xelys jobs xelys jobs

Senior Security Engineer

Bitwarden

full-remoteseniorpermanentsecurity United States 94 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Purple TeamPenetration TestingVulnerability ManagementApplication SecurityThreat ModelingOWASP ZAPBurp SuiteNmapKali LinuxSQLMap

About the role

Role overview

Bitwarden is hiring a Senior Security Engineer for an all-remote U.S. team. You will lead purple team testing and support security findings response through threat research, penetration testing, code audits, security validation, and cryptography reviews across Bitwarden products and services.

Responsibilities

  • Threat research & modeling: Research emerging threats across the surface web, dark web, and deep web; build threat models and conduct threat hunts.
  • Purple/pentest execution: Plan and execute purple team engagements; coordinate internal red team testing operations that emulate threat actors.
  • Security collaboration: Work with application teams, platform engineers, and the Security Operations Center (SOC) to improve offensive and defensive security controls.
  • Vulnerability testing & incident support: Contribute to vulnerability testing/analysis and incident response and analysis.
  • Multi-surface application security: Test web, mobile, CLI, and desktop application security across multiple products (Bitwarden Password Manager, Secrets Manager, Passwordless.dev), including APIs, serverless functions, and databases.
  • Secure engineering process: Participate in code reviews and help improve security posture through knowledge sharing.
  • Reporting & validation: Provide technical validation and leadership review of purple team reports, including findings, attack paths, and recommendations.
  • Remediation support: Assist with remediation of identified security issues from internal and external testing.
  • Tooling & automation: Manage tools for code scanning, vulnerability identification, and findings reporting.
  • Training & guidance: Train others on adversary simulation tactics and procedures; provide security subject matter expertise across security testing, cloud analysis, investigations, and vendor security analysis.

Requirements

  • Experience with penetration testing tools and manual testing, including: Burp Suite, Nmap, Nessus, Metasploit, Kali Linux, SQLMap, OWASP ZAP, and manual testing tools.
  • Strong experience with vulnerability management tools and strategies.
  • Solid application security testing knowledge.
  • Understanding of authentication concepts including OpenID Connect, SAML, OAuth, and SSO flows.

Nice to have

  • In-depth understanding and usage of application security testing technologies (explicitly called a plus).

About Bitwarden

Bitwarden empowers enterprises, developers, and individuals to securely store and share sensitive data through a transparent, open-source approach. It focuses on password management and extends into secrets management as well as passwordless and passkey innovations, supported by a global community of security experts. The company is headquartered in Santa Barbara, California.

Scraped 4/28/2026