Jobs in Naperville, IL

333verified openings
Filter by
No filters selected
(USA) Ecolab Inc. Verified 19m ago

Senior Offensive Security Engineer

USA - Illinois - Naperville On-site

$101,400–$152,100 a year
Pay$101,400–$152,100
TypeFull-time
Work settingOn-site
Verified listing

JobFig found this opening at its original source and checks that it remains available.

About the role

The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Senior Offensive Security Engineer, Commercial Products will actively perform security testing for most of their time while supporting offensive security engagements, mentoring engineers as needed, and helping improve engagement scope, testing methods, reporting quality, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab’s commercial offerings.

What you'll bring

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
  • 5+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
  • Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
  • Experience supporting offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
  • Experience supporting technical workstreams, mentoring engineers, or coordinating testing activities while remaining directly involved in hands-on testing and analysis.
  • Experience with Microsoft Azure
  • familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
  • Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.
  • Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.
  • Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.
  • Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.
  • Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.