Staff Offensive Security Engineer
Cloaked
- Location
- United States
- Employment
- Full Time
- Work model
- Remote
- Level
- Staff
- Posted
- 1h ago
Skills
About this role
Cloaked is a consumer privacy and identity platform on a mission to give people back control of their personal data. We let anyone generate unlimited identities - masked emails, phone numbers, and payment cards - scrub their information off data-broker sites, and shield themselves from spam, scams, and breaches, all from one app. Backed by a $375M Series B, we've protected 10M+ identities and removed 1B+ records from the data brokers who profit off personal information. Now we're building the AI-native future of privacy: autonomous agents that monitor, manage, and defend your digital footprint for you. // THE MANDATE Most security roles are compliance disguised as engineering. This is not. We are looking for a Staff Offensive Security Engineer to operate as a persistent, advanced threat against our own infrastructure. We do not want automated reports. We want custom exploit development, logical subversion, and a strategic mindset. If you measure your success by the sheer volume of vulnerabilities you find, look elsewhere. If you measure it by your ability to map business risk, execute highly targeted campaigns, and elevate the engineers around you, keep reading. // THE SCOPE You are not a vulnerability scanner; you are a strategic adversary. Your directive is to compromise our most critical assets before actual adversaries do. Absolute Autonomy: There is no daily task list. You are handed the Rules of Engagement. From there, it is on you to design, dictate, and execute campaigns that provide uncompromising coverage of our attack surface, backed by thorough, rigorous test cases. Beyond the Tooling: Off-the-shelf scanners will not find what you are looking for here. We need you for the complex logical flaws and chained vectors that require human intuition. Furthermore, you aren't just using tools - you are building them. You will engineer complex, future-forward offensive systems that redefine how we test our own defenses at scale. Ruthless Prioritization: You have an infinite attack surface and finite time. You must be able to cut through the noise and prioritize your targets based on catastrophic business risk rather than easy, low-impact wins. Business Subversion: You do not operate in a vacuum. You will partner directly with product and engineering leaders to deeply understand the core business logic of our platforms - and then weaponize that logic against them. Force Multiplier: Breaking in is only half the mandate. When the operation concludes, you teach. You will deconstruct your attack paths and help engineering eradicate entire attack classifications at the root. By driving foundational system hardening and secure development standards, you ensure whole categories of vulnerabilities never see production again. Ubiquitous Ownership: Despite the advanced mandate, our ultimate bottom line is protecting our customers, which means finding flaws early across every single part of the business. You will cross business units to provide hands-on security guidance, rigorous architecture review, and audit support. One day you might be red-teaming a physical system, and the next you are tearing apart our flagship product. We demand apex-level hacking, but we have zero tolerance for a "that's not my job" mentality. // THE PROFILE We don't screen for certifications or a linear cybersecurity career path. We screen for multi-disciplinary scars, coding fluency, and a deep understanding of modern architecture. You are a Builder First: You write code. You don't just find vulnerabilities after the fact; you anticipate them. You know exactly where the architectural fractures will be before a system is even built or deployed. Non-Linear Background: You have seen the tech stack from every angle. We value a diverse background - whether you've spent time in customer support, QA/test, development, blue team, red team, or all of the above. You know how users break things accidentally, which fuels how you break them intentionally. Cloud & SaaS