Security Engineer, Level 5, Offensive Security
Job Description
Snap’s Offensive Security Team is hiring a Security Engineer (Level 5) to design and lead offensive security and privacy engagements across corporate, cloud, internal apps, and mobile clients.
Responsibilities
- Design, execute, and lead offensive security and privacy engagements, including red, purple, and orange team exercises across corporate environments, cloud projects/accounts, internal applications, and mobile client applications.
- Maintain strong awareness of real-world threat actors, including tools, tactics, and procedures; partner with the threat intelligence team to enumerate exhaustive killchains that seed and prioritize the future engagement roadmap.
- Produce detailed post-engagement reports covering discovered vulnerabilities, security posture strengths/weaknesses, detection coverage, and actionable recommendations, including prioritized risk mitigation and defensive improvements.
- Build and operate offensive engagement infrastructure and tooling to run covert operations and emulate adversary tactics, including creation of custom implants, payloads, and exploits to test defenses.
- Coordinate with other security and privacy teams to share findings, inform strategic roadmaps, and align on security improvement initiatives.
- Act as a subject matter expert and consultant for security and privacy teams by participating in security reviews, reproducing vulnerabilities, and supporting high-stakes incident response.
- Explore novel research topics tied to Snap’s tech stack and apply lessons learned to future exercises.
Requirements
- Proven experience leading offensive security engagements, coordinating multiple security engineers, and managing assessments to thoroughly test and evaluate security measures.
- Expert knowledge in four or more areas: operating system internals, networking, application development, mobile client development, Kubernetes, and cloud infrastructure (AWS/GCP), plus payload/implant/exploit development.
- Coding proficiency in one or more modern languages, including Java, Python, or Go.
- Adept at threat modeling and establishing killchains.
- Script automation skills using Bash and PowerShell to streamline security tasks and improve engagement efficiency.
- Strong learning drive and ability to succeed in new, unique, and complex technical environments, building foundational understanding and applying it during engagements.
Technologies
- Java
- Python
- Go
- Bash
- PowerShell
- Kubernetes
- AWS
- GCP
- ATT&CK
Minimum Qualifications
- Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field.
- May also include evidence of personal security research (CVEs or blogs), public bug bounty reports, prior CTF participation, and/or GitHub repositories demonstrating security tools you developed.
- 6+ years of post-Bachelor’s security-related experience; or Master’s degree in a technical field + 5+ years post-grad security-related experience; or PhD in a relevant technical field + 2+ years post-grad security-related experience.
Preferred Qualifications
- Familiarity with frameworks like ATT&CK to represent tools, tactics, and procedures.
- Experience leading or participating in incident response, including deep understanding of digital forensics, detection engineering, and threat hunting.
- Proven ability to collaborate cross-functionally at all levels (developers, IT, executive leadership) to align security measures with organizational goals.
Benefits
- Paid parental leave
- Comprehensive medical coverage
- Emotional and mental health support programs
- Compensation packages that allow you to share in Snap’s long-term success
- Equity in the form of RSUs
Location and Work Model
- Los Angeles, CA (onsite)
- Expect team members to work in the office 4+ days per week
Compensation
- Zone A (CA, WA, NYC): $209,000-$313,000 base salary annually
- Zone B: $199,000-$297,000 base salary annually
- Zone C: $178,000-$266,000 base salary annually