Security Engineer – Red Team & Offensive Security

1 Month ago • 3-6 Years • Cyber Security

Job Summary

Job Description

The Security Engineer - Red Team & Offensive Security role at Sitecore involves leading and managing penetration testing, vulnerability management, bug bounty coordination, and code security initiatives. The engineer will work closely with product engineering teams, security stakeholders, and external partners to identify, assess, and drive the remediation of vulnerabilities. The role requires expertise in threat actors, modern attack vectors, and best practices for secure application and infrastructure design. Responsibilities include managing penetration testing, vulnerability management using Wiz, code security via Wiz Code, bug bounty program coordination, attack surface management, threat intelligence, and cross-team collaboration. This position requires strong communication skills and the ability to present technical concepts to non-technical audiences.
Must have:
  • 3-6 years of experience in application security or red team operations.
  • Hands-on experience with security tools and scripting for automation.
  • Familiarity with OWASP Top 10 and cloud-native security.
  • Strong understanding of vulnerability management lifecycle.
Good to have:
  • Experience managing or participating in bug bounty programs.
  • Security certifications such as OSCP, GWAPT, GPEN, or CEH.

Job Details

Security Engineer – Red Team & Offensive Security

About The Role:

Sitecore is seeking a proactive and technically skilled Security Engineer with a focus on Red Team and offensive security operations. This role will support security testing and hardening efforts across Sitecore’s cloud-native and SaaS products by leading and managing penetration testing, vulnerability management, bug bounty coordination, and code security initiatives.

The engineer will work closely with product engineering teams, security stakeholders, and external partners to identify, assess, and drive the remediation of vulnerabilities. The ideal candidate should be deeply familiar with threat actors, modern attack vectors, and best practices for secure application and infrastructure design.

Key Responsibilities:

Penetration Testing & Red Team Operations

  • Own and manage the penetration testing calendar across products and infrastructure.
  • Coordinate with external partners for scheduled and ad-hoc security testing.
  • Analyze and triage findings, produce detailed test reports, and follow up on remediation efforts.

Vulnerability Management (Wiz)

  • Perform regular scanning and analysis using Wiz for cloud and infrastructure vulnerabilities.
  • Prioritize findings based on risk, exploitability, and business impact.
  • Track and report on remediation progress across teams and ensure compliance with internal SLAs.

Code Security (Wiz Code)

  • Work with development teams to integrate secure coding practices and manage static analysis via Wiz Code.
  • Review and triage security findings in application code, guiding engineering teams on remediations.

Bug Bounty Program (HackerOne)

  • Coordinate Sitecore’s Bug Bounty Program with HackerOne, reviewing reports, validating findings, and managing triage workflows.
  • Collaborate with researchers and internal stakeholders to assess and resolve reported vulnerabilities.

Attack Surface Management

  • Continuously monitor Sitecore’s external and internal attack surface.
  • Proactively identify exposed assets, misconfigurations, or gaps that may lead to exploitation.

Threat Intelligence & Security Research

  • Stay current with evolving threat landscapes, vulnerabilities (CVEs), and TTPs (Tactics, Techniques, and Procedures).
  • Share intelligence and recommendations with internal teams to strengthen defenses and design.

Cross-Team Collaboration & Reporting

  • Work closely with Engineering, Cloud, and Product Security teams to share findings, improve visibility, and reduce exposure.
  • Maintain detailed documentation, dashboards, and status reports on open vulnerabilities, tracking remediation timelines and SLAs.

 What You Need to Succeed:

  • 3–6 years of experience in application security, penetration testing, or red team operations.
  • Hands-on experience with tools like Wiz, Wiz Code, Burp Suite, Nmap, Metasploit, and scripting for automation.
  • Familiarity with OWASP Top 10, cloud-native security (Azure, AWS), and container security best practices.
  • Strong understanding of vulnerability management lifecycle, secure SDLC, and offensive security techniques.
  • Experience managing or participating in bug bounty programs is a strong plus.
  • Security certifications such as OSCP, GWAPT, GPEN, or CEH are a plus.
  • Excellent written and verbal communication skills with the ability to present technical concepts to non-technical audiences.

Work Conditions

  • Based in KL, with working hours aligned to U.S. Central or Eastern time zones.
  • Occasional after-hours availability may be required for coordinating tests or responding to time-sensitive findings.
  • Requires close collaboration with globally distributed engineering and security teams.
Why you should click ‘Apply’:  
  • Great team and company culture! You can find out more about our company culture and our commitment to creating a diverse and inclusive workplace, on our YouTube Channel.
  • Thanks to the work of every employee globally, Sitecore has been recognized for award-winning Culture by Comparably.   

Similar Jobs

Socure - Head of Product Management, AML

Socure

United States (Remote)
1 Month ago
Tide - Senior Product Marketing Manager

Tide

United Kingdom (Hybrid)
1 Month ago
NCR Voyix - Software Engineer II - Frontend

NCR Voyix

Cebu City, Central Visayas, Philippines (On-Site)
2 Weeks ago
Axon - Manager, Go-to-Market Readiness

Axon

San Francisco, California, United States (On-Site)
1 Month ago
HYCU - Product Manager

HYCU

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
zeta - Application Security Engineer II

zeta

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Optiv - Client Director - Cybersecurity Sales

Optiv

Columbia, Maryland, United States (On-Site)
2 Weeks ago
Rocket - Security Analyst

Rocket

Pune, Maharashtra, India (On-Site)
2 Weeks ago
Roblox - Principal Security Engineer, Detection and Response

Roblox

San Mateo, California, United States (Hybrid)
1 Week ago
NVIDIA - Intellectual Property Security Engineer

NVIDIA

Bengaluru, Karnataka, India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Rippling - Account Executive - Enterprise (UK/Ireland)

Rippling

Dublin, County Dublin, Ireland (Hybrid)
3 Weeks ago
Interface AI - Senior Product Marketing Manager

Interface AI

(Remote)
1 Month ago
zeta - Manager Data Analytics EDW

zeta

Bengaluru, Karnataka, India (On-Site)
2 Months ago
clevertap - Sales Development Representative (Outbound)

clevertap

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Qualcomm - Senior Analyst, SaaS

Qualcomm

Santa Clara, California, United States (On-Site)
2 Weeks ago
SaaS Labs - Product Marketing Manager

SaaS Labs

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Adobe - Principal Product Operations Program Manager

Adobe

San Jose, California, United States (On-Site)
1 Month ago
Capgemini - Application Consultant

Capgemini

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Thousand Eyes - Customer Success Manager

Thousand Eyes

São Paulo, Brazil (On-Site)
2 Weeks ago
Autodesk - Sales Manager, ANZ

Autodesk

North Sydney, New South Wales, Australia (On-Site)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Jobs in Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia

e2 open - Associate Accountant (Fresher)

e2 open

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
4 Weeks ago
NCR Voyix - SAS - Sr Supervisor

NCR Voyix

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
1 Month ago
luxsoft - Application Maintenance/Production Support

luxsoft

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
1 Week ago
NinjaVan - Assistant, Middle Mile (Freight Coordinator, Longhaul)

NinjaVan

Shah Alam, Selangor, Malaysia (On-Site)
3 Weeks ago
e2 open - Contract Intake Analyst

e2 open

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
1 Month ago
Axi - Retail Services Associate

Axi

Malaysia (On-Site)
1 Week ago
Razer - Merchant Risk and Underwriting Specialist

Razer

Shah Alam, Selangor, Malaysia (On-Site)
2 Weeks ago
NinjaVan - Internship (Operation Excellence)

NinjaVan

Shah Alam, Selangor, Malaysia (On-Site)
8 Months ago
Valeo - Spare Parts Warehouse Technician

Valeo

Penang, Malaysia (On-Site)
1 Month ago
Razer - Software Engineer

Razer

Shah Alam, Selangor, Malaysia (On-Site)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

bytedance - Senior Software Engineer, Anti-DDoS - Network Security

bytedance

San Jose, California, United States (On-Site)
2 Months ago
FICO - Security Engineer - Lead Engineer

FICO

Bengaluru, Karnataka, India (On-Site)
1 Year ago
GoDaddy - Principal Security Engineer

GoDaddy

India (Remote)
3 Weeks ago
Google - Software Engineer III, Security/Privacy, Google Cloud Compute Infrastructure

Google

Kirkland, Washington, United States (On-Site)
2 Months ago
Highspot - Security Engineer

Highspot

Hyderabad, Telangana, India (Hybrid)
1 Month ago
ARHS - Cloud Engineer / Security and Compliance Specialist

ARHS

Brussels, Brussels, Belgium (Remote)
7 Months ago
Boomi  - WebOps Engineer, CI/CD & Security Standards

Boomi

Vancouver, British Columbia, Canada (Hybrid)
1 Month ago
Perplexity - Cloud Security Engineer

Perplexity

California, United States (On-Site)
1 Month ago
Illumina - Senior IT Security Risk and Compliance Analyst

Illumina

Bengaluru, Karnataka, India (Hybrid)
1 Week ago
BigID - Principal Software Engineer - AI Security

BigID

Tel Aviv-Yafo, Tel Aviv District, Israel (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

United States (On-Site)

Boston, Massachusetts, United States (On-Site)

London, England, United Kingdom (On-Site)

Minneapolis, Minnesota, United States (On-Site)

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)

Sydney, New South Wales, Australia (On-Site)

London, England, United Kingdom (On-Site)

Sydney, New South Wales, Australia (On-Site)

Netherlands (On-Site)

View All Jobs

Get notified when new jobs are added by Site Core

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug