our company's attack surface spans several distinct businesses: the engine and editor developers build on, a wide portfolio of cloud products and services, a large monetization business, and a growing set of AI-assisted creation tools. Code built with our company runs everywhere from a developer's workstation to billions of end-user devices, so targets range from native binaries to distributed cloud systems to AI pipelines, and findings here matter.
This role brings an attacker's mindset to that landscape: penetration testing and red team engagements built on complex attack chains. You would combine manual techniques with automation and tooling you develop as part of your craft, extending your reach across the company ecosystem.
What you'll be doing
Plan and execute objective-based penetration tests and red team engagements across our company's products, cloud services, and infrastructure
Find and validate exploitable vulnerabilities, chain them into realistic attack paths, and demonstrate impact with reproducible proofs of concept
Develop the automation and tooling that extend the team's offensive reach across the company ecosystem
Run joint exercises with the SOC and detection engineering teams to validate telemetry and improve detections
Deliver clear findings to engineering teams and surface recurring risk patterns to security leadership.
This role brings an attacker's mindset to that landscape: penetration testing and red team engagements built on complex attack chains. You would combine manual techniques with automation and tooling you develop as part of your craft, extending your reach across the company ecosystem.
What you'll be doing
Plan and execute objective-based penetration tests and red team engagements across our company's products, cloud services, and infrastructure
Find and validate exploitable vulnerabilities, chain them into realistic attack paths, and demonstrate impact with reproducible proofs of concept
Develop the automation and tooling that extend the team's offensive reach across the company ecosystem
Run joint exercises with the SOC and detection engineering teams to validate telemetry and improve detections
Deliver clear findings to engineering teams and surface recurring risk patterns to security leadership.
Requirements:
5+ years of hands-on experience in offensive security, penetration testing, or red teaming
Proven ability to find, exploit, and chain vulnerabilities across applications
Deep understanding of how modern web applications and APIs break
Hands-on experience assessing cloud environments (AWS or GCP)
Strong ability to develop and validate offensive tooling
You might also have
Adversary emulation experience: designing engagements around real threat actor TTPs
Security research in real-time 3D, game engines or SDKs, or mobile runtimes
Experience attacking CI/CD and build systems.
5+ years of hands-on experience in offensive security, penetration testing, or red teaming
Proven ability to find, exploit, and chain vulnerabilities across applications
Deep understanding of how modern web applications and APIs break
Hands-on experience assessing cloud environments (AWS or GCP)
Strong ability to develop and validate offensive tooling
You might also have
Adversary emulation experience: designing engagements around real threat actor TTPs
Security research in real-time 3D, game engines or SDKs, or mobile runtimes
Experience attacking CI/CD and build systems.
This position is open to all candidates.










