Security Engineer, Level 5, Offensive Security
Santa Monica, CA - USA
Job Summary
The Company operates Snapchat a visual messaging app that enhances your relationships with friends family and the world and Specs Inc. a wholly-owned subsidiary dedicated to making computing more human in addition to Bitmoji Saturn and other digital services.
Snap Security teams protect the trust and safety of our global community by securing the systems and data that power Snapchat. We safeguard hundreds of millions of Snapchatters every day ensuring that every product and service is built on a foundation of security and resilience. Our values guide everything we do - from how we anticipate and mitigate threats to how we collaborate across Snap. We move fast with precision and always execute with privacy at the forefront.
Were looking for a Security Engineer to join our Offensive Security Team!
What youll do:
- Design execute and lead offensive security and privacy engagements including red purple and orange team exercises across corporate environments cloud projects/accounts internal applications and mobile client applications.
- Maintain a comprehensive understanding of real-world threat actors their tools tactics and procedures with a propensity to target Snap collaborating extensively with the threat intelligence team to enumerate exhaustive killchains that seed and prioritize the future engagement roadmap.
- Deliver detailed post-engagement reports that identify vulnerabilities highlight strengths and weaknesses in our security posture assess detection coverage and provide actionable recommendations including prioritized risk mitigation strategies and improvements to defensive measures.
- Implement and manage offensive security engagement infrastructure and tooling to conduct covert operations and mimic the tactics of relevant adversaries including the development of custom implants payloads and exploits to thoroughly test and evaluate our defenses.
- Collaborate closely with other security and privacy teams to share insights from engagements informing strategic roadmaps by identifying priority areas for improvement and aligning on initiatives.
- Serve as a subject matter expert and consultant to other security and privacy teams participating in security reviews reproducing vulnerabilities and contributing to high-stakes incident response efforts.
- Explore novel research topics relevant to our tech stack to proactively improve our security posture and integrate lessons learned into future exercises.
Knowledge Skills & Abilities:
- Proven experience in leading offensive security engagements coordinating multiple security engineers and managing and executing assessments to thoroughly test and evaluate security measures.
- Expert knowledge in four or more of the following: operating system internals networking application development mobile client development Kubernetes cloud infrastructure (AWS/GCP) and payload/implant/exploit development.
- Coding proficiency in one or more modern languages including Java Python Go etc.
- Adept at threat modeling and establishing killchains
- Proficiency in scripting languages like Bash and PowerShell to automate security tasks and improve efficiency of engagements.
- Possess an insatiable drive for learning and the ability to thrive in new unique and complex technical environments with the capability to build a foundational understanding and effectively apply it within the context of engagements.
Minimum Qualifications:
- Bachelor of Science in Computer Science Engineering Information Systems or equivalent years of experience in a related technical field
- You may also provide evidence of personal security research (CVEs or blogs) public bug bounty reports previous CTF participation and/or code repositories on GitHub showcasing personally developed security tools
- 6 years of post-Bachelors security related experience; or Masters degree in a technical field 5 year of post-grad security related experience; or PhD in a relevant technical field 2 years of post-grad security related experience
Preferred Qualifications:
- Familiar with frameworks like ATT&CK to represent tools tactics and procedures.
- Experience in leading or participating in incident response efforts with a deep understanding of digital forensics detection engineering and threat hunting.
- Proven ability to work effectively with cross-functional teams at all-levels including developers IT and executive leadership to align security measures with organizational goals.
Default Together Policy at Snap: At Snap Inc. we believe that being together in person helps us build our culture faster reinforce our values and serve our community customers and partners better through dynamic collaboration. To reflect this we practice a default together approach and expect our team members to work in an office 4 days per week.
At Snap we believe that having a team of diverse backgrounds and voices working together will enable us to create innovative products that improve the way people live and communicate. Snap is proud to be an equal opportunity employer and committed to providing employment opportunities regardless of race religious creed color national origin ancestry physical disability mental disability medical condition genetic information marital status sex gender gender identity gender expression pregnancy childbirth and breastfeeding age sexual orientation military or veteran status or any other protected classification in accordance with applicable federal state and local laws. EOE including disability/vets.
We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example the requirements of the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring where applicable).
Compensation
In the United States work locations are assigned a pay zone which determines the salary range for the position. The successful candidates starting pay will be determined based on job-related skills experience qualifications work location and market conditions. The starting pay may be negotiable within the salary range for the position. These pay zones may be modified in the future.
The base salary range for this position is $209000-$313000 annually.If you believe this job description is missing required pay transparency information please submit a report through this form: Job Description Pay Range Disclosure.
Required Experience:
IC
About Company
We believe the camera presents the greatest opportunity to improve the way people live and communicate.