Full-Time

Lead Offensive Security Engineer

IoT

Confirmed live in the last 24 hours

Praetorian

Praetorian

51-200 employees

Provides continuous cybersecurity testing services

Cybersecurity

Compensation Overview

$135k - $200kAnnually

+ Equity Incentive Plan

Senior

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Microsoft Azure
Docker
AWS
Firebase
Google Cloud Platform
Requirements
  • Demonstrated passion for cybersecurity
  • 5+ years of IoT security experience in one or more cross-functional areas: hardware or software reverse engineering, firmware analysis, embedded cryptography, wireless protocols, glitching/side-channel analysis, or IoT PaaS security
  • Additional experience in at least 3 of the following: Product Security Testing (Application, Mobile, LLM), Network Security Testing and/or Red Team, Web Application Penetration Testing, Cloud Security (AWS, Azure, GCP), Secure Code Review, Reverse Engineering, Vulnerability Research/ Exploit Development
  • Understanding of threat models, attack paths and intelligence considerations within the scoping of technical projects
  • Ability to write technical reports and present technical findings both internally and externally
  • Experience with startup and/or high-tech companies
  • Prior security consulting experience
  • Software or web application development experience in multiple languages
  • Experience with cutting edge technology stacks and modern security technologies
  • Advanced technical knowledge in any of the following: Exploit development beyond Windows and for MacOS X or Linux, Reverse engineering malware, data obfuscators, or ciphers, Software maturity models such as OpenSAMM, BSIMM, and SDL, Identity technologies for Azure AD, Auth0, Firebase, OKTA, or Google Identity, Secrets management such as Hashicorp Vault and cloud native KMSs, Containerization technologies such as Docker and registry platforms such as DockerHub, ACR, ECR, & GCR, Orchestration technologies such as Kubernetes and cluster management platforms such as AKS, EKS, & GKE, Command and control channel frameworks and deployment, Automotive security, ICS/SCADA, Network device security, Medical device security, Home automation security, and/or cryptocurrency wallet security, Hardware RE, software RE, firmware analysis, embedded cryptography, wireless protocols, Software-defined radio, glitching, side-channel analysis, and/or IoT PaaS and similar technologies
  • Capture-the-flag, CCDC, CPTC or other security related competitions
  • Ranked achievements on testing platforms such as Hack the Box, Tryhackme, Portswigger, Proving Ground and similar
  • Pursuit of advanced learning opportunities via security training courses, conferences, personal projects and similar
  • Track record in vulnerability research and CVE assignments
  • Security community experience via presentations, conference attendance, blogs, white papers and similar
  • OSCE, OSEP, OSED, CRTO, cloud certifications and similar
  • Ability to travel up to 20% to support client engagements
Responsibilities
  • Lead the technical execution of challenging offensive security projects focused on IoT Security for our customers
  • Identify nuanced vulnerabilities in advanced systems
  • Develop custom methodologies, payloads, exploits, and tools to ensure project success
  • Develop documentation for novel mitigation strategies to emerging or undocumented security risks identified in client environments
  • Develop comprehensive reports and presentations for our customers
  • Serve as a mentor to other engineers in their technical and professional development
  • Collaborate with the security community to develop novel attack techniques, tactics, and procedures (TTPs) through Praetorian’s Security Blog and other forms of community engagement

Praetorian provides ongoing security testing services to protect various infrastructures, including IoT devices, SaaS applications, mobile apps, cloud infrastructure, and critical systems. Their approach involves continuous security analysis rather than one-time evaluations, allowing clients to identify and address vulnerabilities as they arise. This subscription-based model enables clients to enhance their security without needing extensive in-house capabilities. Praetorian's services include defensive enablement, purple team exercises, red team operations, incident response, product security, and automated security analysis, ensuring that clients maintain a high level of security over time.

Company Stage

Series A

Total Funding

$9.7M

Headquarters

Austin, Texas

Founded

2010

Growth & Insights
Headcount

6 month growth

10%

1 year growth

23%

2 year growth

32%
Simplify Jobs

Simplify's Take

What believers are saying

  • Praetorian's recognition as a finalist in the Cloud Security Awards and SC Awards highlights its industry leadership and innovation.
  • The appointment of experienced leaders like David Hunt and Peter Kwan strengthens the company's strategic direction and technical expertise.
  • The release of open-source tools like Konstellation and Gato demonstrates Praetorian's commitment to community engagement and technological advancement.

What critics are saying

  • The highly competitive cybersecurity market requires Praetorian to continuously innovate to maintain its edge.
  • Dependence on subscription-based revenue could be risky if clients opt for short-term solutions or switch providers.

What makes Praetorian unique

  • Praetorian's continuous security testing model ensures ongoing protection, unlike competitors who may offer only one-time evaluations.
  • Their focus on a wide range of infrastructures, from IoT to critical infrastructure, sets them apart in the cybersecurity market.
  • The integration of AI and automation in their Chariot platform provides advanced attack surface management and adversarial emulation, distinguishing them from traditional security services.

Help us improve and share your feedback! Did you find this helpful?