Staff Security Engineer, Offensive Security Job at CoreWeave in Roseland
CoreWeave, Roseland, NJ, US
Job Description
CoreWeave is the AI Hyperscaler™, delivering a cloud platform of cutting edge services powering the next wave of AI. The company's technology provides enterprises and leading AI labs with the most performant, efficient and resilient solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers covering every region of the US and across Europe. CoreWeave was ranked as one of the TIME100 most influential companies of 2024.
As the leader in the industry, we thrive in an environment where adaptability and resilience are key. Our culture offers career-defining opportunities for those who excel amid change and challenge. If you're someone who thrives in a dynamic environment, enjoys solving complex problems, and is eager to make a significant impact, CoreWeave is the place for you. Join us, and be part of a team solving some of the most exciting challenges in the industry.
CoreWeave powers the creation and delivery of the intelligence that drives innovation. To learn more about our values, please visit our careers website.
CoreWeave's Cyber Security team is seeking an experienced and talented offensive security engineer to join our team. As part of the Cyber Security Organization at CoreWeave, security engineers work to measure and improve the security of internal and external infrastructure and application offerings that provide high-power compute to customers. CoreWeave Security engineers integrate within engineering to act as a security liaison between product, engineering, and security. They provide assurance to business & network partners that CoreWeave's capabilities and technologies have been adequately hardened.
Responsibilities:- Perform penetration testing as well as purple- and red-team exercises
- Conduct threat modeling, code reviews, and design reviews for development teams within the business
- Research/stay abreast of new hacking techniques and find ways to counter them
- Find effective solutions to cybersecurity problems
- Develop best practices and improve security standards for the organization to adhere to while maintaining our internal compliance stance and security posture
- Ability to provide solutions to complex issues; handle multiple tasks in a fast-paced environment; set priorities; meet deadlines per project scope
- Demonstrated ability to present complex, technical information to both technical and non-technical audiences
- Strong time management, good technical writing, presentation, and documentation skills
- Ability to work with minimal supervision, attention to detail, and follow-through
- Other work-related duties as assigned
- Proficiency in using at least one programming or scripting language (e.g. GoLang, Python, C/++) to solve automatable tasks and perform code reviews
- At least five years of experience in the offensive cybersecurity industry
- Penetration Testing experience
- Strong technical background and experience writing and using offensive security tooling
- Experience using Kubernetes and Kubernetes-related security measures
- Extensive experience with Linux OS environments
- Ability to navigate ambiguity and determine solutions to underlying problems
- Excellent interpersonal, verbal, and written communication skills with strong attention to detail
- Ability to work with minimal supervision while handling multiple tasks in a fast-paced environment
- A strong desire to learn new technologies and skills
- Certifications like Sec+, Net+, OSCP, or other relevant industry certifications.
- An understanding of best practices and how to implement them at a business-wide level
- 5+ years' experience in the cybersecurity industry or related role
- Experience with EDR tuning, detections-as-code, and threat hunting as a Blue Team member
The Security Engineer works standard business hours. CoreWeave is a fast growth startup, and the selected candidate must be willing to be flexible when they are needed. There will be times when the Security Engineer needs to be available outside of regular business hours to support critical issues or meetings.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $240,000-$275,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
Hybrid Workplace
Successful candidates will be expected to attend onboarding training at our NJ Headquarters within their first several weeks of employment, with subsequent quarterly travel requirements of 1 week duration.
If you reside within a 30-mile radius of our New Jersey, New York, or Philadelphia offices, we're excited for you to join us at the office at least three times a week, recognizing the significance we place on fostering connections, collaboration, and creativity within our office culture. Our commitment to operating as a hybrid workplace underscores our dedication to enabling our employees to tailor their work-life balance to their individual preferences.
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs, including:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
Our Workplace
At CoreWeave, we are committed to operating as a hybrid workplace, offering employees flexibility in how they structure their time between in-office and remote work. We recognize the significance of fostering connections, collaboration, and creativity within our office culture and its positive impact on our business. Our philosophy operating as a hybrid workplace underscores our dedication to enabling employees to tailor work-life balance to their individual preferences.
For those who do not live within 30 miles of one of our offices, we are open to considering remote work for candidates whose skills and experience strongly align with the role. While we prioritize a hybrid work environment for most roles, we understand the importance of flexibility and are open to remote work for specific positions and specialized skill sets. Onboarding is essential to your success. New employees not based out of an office will be invited to attend onboarding training at one of our hubs within their first month of employment. We continue to foster a collaborative environment by bringing teams together quarterly.
California Consumer Privacy Act - California applicants only
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com.