Offensive Security Lead

il y a 7 heures


Rue SaintDenis Paris France Escape Temps plein

We are seeking our first Offensive Security Lead to join Escape and play a key role in validating and enhancing our AI-powered Code-to-cloud ASM and DAST platform. This role is central to Escape's mission: ensuring our security scanners accurately detect real-world vulnerabilities by thinking like an attacker. You will lead offensive security initiatives, conduct penetration testing and red team operations on customer applications, and work closely with our Security Research and Scanners teams to continuously improve our detection capabilities.

As the Offensive Security Lead, you will be responsible for designing and executing sophisticated attack scenarios, validating scanner findings against real-world exploitation techniques, and translating your offensive research into actionable improvements for our platform. You will be the internal adversary who stress-tests our technology and helps our enterprise customers understand their true security posture.

Context

  • Location: Paris , 2 days remote/week

  • Company: Escape – Leading AI Cybersecurity Startup

  • Cofounders: CEO (Tristan Kalos) and CTO (Antoine Carossio)

  • Engineering Team: 16 Engineers, 4 Technical Leads, 1 Product Owner, 3 Pentesters

  • You'll be building and leading the offensive security practice, managing a team of 3 red teamers while remaining hands-on with technical work

Key Responsibilities:
  • Team Leadership & Management: Build, mentor, and manage a team of 3 red teamers, establishing offensive security best practices, methodologies, and quality standards. Foster a culture of continuous learning and technical excellence while ensuring operational efficiency.

  • Offensive Security Operations: Design and execute penetration tests, red team engagements, and adversary simulations against modern web applications, APIs, cloud infrastructure, and codebases to validate Escape's detection capabilities.

  • Research-to-Detection Pipeline: Collaborate with the Security Research team to discover novel attack techniques, validate vulnerability detection logic, and ensure our scanners catch what real attackers would exploit.

  • Customer-Facing Validation: Support enterprise customer engagements by demonstrating real-world exploitability of findings, conducting proof-of-concept attacks, and helping VP Security and Security Engineer personas understand risk severity.

  • Attack Scenario Development: Build realistic attack chains and scenarios that combine Code-to-cloud vulnerabilities, helping customers understand end-to-end exploitation paths from code to runtime.

  • Scanner Quality Assurance: Act as the final validator for scanner accuracy by attempting to exploit reported vulnerabilities, reducing false positives, and identifying false negatives through manual testing.

  • Offensive Tooling & Automation: Develop custom tools, exploits, and automated attack workflows that can be integrated into our continuous security validation processes.

  • Strategic Planning: Define the offensive security roadmap, prioritize testing initiatives, and allocate team resources to maximize impact on product quality and customer success.

  • Knowledge Transfer: Train Security Engineers and developers on offensive security techniques, helping them build security intuition and understand attacker perspectives.

Tech Stack
  • Target Environment: Modern web applications, REST/GraphQL APIs, cloud-native infrastructure (AWS/Kubernetes), CI/CD pipelines, container environments

  • Offensive Tools: Burp Suite, custom Python/Go exploits, browser automation (Playwright), Metasploit Framework, cloud pentesting toolkits (Pacu, ScoutSuite)

  • Languages: Python (primary), Go, Bash scripting, proficiency in reading/writing exploits in multiple languages

  • Infrastructure: Kubernetes (EKS), Docker, AWS services

  • Collaboration: GitLab, Slack, direct integration with our scanner codebase (Python/Go)


  • Offensive Security

    il y a 2 jours


    Paris, Île-de-France Apple Temps plein

    Apple's Security Engineering & Architecture organization is responsible for the security of all Apple products. Passionate about safeguarding our users, we believe that the best defense requires a great offense. When it comes to securing more than a billion devices running the world's most sophisticated operating systems, that means finding vulnerabilities...

  • Senior DevSecOps Engineer

    il y a 2 semaines


    France Neotrust Temps plein

    Job Description — Senior DevSecOps Engineer (Offensive Security Focus)Location: Hybrid (Paris) or Remote (France/Europe)Department: Cybersecurity / DevSecOpsSeniority: Senior / ExpertDuration: 1 year (renewable)Contract: Full-time (Freelance)About the roleWe're looking for a Senior DevSecOps Engineer with a strong Offensive Security mindset to elevate our...


  • Paris, Île-de-France Apple Temps plein

    Apple's Security Engineering & Architecture organization is responsible for the security of all Apple products. Passionate about safeguarding our users, we believe that the best defense requires a phenomenal offense. When it comes to securing more than a billion devices running the world's most sophisticated operating systems, that means finding...


  • Saint-Ouen, Île-de-France Inetum Temps plein

    Description De L'entrepriseInetum est un leader européen des services numériques. Pour les entreprises, les acteurs publics et la société dans son ensemble, les consultants et spécialistes du groupe visent chaque jour l'impact digital : des solutions qui contribuent à la performance, à l'innovation et au bien commun.Présent dans 19 pays au plus près...

  • Ingénieur Offensive Security

    il y a 2 semaines


    Saint-Ouen, Île-de-France Inetum Temps plein

    Description de l'entreprise Inetum est un leader européen des services numériques. Pour les entreprises, les acteurs publics et la société dans son ensemble, les consultants et spécialistes du groupe visent chaque jour l'impact digital : des solutions qui contribuent à la performance, à l'innovation et au bien commun. Présent dans 19 pays au plus...


  • Saint-Ouen, France Inetum Temps plein

    **Description de l'entreprise** Inetum est un leader européen des services numériques. Pour les entreprises, les acteurs publics et la société dans son ensemble, les 28 000 consultants et spécialistes du groupe visent chaque jour l'impact digital : des solutions qui contribuent à la performance, à l'innovation et au bien commun. Présent dans 26 pays...

  • Cybersecurity Researcher

    il y a 2 semaines


    Paris, France Symbiotic Security Temps plein

    Cybersecurity Researcher (Application Security) Design, validate, and improve practical protections that help developers avoid introducing vulnerabilities, including those generated by AI coding assistants. Conduct offensive research to discover new vulnerability classes, build proof‑of‑concepts, and translate findings into robust, scalable defenses that...

  • Offensive Security Manager

    il y a 2 semaines


    Paris, France Apple Temps plein

    We are looking for a manager with experience in dealing with complex systems and bringing ideas to the level of products. Our organization focuses on securing low-level technologies such as the iOS and macOS kernel boot ROMs firmware and hardware. Working alongside a wide variety of teams and vendors your influence will be felt throughout Apple’s...

  • Security Strategy Lead

    il y a 2 semaines


    Paris, France AXA Group Operations Temps plein

    Join to apply for the Security Strategy Lead role at AXA Group Operations4 days ago Be among the first 25 applicantsJoin to apply for the Security Strategy Lead role at AXA Group OperationsAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million...

  • Lead Security Engineer

    il y a 2 semaines


    Rue Chapon, Paris, France Nabla Temps plein

    About NablaWe are a team of entrepreneurs, clinicians and engineers committed to bringing back joy to the practice of medicine.Together with a community of clinician innovators, we've harnessed the best of machine learning science to develop Nabla: the leading AI assistant that's restoring the human connection at the heart of healthcare. By streamlining...