Jobs / Eco***
Lead Offensive Security Engineer
Eco*** · Naperville, IL, United States
Visa sponsorship details are locked. Unlock company name and apply link with .
Naperville, IL, United States120,500-180,700 USD/yearlyRemote
Remuneration
120,500-180,700 USD/yearly
Location
Naperville, IL, United States
Visa sponsorship
Sponsors visa
Job summary
The Lead Offensive Security Engineer will lead hands-on offensive security testing across Eco***’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations.
Benefits
Ecolab strives to provide comprehensive and market-competitiveTo meet the needs of our associates and their families.If you are viewing this posting on a site other than our Ecolab Career website,At jobs.ecolab.com/working-here.Potential CustomerIn addition, we are committed to furthering the principles of Equal Employment OWe will consider for employment all qualified applicants, including those with c
Qualifications
- Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
- 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
- Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
- Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
- Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.
- Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
- Experience with application security testing
- Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications.
- Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.
- Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.
- Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.
- Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.
Responsibilities
- Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
- Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
- Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
- Use commercial and enterprise-approved security
Skills
Communication
Certifications
GPENGWAPTGWEBGitHub Advanced SecurityISO 27001OSCP
Degrees
AssociateDegree
Work schedule
Overtime
Industry
AutomotiveEducationManufacturingMediaSaas
Company size
EnterpriseSmb
Security clearance
Secret