Meta's Offensive Security Group is looking for an Offensive Security Engineer that can execute tactical, offensive assessments across our environments. Our objective is to preempt the adversary in attacking Meta, and make the company, its employees, and its users safer and more secure.
Should have knowledge across the attack lifecycle and should have experience in execution of security assessments against various technologies and stacks. Candidates are expected to support delivering technology-oriented assessments that positively benefit the overall security posture of the organization. This role requires a desire to help drive fixes after testing cycles, both as short term mitigations and long term improvements.Bachelor's degree (or foreign degree equivalent) in Information Systems Engineering, Computer Science, Engineering, Information Security, Cyber Security, Information Assurance, or related field, and 5+ years of work experience in Red Teaming and Offensive Security in a large, regulated organization. Be a technical and process subject matter expert regarding Red Teaming and Offensive Security services, and attacker tactics, techniques, and procedures. Experience leading and managing complex cross-functional programs and teams. Analyze C, C++, C# or Java code implementations for vulnerabilities and design flaws. Modern Web Browser, Web Application, User mode, Kernel mode, debugging, reverse engineering and exploitation techniques. Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux. Coding and scripting experience in one or more general purpose languages. Contributions to the security community (public research, blogging, presentations, bug bounty, tooling, etc.) Track record of participation in capture the flag (CTF) competitions. OSCP certification, or equivalent.