Twilio Inc. logo

Staff Engineer, Offensive Security

Job Overview

Location

Remote - Ireland

Job Type

Full-time

Category

Security Engineer

Date Posted

March 16, 2026

Full Job Description

đź“‹ Description

  • • As a Staff Engineer, Offensive Security at Twilio Inc., you will operate at the forefront of cybersecurity, acting as a crucial Technical Lead within the security team. Your role transcends traditional bug hunting; you will be instrumental in designing and executing complex attack chains that expose systemic risks across Twilio's vast technological landscape. This position demands a deep dive into both offensive and defensive security strategies, requiring you to spend significant time writing custom code, researching novel bypass techniques, and meticulously executing tests to ensure the robustness of our systems.
  • • You will be responsible for comprehensive Full-Stack Penetration Testing, meticulously examining web applications, APIs, and mobile applications (iOS/Android) for vulnerabilities. This includes both manual testing methodologies and the strategic application of automated tools to identify weaknesses.
  • • Your expertise will extend to Internal and External Network Audits, where you will conduct thorough assessments of network infrastructure and cloud environments using a diverse array of specialized tooling.
  • • A key responsibility involves Vulnerability Validation, where you will triage and validate reports from automated scanners and bug bounty hunters. This critical step ensures the accuracy of findings, filters out false positives, and prioritizes the escalation of genuine, high-impact vulnerabilities.
  • • In an era of rapidly evolving AI, you will perform initial AI/LLM Probing, conducting prompt injection and jailbreak tests on AI prototypes, services, and applications. You will leverage established checklists, such as the OWASP Top 10 for LLMs, to systematically assess the security posture of these advanced systems.
  • • You will be tasked with Technical Reporting, crafting high-quality, detailed reports that clearly articulate the "path to compromise." These reports will provide developers with clear, reproducible steps to understand and remediate identified vulnerabilities.
  • • Maintaining and enhancing the team's testing infrastructure is also part of your remit. This includes managing and updating essential tools like Burp Suite Professional and basic C2 listeners, ensuring the team has the most effective resources at its disposal.
  • • You will provide direct Remediation Support to engineering teams, offering expert technical guidance on how to effectively patch critical vulnerabilities such as Cross-Site Scripting (XSS), SQL Injection (SQLi), and Insecure Direct Object References (IDOR).
  • • A significant aspect of this role involves Adversary Emulation. You will design and lead multi-week Red Team operations, meticulously mimicking the tactics, techniques, and procedures (TTPs) of specific threat actors (APTs) to rigorously test the detection capabilities of our Security Incident Response Team (SIRT).
  • • Custom Exploit Development will be a core activity, where you will build custom payloads, droppers, and obfuscated scripts designed to bypass Endpoint Detection and Response (EDR) and Antivirus (AV) solutions, maintaining stealth during simulated attacks.
  • • You will contribute to AI Red Teaming Architecture by building automated testing frameworks for AI systems. This may involve utilizing tools like PyRIT, Promptfoo, or Garak to systematically test AI models for vulnerabilities related to sensitive data leakage and other AI-specific security concerns.
  • • Your responsibilities will include executing sophisticated Cloud & Infrastructure Attacks against platforms like AWS, Azure, and Kubernetes, with a specific focus on identifying and exploiting IAM misconfigurations and container escape vulnerabilities.
  • • You will actively participate in Purple Teaming exercises, collaborating closely with SIRT and Detection Engineering teams to fine-tune SIEM alerts based on the techniques observed and employed during offensive engagements.
  • • Finally, you will provide strategic oversight for the organization's bug bounty program. This involves analyzing submission trends to identify recurring security weaknesses and proactively suggesting broad architectural security changes to prevent future incidents.

Skills & Technologies

Python
AWS
Azure
Kubernetes
iOS
Senior
Remote

Ready to Apply?

You will be redirected to an external site to apply.

Twilio Inc. logo
Twilio Inc.
Visit Website

About Twilio Inc.

Twilio Inc. provides cloud-based communications platforms that enable developers to integrate voice, messaging, video, email, and authentication into applications via APIs. Founded in 2008, the company offers programmable services for SMS, voice calls, WhatsApp, email, and IoT connectivity, serving enterprises, startups, and communication service providers globally. Twilio operates a pay-as-you-go model, allowing customers to scale usage without managing underlying telecom infrastructure. The company is headquartered in San Francisco, California, and trades on the New York Stock Exchange under the symbol TWLO.

Get more remote jobs like this

Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.

Newsletter

Weekly remote jobs and featured talent.

No spam. Only curated remote roles and product updates. You can unsubscribe anytime.

Similar Opportunities

London Office
Full-time
Expires May 12, 2026
Onsite

1 month ago

Apply
❌ EXPIRED
Sydney
Full-time
Expired Apr 14, 2026
Senior
Onsite

2 months ago

Apply
⏰ EXPIRES SOON
Remote - Bulgaria
Full-time
Expires Apr 25, 2026 (Soon)

2 months ago

Apply
Toronto
Full-time
Expires May 14, 2026
Remote

1 month ago

Apply