X

Senior Penetration Tester & Security Engineer

xage security โ€ข United State
Visa Sponsorship
Apply
AI Summary

Lead offensive security efforts for Xageโ€™s zero-trust products by conducting manual penetration testing, threat modeling, and security reviews. Collaborate with engineering teams to identify vulnerabilities, remediate issues, and improve secure coding practices. Drive automation enhancements and educate developers on security best practices in a fast-growing cybersecurity startup.

Key Highlights
Hands-on offensive security role focused on zero-trust product security (authentication, APIs, protocols, and infrastructure)
Manual penetration testing, threat modeling, and security design reviews for current and future products
Collaborative environment with direct impact on secure product development and developer education
Key Responsibilities
Conduct manual penetration testing of Xageโ€™s products, including Web UIs, REST/gRPC APIs, desktop clients, backend services, and deployment infrastructure
Perform threat modeling and security reviews for new and existing product features, providing input and sign-off on security-critical designs
Identify vulnerabilities (e.g., authorization bypasses, injection flaws, protocol misconfigurations) and document findings with reproduction steps and remediation guidance
Collaborate with developers to remediate security issues and integrate fixes into the development lifecycle
Educate developers on secure coding practices and suggest improvements to libraries/tooling to prevent future vulnerabilities
As needed, extend existing automation tools or develop custom fuzzers to support vulnerability detection efforts
Participate in architectural discussions to guide security-conscious design decisions and support compliance/bug bounty efforts
Technical Skills Required
Penetration Testing Threat Modeling Web & API Security
Benefits & Perks
$170,000 โ€“ $200,000 annual salary + equity
Full health, dental, and vision insurance
Visa sponsorship for international candidates
Nice to Have
Experience with Golang, C++, JavaScript, ReactJS, or Electron
Prior offensive security hire in a startup environment
Background in OT/IT authentication and authorization products

Job Description


About Xage

Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high โ€“ and only growing more urgent by the day. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. We are pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat.


We have built tremendous momentum across governments and commercial enterprises around the world, and itโ€™s just the beginning. Recognized by Forbes as one of Americaโ€™s Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of our mission. We are headquartered in Palo Alto, CA and have global teams across North America andEMEA.


Weโ€™re passionate about solving problems that have positive, real-world consequences for the lives of everyday people. We hope youโ€™ll join us in the fight against cyberattacks and safeguarding critical infrastructure.


About the Role

This role will be focused on penetration testing, threat modeling, and security review / analysis of Xageโ€™s current and future products. Candidates should be comfortable with learning and ramping up on new features in a large code base and performing /manual/ penetration testing to uncover business logic flaws, authorization bypasses, injection issues, and improper use of protocols / cryptographic algorithms.


While the candidate should be familiar with automation tools to help with scanning / detection of vulnerabilities, our team has already integrated extensive usage of automated tools and this will be supplemental work for this role to help improve or integrate with these existing systems or to help automate parts of the manual penetration testing effort. Integration of common automation tooling is not a primary responsibility during the early stages of this role.


Candidates will be expected to help review the design of features currently in development, as well as review of previously implemented security critical features to identify issues within the existing product. Long term some additional areas the role may progress to as needed may include war gaming / emulation of adversaries or specific breach scenarios, implementation of custom automation tooling / fuzzers specific to Xageโ€™s products, other program support for bug bounties / developer education / compliance efforts / etc.


This role will require working across multiple teams and organizations so good communication and team work skills are essential, Xageโ€™s engineering culture prides itself on teamwork and collaboration to help multiply everyoneโ€™s skills and development across the entire team.


Key Responsibilities

  • Offensive penetration testing of Xageโ€™s products
  • Penetrating testing areas include Web UIs, REST/gRPC APIs, desktop clients, backend services, and deployment infrastructure
  • Testing should primarily focus on manual efforts which will require reading and understanding the code and architecture of existing Xage products and features
  • As needed, contribute to the extension of existing automation tools or development of novel custom tooling to support detection efforts
  • Threat modeling and security review of Xage products and features
  • Help the product security team to provide input and sign-off on all new features being added to the product
  • Contribute to continuous review of older features already existing in the product to help close any gaps from early stage products and software
  • Provide input and guidance on brainstorming / architectural discussions to help educate and guide the team to appropriate security conscious design decisions
  • Reporting issues, remediation, and verification of resolution
  • Provide clear findings on any vulnerabilities discovered with reproduction steps and possible fixes
  • Work alongside developers to remediate issues and push fixes through the development lifecycle
  • Educate and expand the capabilities of developers to help them understand how to avoid common security issues
  • Suggest improvements to libraries or tooling for development teams to help prevent security issues before they happen


Requirements

  • Multiple years of hands-on offensive security experience (penetration testing, red teaming, vulnerability research, etc.) against software products, not just corporate IT vulnerabilities.
  • Must be fluent and capable enough in coding to understand features within the code base and help uncover vulnerabilities within our products.
  • Strong understanding of common authentication and authorization protocols/areas such as OAuth, SAML, mTLS / PKI, SSO, MFA, FIDO2, RBAC/ABAC models.
  • Strong Web and API security expertise, knowledgeable about OWASP/Top 10 issue, authentication flows, session management, injection issues, etc.
  • Strong networking and protocol fundamentals, should be capable of reading traffic captures and understanding / reverse engineering custom protocols.
  • Strong communication skills, both verbal and written
  • Collaborative and willing to educate / mentor other team members


Preferred Qualifications

  • Experience and fluency with Golang, C++, JavaScript, ReactJS, and ElectronJS
  • Prior experience working in startup environments
  • Prior experience as an initial penetration testing / offensive security hire
  • Prior experience working on an OT / IT authentication and authorization product


Perks

  • Salary Range: $170,000 โ€“ $200,000 p/yr + Equity
  • Full health, dental, vision insurance
  • We will process visa transfers and immigration
  • Work with founders and executives closely and participate in all aspects of company building
  • Early stage opportunity in a massive sized market with proven traction and growing rapidly


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Acceler8 Talent

United State

Software Engineer I

Programming
โ€ข
2h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข
Job Type โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข
Experience Level โ€ขโ€ขโ€ขโ€ขโ€ขโ€ข

American Express

United State

Senior System Engineer

Programming
โ€ข
2h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

Acro Service Corp

United State

Subscribe our newsletter

New Things Will Always Update Regularly