Aquanow, a leading infrastructure and liquidity provider that provides institutional and enterprise application platforms for digital assets, is looking for a Staff Offensive Security Engineer to join our security team. This is a unique opportunity to work alongside a highly-experienced team and contribute to the development of a high-growth trading and technology company. If you want to have your name in the success story of a globalizing company, we look forward to receiving your application to the winning Aquanow team!
Responsibilities
- Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
- Serve as a subject matter expert by documenting findings, recommending remediation strategies, and supporting teams through fixes.
- Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.
- Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.
- Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.
- Write and maintain tooling to automate and scale offensive security assessments.
- Mentor teammates and contribute to shared knowledge through internal documentation, presentations, and external talks or blog posts.
Requirements
- 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
- Demonstrated experience mentoring or guiding other security engineers.
- Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.
- Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.
- Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monitoring, including common evasion techniques.
- Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation.
- Clear written and verbal communication skills, with the ability to explain technical findings to both engineers and senior leaders.
- Experience collaborating with distributed teams and documenting work through tools such as Slack, Jira, GitHub, and email.
- Ability to work independently and solve problems.
Nice to have
- Automation experience with AWS.
- Relevant certifications such as AWS Certified Security - Specialty, CEH are highly desirable.
- Experience in a global fast moving environment covering multiple time zones.
- Familiarity with common security vulnerabilities and the ability to judge their severity and impact on the business.
- Passion in all things security.
- Stay updated with the latest security trends & AI technologies.
Additional details
- The Interview Process:
- Stage 1: A 45-minute video call with the Security Manager
- Stage 2: A 60-minutes technical deep dive with the members of the Security team.
- Stage 3: A 30-minute video call with the CISO
- Stage 4: Potential follow up call