Staff Engineer, Offensive Security

Twilio

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$155,520–$194,400 / yr
Posted
66 days ago
Freshness
Confirmed live yesterday
Closes
Jan 3, 2027

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $184k
This role $175k
$120k most similar roles pay here $236k

This role pays more than 52% of similar roles. Most pay $151,500–$215,784 — the shaded band above. At the midpoint, this role pays about $175k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About Twilio

Twilio is a cloud communications platform that provides APIs and software, allowing developers to embed voice, messaging, video, and email functionalities directly into their applications.

Twilio currently has 36 open roles on FindRole.

Listed pay typically runs $155,520–$194,400 across 33 roles with salary data.

Most-posted roles

View all roles at Twilio

At a glance

TL;DR · Staff Engineer, Offensive Security

Staff Engineer - Offensive Security As a Technical Lead within the security organization, you will design complex attack chains to demonstrate systemic risks rather than simply identifying bugs. You will perform full-stack penetration testing on web applications, APIs, and mobile apps, while conducting network and cloud audits across AWS, Azure, and K8s environments. Your daily work involves validating bug bounty reports, performing AI/LLM probing for prompt injections, and developing custom exploits to bypass EDR systems. You will build automated testing frameworks using PyRIT, Promptfoo, or Garak to detect sensitive data leakage in AI models. To succeed, you must be proficient in Python, C++, Bash, Burp Suite, Metasploit, and various C2 frameworks like Cobalt Strike. You will also lead Red Team operations, provide remediation guidance for vulnerabilities like XSS and SQLi, and manage the corporate bug bounty program.

What does a Engineer earn in Remote?

Median $189520 from 49 postings across 15 companies.

See salary data

What you'll do

  • Perform manual and automated penetration testing on web applications, APIs, and mobile apps.
  • Conduct network and cloud infrastructure audits focusing on IAM misconfigurations and container escapes.
  • Triage and validate vulnerability reports from automated scanners and bug bounty programs.
  • Execute prompt injection and jailbreak tests on AI models and services using OWASP standards.
  • Develop custom payloads, droppers, and scripts to bypass EDR/AV systems for stealthy operations.
  • Design and lead multi-week Red Team operations to emulate specific threat actors.
  • Provide technical guidance to engineering teams to remediate vulnerabilities like XSS, SQLi, and IDOR.
  • Build automated testing frameworks to identify sensitive data leakage in AI systems.

What we're looking for

  • Experience of 7-10 years in offensive security, penetration testing, AppSec, or vulnerability exploitation.
  • Expert knowledge of MITRE ATT&CK, OWASP Top 10 for web applications, and OWASP Top 10 for LLMs.
  • Proficiency with tools including Burp Suite, Nmap, Metasploit, Wireshark, and C2 frameworks like Cobalt Strike or Sliver.
  • Ability to write functional scripts in Python or Bash to automate testing and create custom offensive exploits.
  • Experience with AI security tools such as LangChain, TensorFlow for adversarial testing, or other LLM evaluation frameworks.
  • Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN, or similar OffSec training is highly desirable.
  • Expertise in cloud infrastructure attacks (AWS/Azure/K8s) and identifying IAM misconfigurations or container escapes.
  • Telecom expertise is preferred.

More like this

Similar roles

Staff Security Engineer

Twilio

Remote 17 days ago $155,520$194,400
AI Threat Hunting SIEM SOAR Terraform CloudFormation AWS GCP Infrastructure as Code Incident Response Service-Oriented Architecture MITRE ATLAS Automation Security Engineering
Remote

Senior Security Engineer, Offensive Security

Datadog

91 days ago $195,000$240,000
Red Teaming Offensive Security Python Go AWS GCP Azure Kubernetes CI/CD Automation EDR SIEM Linux macOS Vulnerability Analysis Security Engineering
5+ yrs exp Hybrid

Senior Offensive Security Engineer, Vulnerability Operations

Nvidia

Remote (Austin, TX) +1 9 days ago $224,000$356,500
LLM Python Red Teaming Penetration Testing Kubernetes Exploit Development Vulnerability Research SAST DAST Fuzzing GitOps OpenShift prompt-injection defense Multi-agent Orchestration Offensive Security
10+ yrs exp Remote

Staff Security Engineer

Okta Inc

San Francisco, CA 43 days ago $134,000$184,800
DevSecOps AWS Snyk Semgrep Qualys Cyera CI/CD Security Posture Management SRE SDLC Secrets Management Infrastructure Security Automation Salesforce Google Workspace
10+ yrs exp

Staff Security Engineer

Okta Inc

San Francisco, CA 43 days ago $134,000$184,800
DevSecOps AWS Snyk Semgrep Qualys Cyera CI/CD Security Posture Management Secrets Management SDLC SRE Salesforce Google Workspace Slack Zoom Infrastructure Security
10+ yrs exp