Lead offensive security efforts for Xageโs zero-trust products by conducting manual penetration testing, threat modeling, and security reviews. Collaborate with engineering teams to identify vulnerabilities, remediate issues, and improve secure coding practices. Drive automation enhancements and educate developers on security best practices in a fast-growing cybersecurity startup.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
About Xage
Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high โ and only growing more urgent by the day. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. We are pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat.
We have built tremendous momentum across governments and commercial enterprises around the world, and itโs just the beginning. Recognized by Forbes as one of Americaโs Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of our mission. We are headquartered in Palo Alto, CA and have global teams across North America andEMEA.
Weโre passionate about solving problems that have positive, real-world consequences for the lives of everyday people. We hope youโll join us in the fight against cyberattacks and safeguarding critical infrastructure.
About the Role
This role will be focused on penetration testing, threat modeling, and security review / analysis of Xageโs current and future products. Candidates should be comfortable with learning and ramping up on new features in a large code base and performing /manual/ penetration testing to uncover business logic flaws, authorization bypasses, injection issues, and improper use of protocols / cryptographic algorithms.
While the candidate should be familiar with automation tools to help with scanning / detection of vulnerabilities, our team has already integrated extensive usage of automated tools and this will be supplemental work for this role to help improve or integrate with these existing systems or to help automate parts of the manual penetration testing effort. Integration of common automation tooling is not a primary responsibility during the early stages of this role.
Candidates will be expected to help review the design of features currently in development, as well as review of previously implemented security critical features to identify issues within the existing product. Long term some additional areas the role may progress to as needed may include war gaming / emulation of adversaries or specific breach scenarios, implementation of custom automation tooling / fuzzers specific to Xageโs products, other program support for bug bounties / developer education / compliance efforts / etc.
Searching for Development & Programming roles that provide visa sponsorship? Connect with international employers through Development & Programming Jobs with Visa Sponsorship opportunities actively seeking talented professionals.
This role will require working across multiple teams and organizations so good communication and team work skills are essential, Xageโs engineering culture prides itself on teamwork and collaboration to help multiply everyoneโs skills and development across the entire team.
Key Responsibilities
- Offensive penetration testing of Xageโs products
- Penetrating testing areas include Web UIs, REST/gRPC APIs, desktop clients, backend services, and deployment infrastructure
- Testing should primarily focus on manual efforts which will require reading and understanding the code and architecture of existing Xage products and features
- As needed, contribute to the extension of existing automation tools or development of novel custom tooling to support detection efforts
- Threat modeling and security review of Xage products and features
- Help the product security team to provide input and sign-off on all new features being added to the product
- Contribute to continuous review of older features already existing in the product to help close any gaps from early stage products and software
- Provide input and guidance on brainstorming / architectural discussions to help educate and guide the team to appropriate security conscious design decisions
- Reporting issues, remediation, and verification of resolution
- Provide clear findings on any vulnerabilities discovered with reproduction steps and possible fixes
- Work alongside developers to remediate issues and push fixes through the development lifecycle
- Educate and expand the capabilities of developers to help them understand how to avoid common security issues
- Suggest improvements to libraries or tooling for development teams to help prevent security issues before they happen
Explore our comprehensive directory of visa sponsorship jobs from employers worldwide who are ready to sponsor talented international professionals.
Requirements
- Multiple years of hands-on offensive security experience (penetration testing, red teaming, vulnerability research, etc.) against software products, not just corporate IT vulnerabilities.
- Must be fluent and capable enough in coding to understand features within the code base and help uncover vulnerabilities within our products.
- Strong understanding of common authentication and authorization protocols/areas such as OAuth, SAML, mTLS / PKI, SSO, MFA, FIDO2, RBAC/ABAC models.
- Strong Web and API security expertise, knowledgeable about OWASP/Top 10 issue, authentication flows, session management, injection issues, etc.
- Strong networking and protocol fundamentals, should be capable of reading traffic captures and understanding / reverse engineering custom protocols.
- Strong communication skills, both verbal and written
- Collaborative and willing to educate / mentor other team members
Interested in opportunities specifically in United State? Discover our dedicated Visa Sponsorship Jobs in United State page featuring roles from top employers in this location.
Preferred Qualifications
- Experience and fluency with Golang, C++, JavaScript, ReactJS, and ElectronJS
- Prior experience working in startup environments
- Prior experience as an initial penetration testing / offensive security hire
- Prior experience working on an OT / IT authentication and authorization product
Perks
- Salary Range: $170,000 โ $200,000 p/yr + Equity
- Full health, dental, vision insurance
- We will process visa transfers and immigration
- Work with founders and executives closely and participate in all aspects of company building
- Early stage opportunity in a massive sized market with proven traction and growing rapidly
Similar Jobs
Explore other opportunities that match your interests