Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Menlosecurity logo

Senior Security Engineer - Pentester

Menlosecurity
Posted 3 hours ago
🌍Latin America, North America🏠Remote📁Engineering & Development
Is this job info correct?

Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. The world has fundamentally changed. We are growing from 400 employees into the next phase of our journey, and we need passionate talent filled with empathy and agility. The right candidate for the job is ethical, hyper-organized, fanatical about seeing things through to completion, service-oriented, and humble enough to take feedback and coaching yet confident enough to provide feedback and coaching. Menlo is well-funded for growth and our investors are second to none. They include Vista Equity Partners (“ Vista ”), General Catalyst, JPMC, American Express, HSBC, and Ericsson Ventures. Summary We're looking for a forward-thinking Security Engineer to join our security team, focused on offensive and defensive testing, penetration testing of product features, and the cloud architecture behind the product. You'll operate across a complex multi-cloud environment (AWS & GCP) spanning traditional VMs and modern managed and unmanaged container-based architectures, partnering with fellow Penetration Testing and Cloud Security engineers to run targeted assessments during the testing window immediately before each release. The role reaches beyond the application layer into the Control Plane, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and extends to the frontline of external defense by triaging bug bounty submissions and outside vulnerability reports. AI and large language models are core to how this team works day to day — you'll use them to accelerate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, while applying human judgment to validate findings and communicate risk clearly to product teams. Speed matters here: the team's operating cadence is built around identifying, validating, and reporting vulnerabilities quickly enough to keep pace with release velocity. Outcomes & KPIs Key Outcome(s) Owned: Ensure new product features and the underlying multi-cloud (AWS/GCP) infrastructure are rigorously security-tested before release, and that vulnerabilities surfaced internally or via bug bounty are triaged and communicated with speed and precision. Success Metrics / KPIs : Percentage of roadmap features assessed within the pre-release testing window. Mean time to triage and validate bug bounty / external vulnerability reports. Reduction in critical/high-severity vulnerabilities escaping to production post-release. Time saved per assessment cycle through AI-assisted tooling and automation. Quality and actionability of vulnerability reports and PoCs, as rated by product teams. What You'll Do Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester. Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines. Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI). Assess the security posture of hybrid infrastructure spanning containers and virtual machines. Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation. Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts. Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication. Functional Competencies Required: Multi-Cloud Fluency: Deep architectural understanding of GCP and AWS. Capable of pivoting seamlessly between providers, performing manual configuration reviews of complex IAM/Resource hierarchies, and leveraging native APIs or modern CSPM frameworks to validate security controls. Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc). AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage. Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets). Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling. Strong understanding of browser security mechanisms (CSP, CORS, SameSite cookies, Subresource Integrity), secure authentication/authorization patterns (OAuth 2.0, OIDC, JWT), and security header configurations (HSTS, X-Frame-Options, Permissions-Policy). Proven ability to identify complex security flaws beyond automated scanner detection, validate findings through proof-of-concept development, and provide actionable remediation guidance to engineering teams. Security Automation: Proficiency in Python, Go, or Bash to eliminate "toil" — writing custom scripts and tooling to automate vulnerability discovery, validate security controls, and streamline testing workflows. Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns; able to interpret and audit complex HCL files to identify misconfigurations before they are provisioned. Communication: Ability to write high-quality technical reports that Product Teams can easily understand and act upon. Preferred / Nice to Have: Experience with Gatekeeper policies and Binary Authorization. Our Compensation and Benefits At Menlo Security, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is 158,000 CAD - 237,000 CAD. In accordance with Canadian law, the range provided is Menlo Security’s reasonable estimate of the base compensation for this role. The actual amount may be higher or lower, based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance. Menlo Security does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Menlo Security. Menlo Security is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law. MSGL-I4 Follow us on LinkedIn ! Why Menlo? Our culture is collaborative, inclusive, and fun! We have five core values: Stay Aligned, Get It Done, Customer Empathy, Think Creatively and Help Each Other Out. We believe in open communication, supporting new ideas, and sharing a mutual mindset of what we’re aiming to achieve together. There are tremendous opportunities to take initiative, implement new ideas, and have a hand in building a legacy. All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability . TO ALL AGENCIES: Please, no phone calls or emails to any employee of Menlo Security outside of the Talent organization. Menlo Security’s policy is to only accept resumes from agencies via Ashby (ATS). Agencies must have a valid services agreement executed and must have been assigned by the Talent team to a specific requisition. Any resume submitted outside of this process will be deemed the sole property of Menlo Security. In the event a candidate submitted outside of this policy is hired, no fee or payment will be paid.

Similar jobs

Similar jobs

The Institute for War and Peace Reporting logo

Web Optimization Consultant

The Institute for War and Peace Reporting

🌍Latin America2 hours ago
Condor Agency logo

Web Developer

Condor Agency

🌍Latin America3 hours ago
Kruger NearShore LLC - Rekluti logo

TÉCNICO DE CORE BANCARIO LEGACY

Kruger NearShore LLC - Rekluti

🌍Latin America3 hours ago
Truelogic logo

Senior Full-stack Engineer - Payroll Software

Truelogic

🌍Latin America3 hours ago
Excel logo

Full Stack Engineer

Excel

🌍Canada, Latin America, United States3 hours ago
Bitso logo

Senior Mobile Software Engineer (React Native)

Bitso

🌍Latin America3 hours ago