Senior Offensive Security Engineer - Internal Audit
McMaster-Carr · Chicago, IL (Elmhurst) · United States · On-site
Pay: USD 170,000 – 250,000 a year
Posted Sep 10, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Who We Are
McMaster-Carr is a leading e-commerce company that industrial customers have trusted for 125 years. Our products help them get manufacturing lines back up quickly, keep operations running smoothly, and prototype the next generation of innovative solutions. We earn and keep that trust by offering the right products, making them easy to find, and delivering them fast, so customers can solve problems with greater speed, precision, and ease.
Our industry-leading e-commerce experience, indispensable product selection, and world-class service bring hundreds of thousands of customers to mcmaster.com each day. But we're never standing still. Curious, exceptional people are at the heart of our evolution. They turn new challenges and disruptive technologies into opportunities to refine our operations, expand our offering, and deliver a better experience for every customer.
What you will do
McMaster-Carr is seeking a Senior Offensive Security Engineer to build and operate an independent security assurance capability within Internal Audit. Using penetration testing, adversary emulation, and purple-team techniques, you will evaluate whether our cybersecurity controls work as intended against realistic scenarios.
This is not a conventional penetration-testing role focused only on finding vulnerabilities. As a member of McMaster-Carr’s Internal Audit team, your work will help determine whether controls prevent attacks, whether monitoring produces meaningful alerts, whether response processes work, and where security investments should be strengthened. You will translate technical findings into practical risk insight and solutions for Information Security, business leaders, executive management, and the Audit Committee.
Work is independent yet collaborative with strong governance. You will partner closely with Information Security while remaining organizationally independent from the teams responsible for designing and operating the controls you assess.
Design and execute risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments.
Test whether preventive, detective, and responsive security controls perform as expected under realistic attack Evaluate attack paths, control weaknesses, detection coverage, alert quality, and the effectiveness of incident-response procedures.
Collaborate with Security Operations and other technical teams during purple-team exercises to validate detection and response
Develop test plans, objectives, techniques, targets, safeguards, and rules of engagement for management approval before execution.
Translate technical findings into risk-based remediation recommendations that help leaders of technical teams, Internal Audit leadership, executive management and the Audit Committee prioritize security improvements and
Build a repeatable, continuously improving…