for a hands-on individual with a security engineering mindset to join us as a Senior Embedded Security Engineer as part of the Security team at SPAN. In this role, you will... 
    Senior
    Work at office
    Remote work
    Flexible hours

    SPAN Inc

    San Francisco, CA
    3 days ago
  • $196k - $245k

     ...for people to talk and hang out before, during, and after playing games. We are looking for an experienced Senior Enterprise Security Engineer reporting to the Engineering Manager of Enterprise Security. In this role, you will implement and maintain Discord’s... 
    Senior
    Full time
    Work at office
    Relocation
    Relocation package
    2 days per week
    1 day per week

    Discord

    San Francisco, CA
    2 days ago
  • $180k - $258k

    A healthcare technology company in San Francisco is hiring a Senior Security Engineer to enhance system safety and security. This role focuses on building security protections, ensuring compliance with HIPAA, SOC2, and conducting vulnerability assessments. Ideal candidates... 
    Senior

    Candid Health

    San Francisco, CA
    9 days ago
  •  ...London offices. You’ll own application security at a company where the app layer is the...  ...make the safe path the easy path for 50+ engineers Threat models for new features and architecture...  ...bounty program (HackerOne, Bugcrowd) Offensive security skills - you've done... 
    Remote work
    Shift work

    Mercor

    San Francisco, CA
    4 days ago
  • B Capital in San Francisco is seeking a hands-on Senior Security Engineer to lead and scale security efforts in a rapidly growing team. You will collaborate across functions to safeguard customer data and maintain secure infrastructure. The ideal candidate has over 5 years... 
    Senior

    B Capital

    San Francisco, CA
    4 days ago
  • Jaide Health is seeking a Senior Security Engineer to serve as a trusted advisor, leading security operations and integrating security into the software development lifecycle. The ideal candidate will have over 5 years of experience with a focus on security tool onboarding... 
    Senior
    Remote job
    Full time
    Flexible hours

    Jaide Health

    San Francisco, CA
    3 days ago
  •  ...Senior Network Security Engineer 2 positions San Francisco, CA Hybrid $70-80 W2 (don't offer the max rate by yourself, ask the candidate and negotiate. If you come across a rockstar candidate at higher pay still lock them and share with me) Required Skills... 
    Senior

    Netpace

    San Francisco, CA
    1 day ago
  •  ...Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with any of...  ...Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT... 
    Senior

    Bridge Technologies and Solutions

    San Francisco, CA
    3 days ago
  • $251k - $325k

     ...hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come...  ...event. About the Team The Security team at Tools for Humanity operates at...  ...Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx,... 
    Senior
    Casual work
    Worldwide
    Flexible hours

    Tools for Humanity

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Offensive Security Engineer. Be the first to apply!