Avatar for CloudWalk
A worldwide smart open payment network
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • Valuation $1B+
    This company has a valuation of $1B or more

Offensive Security Engineer

Posted: 4 months ago
Hires remotely in
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

RelocationAllowed
Skills
Azure
TypeScript
AWS
Kubernetes
Go
web application pentesting
GCP
Service Mesh
CI/CD Pipelines
API Pentesting
Cloud Infrastructure Security
LLMs
AI Agents

About the job

About the Role

This is not a traditional pentesting role. At CloudWalk, you’ll go beyond running scans or writing reports. You’ll break into systems, exploit real weaknesses, and then engineer automations and agents to make sure those classes of vulnerabilities never come back. Your work will directly shape how CloudWalk defends itself at scale, turning offensive security knowledge into defensive engineering.

You’ll be part of a team that blends red teaming, mobile/web pentesting, and security automation. If you enjoy moving fast, exploiting hard problems, and coding the solutions, this role is for you.

What You'll Do

  • Break things that matter. Pentest applications across our stack, identifying vulnerabilities in APIs, mobile apps (Android/iOS), and infrastructure before attackers do.
  • Run red team operations. Plan and execute realistic attack campaigns: phishing with custom domains, social engineering, lateral movement, privilege escalation. Measure real organizational resilience, not checkbox compliance.
  • Build offensive tooling. Engineer security platforms, scanning pipelines, and automation that multiply the team's impact.
  • Weaponize AI for defense. Design and build LLM-powered agents that detect, classify, triage and fix vulnerabilities in real time.

What We're Looking For

  • Strong knowledge of common vulnerabilities, exploitation techniques, and secure coding practices. You can find bugs in source code, not just with a proxy.
  • Experience with web application and API pentesting. Mobile pentesting (Android/iOS) is a strong plus.
  • You code daily. Proficiency in Typescript, Go, or similar, not just scripts, but tools and services others can rely on.
  • Familiarity with cloud infrastructure security (GCP/AWS/Azure), Kubernetes, and service mesh concepts.
  • Understanding of CI/CD pipelines and how to embed security checks into them.
  • Experience leveraging LLMs or AI agents for security tasks.
  • Excellent communication and collaboration skills to work effectively with engineering teams.

Bonus Points

  • Experience with red team operations: phishing infrastructure, social engineering, C2 frameworks.
  • Familiarity with payment industry security (PCI DSS, card tokenization, acquiring flows).
  • Experience building security platforms or internal tooling (dashboards, bots, vulnerability management systems).
  • Contributions to open source security tools, published security research or CTFs.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments and credittogether.

About the company

CloudWalk company logo
A worldwide smart open payment network501-1000 Employees
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • Valuation $1B+
    This company has a valuation of $1B or more
Learn more about CloudWalk image

Funding

AMOUNT RAISED
$125K
FUNDED OVER
1 round
Round
S
$125000
Seed - May 2014

Founders

Luis Silva
Founder
San Francisco
image
View the team image