Cloaked logo

Staff Offensive Security Engineer

Cloaked

New York, NYHybridJobNo compensation foundPosted 1mo agoChecked 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
New York, NYHybrid
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Master's degree

Job overview

Cloaked is hiring a Staff Offensive Security Engineer. Cloaked seeks a Staff Offensive Security Engineer to act as a persistent, advanced threat against its own infrastructure, designing and executing custom exploit campaigns, building offensive tools, and partnering with product and engineering leaders to prioritize business risk and harden systems.

Key focus areas include Design and execute custom exploit campaigns against critical assets, Build offensive tools and systems for large‑scale testing, and Prioritize targets based on catastrophic business risk.

Important skills include Offensive Security, Vulnerability Assessments, Strategic Thinking, Risk Analysis, Communication Skills, and Hardening.

Skills & qualifications

RequiredNice to have

Skills

Offensive SecurityVulnerability AssessmentsStrategic ThinkingRisk AnalysisCommunication SkillsHardeningCustom Exploit DevelopmentLogical SubversionStrategic MindsetMapping Business RiskExecuting Targeted CampaignsElevating EngineersDesigning CampaignsThorough Test CasesRigorous Test CasesComplex Logical FlawsChained VectorsHuman IntuitionBuilding ToolsEngineering Offensive SystemsRuthless PrioritizationPrioritizing TargetsUnderstanding Business LogicWeaponizing Business LogicDeconstructing Attack PathsFoundational System HardeningSecure Development StandardsHands-on Security GuidanceRigorous Architecture ReviewAudit SupportRed-Teaming Physical SystemsApex-Level HackingCoding FluencyUnderstanding Modern ArchitectureWriting CodeAnticipating VulnerabilitiesMulti-Cloud EnvironmentsComplex SaaS ArchitecturesAbusing IAM Trust BoundariesTenant Isolation FlawsAPI MisconfigurationsTranslating Complex Exploits

Qualifications

Multi-Disciplinary ScarsNon-Linear BackgroundCloud & SaaS MasteryNo Ego

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
401(k) Match

Full job description

Cloaked is a consumer privacy and identity platform on a mission to give people back control of their personal data. We let anyone generate unlimited identities - masked emails, phone numbers, and payment cards - scrub their information off data-broker sites, and shield themselves from spam, scams, and breaches, all from one app. Backed by a $375M Series B, we've protected 10M+ identities and removed 1B+ records from the data brokers who profit off personal information. Now we're building the AI-native future of privacy: autonomous agents that monitor, manage, and defend your digital footprint for you.

// THE MANDATE Most security roles are compliance disguised as engineering. This is not.

We are looking for a Staff Offensive Security Engineer to operate as a persistent, advanced threat against our own infrastructure. We do not want automated reports. We want custom exploit development, logical subversion, and a strategic mindset.

If you measure your success by the sheer volume of vulnerabilities you find, look elsewhere. If you measure it by your ability to map business risk, execute highly targeted campaigns, and elevate the engineers around you, keep reading.

// THE SCOPE You are not a vulnerability scanner; you are a strategic adversary. Your directive is to compromise our most critical assets before actual adversaries do.

  • Absolute Autonomy: There is no daily task list. You are handed the Rules of Engagement. From there, it is on you to design, dictate, and execute campaigns that provide uncompromising coverage of our attack surface, backed by thorough, rigorous test cases.

  • Beyond the Tooling: Off-the-shelf scanners will not find what you are looking for here. We need you for the complex logical flaws and chained vectors that require human intuition. Furthermore, you aren't just using tools - you are building them. You will engineer complex, future-forward offensive systems that redefine how we test our own defenses at scale.

  • Ruthless Prioritization: You have an infinite attack surface and finite time. You must be able to cut through the noise and prioritize your targets based on catastrophic business risk rather than easy, low-impact wins.

  • Business Subversion: You do not operate in a vacuum. You will partner directly with product and engineering leaders to deeply understand the core business logic of our platforms - and then weaponize that logic against them.

  • Force Multiplier: Breaking in is only half the mandate. When the operation concludes, you teach. You will deconstruct your attack paths and help engineering eradicate entire attack classifications at the root. By driving foundational system hardening and secure development standards, you ensure whole categories of vulnerabilities never see production again.

  • Ubiquitous Ownership: Despite the advanced mandate, our ultimate bottom line is protecting our customers, which means finding flaws early across every single part of the business. You will cross business units to provide hands-on security guidance, rigorous architecture review, and audit support. One day you might be red-teaming a physical system, and the next you are tearing apart our flagship product. We demand apex-level hacking, but we have zero tolerance for a "that's not my job" mentality.

// THE PROFILE We don't screen for certifications or a linear cybersecurity career path. We screen for multi-disciplinary scars, coding fluency, and a deep understanding of modern architecture.

  • You are a Builder First: You write code. You don't just find vulnerabilities after the fact; you anticipate them. You know exactly where the architectural fractures will be before a system is even built or deployed.

  • Non-Linear Background: You have seen the tech stack from every angle. We value a diverse background - whether you've spent time in customer support, QA/test, development, blue team, red team, or all of the above. You know how users break things accidentally, which fuels how you break them intentionally.

  • Cloud & SaaS Mastery: Your playground is modern infrastructure. You are fluent in multi-cloud environments and complex SaaS architectures. You know exactly how to abuse IAM trust boundaries, tenant isolation flaws, and API misconfigurations.

  • No Ego: You have the communication skills to translate a highly complex exploit into actionable engineering requirements without talking down to the engineers who built it.

What we offer Cloaked is a well-funded Series B startup based out of NYC.

Although we are a distributed team, the NYC team operates with a hybrid model. The office building is home to several amenities, including a gourmet cafe, cocktail bar, and a rooftop work area.

We have a fully built out kitchen packed with drinks and snacks. The Cloaked team has diverse interests and so we frequently embark on team outings and go out for socials!

Compensation and Benefits We offer above market rate pay and equity based off of the market’s best commercially available data. Your compensation will be a combination of salary, bonus and equity.

Cloaked employees have 401K, as well as top of the line Health, Dental, and Vision benefits.

We offer flexible work arrangements and the ability to work remotely as needed. Cloaked provides a home office stipend in addition to a new company laptop (and other tech depending on the role).

Perks 🌴 Competitive PTO: We encourage employees to take a minimum # of vacation per quarter. We see PTO as a preventative burnout measure and are committed to changing the industry standard.

🤸 Monthly health stipend: Used for any kind of physical, mental or emotional care you’d like to take for yourself, be it a gym membership, a meditation app, or time with a personal trainer.

🥗 Late Night Meals: We understand that sometimes work can get in the way of meal prep. In response to that, we offer employees a monthly meal stipend to be used when they don’t have time to get a home cooked meal going!

🧠 Professional Growth: Opportunities for career development and personal growth are provided to all employees who seek to further their knowledge and capabilities through an unlimited professional development fund. Additionally team members are encouraged to regularly attend conferences and industry events.

We are really excited about having you join our mission-driven team and help us build the future of online privacy!

You've read the whole posting — now see how you match it.