Omnissa ยท 7 hours ago
Sr. Offensive Security Engineer
Omnissa is the first AI-driven digital work platform, built to support flexible, secure, work-from anywhere experiences. They are seeking a Senior Offensive Security Engineer to run assumed-breach exercises, improve detections and playbooks, and partner with SOC and Detection Engineering to drive findings to closure.
Consumer ApplicationsCyber SecurityInformation TechnologyOnline PortalsSoftware
Responsibilities
Run assumed-breach and adversary emulation end to end
Build the emulation plan: pick scenarios based on top risk, incident learnings, and meaningful platform changes
Validate high-impact attack paths across identity, endpoint, cloud/SaaS, and applications; capture evidence, replay steps, impact, and practical remediation
Partner with SOC and Detection Engineering to define required telemetry and publish an ATT&CK-mapped gaps list with pass/fail criteria
Conduct targeted technical deep dives when needed (debugging, static/dynamic analysis, tradecraft) to confirm root cause without production impact
Build and maintain a runnable library others can use safely: scenarios, runners, runbooks/guardrails, expected telemetry; raise quality through reproducibility and peer review
Set scope/ROE, quality bar, and acceptance criteria for compliance-driven tests run by internal partners and external vendors
Review deliverables for accuracy and reproducibility; require retest evidence and drive closure to an audit-ready standard
Qualification
Required
Experience leading assumed-breach and/or adversary emulation in enterprise environments: tight ROE, strong evidence, and retest-to-closure discipline
Demonstrated, peer-recognized depth in one domain (identity, endpoint, cloud/SaaS, or appsec) plus credible working depth in at least one other
Strong fundamentals in OS internals and debugging (process/memory, authentication flows) and networking (protocols, DNS/TLS, segmentation)
Ability to analyze artifacts/tradecraft and clearly explain root cause and impact
Strong scripting for automation and safe PoCs: Python plus PowerShell and/or Bash
Track record translating offensive work into defensive outcomes (telemetry, detections, response actions/playbooks) and verifying fixes via retest
Clear writing: evidence, replay steps, ATT&CK mapping, detection gaps, and closure criteria
Cross-team ownership: you can drive remediation with engineering teams, handle pushback, and keep the bar high
Operational discipline: tight ROE, OPSEC, safety controls, and clean rollback, no surprises in production
Preferred
Built a reusable emulation library others can run safely (scenarios, runners, guardrails)
Integrated emulation checks into CI/CD, scheduled runs, or IaC workflows (e.g., Terraform)
Deeper background in debugging/RE or security tooling interactions (endpoint tradecraft, protocol/app internals)
Certifications (OSCP/OSWE/GPEN/CRTO) helpful, not required
Benefits
Employee ownership
Health insurance
401k with matching contributions
Disability insurance
Paid-time off
Growth opportunities
Company
Omnissa
Omnissa is a digital work platform. It is a sub-organization of Broadcom.
Funding
Current Stage
Late StageTotal Funding
unknown2024-02-26Acquired
Recent News
Company data provided by crunchbase