Senior Offensive Security Engineer

Remote $112k–$188k senior 4 months ago full-time quality 8.6/10

Role in brief

Bitmex, a crypto derivatives exchange, is seeking a Senior Offensive Security Engineer to manage its bug bounty program, conduct penetration tests, and perform security research. This role involves collaborating with engineering teams to fix vulnerabilities and enhance overall security. Ideal candidates have extensive offensive security experience and strong communication skills.

Security ResearchRed TeamCI/CDAWS CloudApplication SecurityThreat IntelligenceCode ReviewsProduct SecurityKubernetesGo DevelopmentIncident InvestigationPurple Team

About the role

This role focuses on strengthening Bitmex's security posture through offensive security measures. Responsibilities include overseeing the bug bounty program, reviewing researcher reports, and coordinating with software engineering to address identified vulnerabilities. The engineer will also analyze external penetration test results and conduct internal tests on the company's software and infrastructure.

A key part of the position involves conducting red and purple team exercises to evaluate monitoring systems. The engineer will also engage in security research and threat intelligence, working closely with the security response team. Application security, code reviews, and providing internal training to engineers are also within the scope of this role.

Success in this position means actively contributing to the company's security initiatives, ensuring timely resolution of security findings, and proactively identifying potential threats. The role requires a proactive approach to security, helping to maintain Bitmex's record of no lost funds and supporting its professional trading platform.

The salary for this role ranges from $112,000 to $188,000 USD.

Skills that matter here

  • Red Team: This role involves participating in and leading red team exercises to test the effectiveness of existing security monitoring and defenses.
  • Application Security: The engineer will be responsible for ensuring the security of applications through reviews and by providing training to development teams.
  • Threat Intelligence: This position requires conducting security research and utilizing threat intelligence to anticipate and mitigate potential risks.
  • Code Reviews: The role includes performing code reviews to identify and address security vulnerabilities in the software codebase.
  • Incident Investigation: The engineer will be part of incident response efforts, assisting in the triage and investigation of security issues.
  • Product Security: This role contributes to the overall security of Bitmex's products by identifying and remediating vulnerabilities.

Who this role suits

  • A candidate with at least five years of experience in information security, specifically with proven expertise in offensive security.
  • Someone who possesses strong communication skills, capable of engaging effectively with researchers and internal engineering teams.
  • An individual with a strong work ethic, who actively contributes to company goals and is recognized for their security contributions.
  • A professional who is proactive in identifying and addressing security vulnerabilities, and who can also train others.

From the employer

  • Manage our bug bounty program, reviewing reports, engaging with researchers and cooperating with software engineering to fix bugs
  • Reviewing the outcomes of external penetration tests, replicating issues and again, working with engineering to fix findings
  • Conducting internal penetration tests on our software and infrastructure stack
  • Red and purple team exercises to test our monitoring
  • Security research & threat Intelligence, working with security response
  • Application security & code reviews, internal training of engineers
  • Being part of incidents to help triage and investigate issues
  • 5+ Years in Information Security.
  • Proven expertise in offensive security either through certifications, recognition, or referees.
  • Strong communication skills and work ethic: contribute actively to the company and become ‘known’
  • Candidates with less experience will be considered for an Offensive Security Engineer position.
  • Work from home to help you find the perfect balance between work, family and personal life
  • 25 days of annual leave, on top of public holidays, as well as maternity, paternity and childcare leave… etc to accommodate your growing responsibilities
  • A top tier & comprehensive medical, dental and vision policy for you and your dependents
  • Professional development allowance to support your career advancement
  • Access to our annual wellness benefits to cultivate your physical and mental growth
  • Remote Working policy, where you get to work away from your home country
  • Team building & offsite events to bring our global team closer
  • Life insurance coverage to provide a safety net for your family’s future

Questions about this role

What is the remote work policy for this role?

This is a remote position, and the company offers a policy that allows employees to work from outside their home country.

What level of seniority is expected for this position?

This is a senior-level position, requiring at least five years of experience in information security, with a focus on offensive security.

How do I apply for this position?

The job description does not specify an application process, but typically applications are submitted through the company's career page or a linked job portal.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Bitmex.