ApplySarthi

Offensive Security Engineer

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

41 open offensive roles across 21 companies are on ApplySarthi right now, most of them in Bengaluru (1).

What offensive roles keep asking for: Python (63%), Penetration testing (61%), Go (32%), IAM (32%), Kubernetes (32%), AWS (27%), Azure (22%), GCP (22%) — counted across their open postings here.

Remote Offensive Security Engineer jobs · Go jobs · IAM jobs · Kubernetes jobs · Penetration testing jobs

Jobgether has 4,372 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for offensive roles keep coming back to Python, Penetration testing, Go, IAM. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with Penetration testing? Tell me one thing you learned the hard way.
  3. Tell me about an outage you handled. What did you learn from it?
  4. How do you decide what to monitor, and what should wake someone up at night?
  5. How would you cut the cloud bill of a system without hurting it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Offensive Security Engineer at Jobgether interview free →

Accountabilities:: Validate and extend Secure SDLC threat models through continuous penetration testing, assessing threat severity, mitigation status, and underlying security assumptions. Automate routine security validations to keep pace with a rapidly evolving platform while reserving manual analysis for complex and high-impact scenarios. Plan and execute full-scope red team engagements across cloud compute, storage, inference, networking, orchestration layers, and internal tooling. Identify attack paths capable of impacting organizational operations, customer environments, or critical platform assets. Collaborate with detection and response and other security engineering teams on purple team exercises, validating detection coverage and closing defensive gaps. Research novel attacks against GPU infrastructure, including firmware, vendor drivers, device passthrough, SR-IOV/IOMMU configurations, and RDMA/InfiniBand environments. Investigate vulnerabilities within inference technologies and AI platform services, including model-serving infrastructure and managed orchestration platforms. Assess tenant-isolation boundaries and explore potential low-level attack paths that could compromise isolation. Conduct targeted offensive security assessments of new products and significant infrastructure changes before they reach production. Develop custom offensive tooling and post-exploitation capabilities to improve the effectiveness and scalability of security testing. Produce clear, actionable reports for both technical teams and senior leadership, prioritizing findings and providing practical remediation guidance. Establish and continuously improve red team processes, tooling, methodologies, and operating practices as the platform scales. Requirements: 6+ years of experience in offensive security, penetration testing, red teaming, adversary simulation, or a closely related discipline. Deep hands-on experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escape techniques. Strong understanding of the broader attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration. Proven ability to develop custom security tooling and post-exploitation capabilities using Python, Go, or similar programming languages. Experience conducting purple team exercises and collaborating constructively with blue teams and defensive security functions. Ability to communicate complex technical findings through clear, senior-level reports that contextualize business risk and provide actionable guidance to engineers. Experience with ML infrastructure, model-serving pipelines, or GPU clusters is a strong advantage. Reverse engineering and exploit development experience is a plus. Application security experience is advantageous. Familiarity with eBPF bypass techniques, kernel-level exploitation, vulnerability research, or CVE discovery is beneficial. Understanding of cloud provider internals, including hypervisor and networking layers, is a plus. Experience presenting security research at industry conferences such as Black Hat or DEF CON is advantageous. Strong problem-solving skills, curiosity, technical depth, and the ability to work independently in a rapidly evolving environment. Benefits: Competitive compensation with equity upside. Flexible, remote-first working environment. Opportunities for career growth, continuous learning, and professional development. Significant ownership and flexibility in how security challenges are approached. Opportunity to work on novel attack surfaces spanning GPU infrastructure, AI platforms, and large-scale multi-tenant cloud environments. Collaboration with highly experienced engineers working on advanced AI infrastructure. Opportunity to contribute directly to impactful AI and cloud security initiatives. International environment with talented teams across multiple regions. Inclusive and collaborative culture focused on innovation, trust, meaningful impact, and continuous growth.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-06. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.