xelys jobs xelys jobs

Senior Security Engineer

Bitwarden

full-remoteseniorpermanentsecurity Santa Barbara, CA 94 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Penetration TestingPurple TeamVulnerability ManagementThreat ModelingThreat HuntingBurp SuiteNmapNessusMetasploitOWASP ZAP

About the role

Role: Senior Security Engineer (Purple Team)

As a Senior Security Engineer at Bitwarden, you will run and support purple team testing against Bitwarden’s products and services. You’ll perform offensive security activities (e.g., penetration testing and threat hunts) and collaborate with defensive teams to improve security controls.

Responsibilities

  • Conduct purple team testing including:
    • Threat research and analysis
    • Penetration testing and security validation
    • Code audits and cryptography reviews
  • Perform security findings response, including triage and assistance with external inquiry and report response
  • Build threat models and plan/execute threat hunts and purple team engagements
  • Coordinate internal red team operations that emulate threat actors
  • Work with application development, platform engineering, and SOC teams to strengthen offensive/defensive controls
  • Contribute to vulnerability testing/analysis and incident response
  • Test security across a multi-product portfolio, including:
    • Web, mobile, CLI, and desktop applications
    • Bitwarden Password Manager, Secrets Manager, and Passwordless.dev
    • APIs, serverless functions, and database systems
  • Participate in security-related code reviews and help remediate identified issues
  • Produce and validate purple team findings, including technical leadership review of reports
  • Communicate findings, attack paths, and recommendations to stakeholders
  • Train others on adversary simulation tactics and procedures
  • Stay current with security trends, publications, and advisories

Requirements / What You Bring

  • Strong background in penetration testing and manual security testing
  • Experience with security/vulnerability management tools such as:
    • Burp Suite, NMAP, Nessus, Metasploit, Kali Linux, SQLMap, OWASP ZAP
  • In-depth knowledge of vulnerability management tools and strategies
  • Understanding of authentication concepts and flows, including OpenID Connect, SAML, OAuth, SSO
  • Strong, self-driven technical capability spanning offensive and defensive security

Nice-to-haves

  • In-depth understanding and usage of application security testing technologies

Location / Work Setup

  • All-remote team; role requires you to be located in the U.S.
  • No visa sponsorship at this time.

About Bitwarden

Bitwarden is a security-focused company offering transparent, open-source password management, secrets management, and passwordless/passkey capabilities. It serves enterprises, developers, and individuals with tools designed to help securely store and share sensitive data and extend strong security practices across online activity.

Scraped 4/28/2026