JobRaahGet matched free

Jobs

Senior Offensive Security Engineer

DRW · New York City · United States · On-site

Pay: USD 175,000 – 275,000 a year

Posted Oct 6, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk. Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets. We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus. About the Role DRW is building out its offensive security capability, and we’re looking for a Senior Offensive Security Engineer to lead the charge. In this role, you’ll plan and execute red team engagements, penetration tests, and adversary simulations against our trading infrastructure, corporate environment, and cloud platforms, acting as a trusted adversary who helps us find and fix weaknesses before anyone else does. You’ll work closely with our security, infrastructure, and trading teams to translate what you find into real improvements, and you’ll help shape the methodology, tooling, and roadmap for offensive security at DRW as the function matures. This is a hands-on, high-trust role for someone who thinks like an attacker, communicates like a partner, and cares about making the firm measurably harder to compromise. What You'll Do Plan and execute red team engagements and adversary simulations against trading systems, corporate IT, and cloud environments, modeling realistic attacker tactics, techniques, and procedures (TTPs) mapped to frameworks such as MITRE ATT&CK Conduct penetration tests across networks, web and internal applications, APIs, and cloud infrastructure, and report findings with clear, actionable remediation guidance Design and build custom tooling, scripts, and exploits to emulate adversary behavior, test control effectiveness, and validate detection coverage Partner with the Security Engineering and SOC teams in purple-team exercises to close gaps between what attackers can do and what defenders can see Run social engineering and phishing simulations to assess and improve organizational security awareness Identify, validate, prioritize, and track vulnerabilities and control weaknesses through to remediation in collaboration with infrastructure, platform, and application owners Present engagement results and risk narratives to both technical teams and senior leadership in a way that drives action Stay current on the threat landscape, emerging TTPs, and offensive…