Senior Offensive Security Engineer

Ecolab


Job Location:

Naperville, IL - USA

Monthly Salary: $ 101400 - 152100
Posted on: 7 hours ago
Vacancies: 1 Vacancy

Job Summary

The Senior Offensive Security Engineer Commercial Products will perform hands-on offensive security testing across Ecolabs commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products including web and mobile applications APIs cloud services IoT solutions PLC/IPC-connected equipment embedded or field-deployed devices and related product integrations. The Senior Offensive Security Engineer Commercial Products will actively perform security testing for most of their time while supporting offensive security engagements mentoring engineers as needed and helping improve engagement scope testing methods reporting quality remediation validation and risk-based prioritization. This role will partner closely with product security engineering architecture cloud IoT legal/compliance and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolabs commercial offerings.

What you will do:

  • Perform hands-on offensive security testing across Ecolab commercial products including web applications mobile applications APIs cloud services IoT platforms PLC/IPC-connected equipment embedded devices and product integrations.

  • Plan scope and execute technical security assessments focused on identifying exploitable vulnerabilities attack paths insecure configurations weak access controls exposed secrets insecure APIs cloud misconfigurations and product-specific security gaps.

  • Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing analysis documentation and remediation validation activities.

  • Contribute to repeatable red team and offensive testing methods engagement rules reporting standards evidence expectations and risk-rating approaches appropriate for commercial digital products.

  • Partner with product security application engineering cloud engineering IoT engineering architecture and business teams to translate testing results into clear remediation actions and risk-based priorities.

  • Conduct safe and authorized technical testing of IoT and industrially connected equipment including physical access testing of product hardware field devices PLC/IPC interfaces device communications and related technology components where appropriate.

  • Use commercial and enterprise-approved security tools such as Snyk Wiz Burp Suite OWASP ZAP GitHub Advanced Security Nmap Horizon3 NodeZero DAST tooling and related technologies to identify validate and document security issues.

  • Validate vulnerabilities discovered through internal testing automated scanning third-party penetration testing customer inquiries bug reports and product security reviews.

  • Prepare clear actionable reports that explain vulnerability impact exploitability business context affected assets remediation guidance compensating controls and validation results.

  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization communicating risk business impact and practical remediation paths.

  • Support product threat modeling secure architecture reviews application security reviews cloud security assessments and security design discussions based on offensive testing insights.

  • Support improvements to Ecolabs vulnerability management secure SDLC DevSecOps and product security governance practices by identifying recurring weakness patterns and practical control improvements.

  • Support coordination with third-party penetration testing providers when appropriate including scope development test readiness evidence review finding validation and remediation tracking.

  • Maintain awareness of emerging offensive security techniques AI-enabled attack methods application security risks cloud security trends IoT attack vectors and relevant industry standards.

  • Act as an advocate and champion for practical risk-based product security across Ecolabs commercial digital product teams.

Minimum Qualifications:

  • Bachelors Degree in Cybersecurity Computer Science Information Technology Engineering or related technology-driven field.

  • 5 years of hands-on experience in cybersecurity application security offensive security penetration testing product security cloud security IoT security software engineering or related technical field.

  • Demonstrated hands-on experience performing authorized technical security testing of web applications mobile applications APIs cloud services and/or IoT-connected products.

  • Experience supporting offensive security engagements vulnerability assessments penetration tests remediation validation and technical security reporting.

  • Experience supporting technical workstreams mentoring engineers or coordinating testing activities while remaining directly involved in hands-on testing and analysis.

  • Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts services and common misconfiguration risks.

  • Experience with application security testing tools and practices including SAST SCA DAST API testing cloud security posture assessment vulnerability validation and secure code review concepts.

  • Familiarity with tools such as Snyk Wiz Burp Suite OWASP ZAP GitHub Advanced Security Nmap Horizon3 NodeZero DAST tooling and related offensive or product security testing technologies.

  • Knowledge of secure software development DevSecOps CI/CD pipelines identity and access management encryption secrets management secure API design and secure cloud architecture principles.

  • Understanding of IoT embedded industrial or field-deployed technology security considerations including device communications network segmentation authentication update mechanisms and physical access risks.

  • Familiarity with industry frameworks and standards such as OWASP CIS NIST ISO 27001 SOC 2 and secure SDLC practices.

  • Strong interpersonal analytical problem-solving organizational and written/verbal communication skills.

  • Ability to communicate technical findings clearly to software engineers architects cybersecurity leaders product owners and non-technical business stakeholders.

  • Ability to accommodate a flexible work schedule for supporting global activities.

Preferred Qualifications:

  • One practical offensive security certification such as OSCP GPEN GWAPT GWEB PNPT or similar hands-on application web cloud or penetration testing certification.

  • Experience testing commercial software products SaaS platforms customer-facing applications cloud-hosted services mobile applications APIs IoT platforms or connected equipment.

  • Experience with hardware embedded systems PLC/IPC-connected devices industrial communications device provisioning secure firmware/update processes or field-deployed technology.

  • Experience with Azure security services cloud-native application security container security Kubernetes security and identity-based cloud controls.

  • Experience integrating offensive security findings into vulnerability management secure architecture threat modeling product risk governance and engineering remediation workflows.

  • Experience contributing to testing playbooks reporting templates engagement standards risk-rating models and remediation validation procedures.

  • Experience with AI-enabled products AI integrations or the security implications of AI/ML capabilities in commercial software environments.

  • Ability to influence without authority and drive security improvements across globally distributed engineering product and technology teams.

Annual or Hourly Compensation Range

The pay range for this position is $101400.00 - $152100.00. Many factors are taken into consideration when determining compensation such as experience education training geography etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families.Click here to see our benefits.

If you are viewing this posting on a site other than our Ecolab Career website view our benefits at Customer Requirements Notice

To meet customer requirements and comply with local or state regulations applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.


Americans with Disabilities Act (ADA)

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process please visit the Recruiting Support link in the footer of each page of our career website.


Required Experience:

Senior IC

The Senior Offensive Security Engineer Commercial Products will perform hands-on offensive security testing across Ecolabs commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products including web and mobile applications APIs cloud services ...

About Company

Company Logo

Ecolab is the global leader in water, hygiene and energy technologies and services. Every day, we help make the world cleaner, safer and healthier – protecting people and vital resources.

View Profile View Profile