Overview
In this role you lead DRW’s offensive security program, planning and executing red team engagements, adversary simulations, and penetration tests across trading, corporate, and cloud environments. You translate findings into practical improvements, shaping the security roadmap and tooling. You collaborate with security, infrastructure, and trading teams to harden systems and advance DRW’s defenses. This role combines hands-on testing with mentoring and methodology development, offering high-impact opportunities to reduce risk across global platforms.
Responsibilities
- Plan and execute red team engagements and adversary simulations across trading systems, corporate IT, and cloud environments using ATT&CK-aligned TTPs
- Conduct penetration testing of networks, web and internal apps, APIs, and cloud infrastructure with clear remediation guidance
- Design and build custom tooling, scripts, and exploits to simulate adversary behavior and test detections
- Collaborate with Security Engineering and SOC in purple-team exercises to close gaps between attacker and defender capabilities
- Run social engineering/phishing simulations to assess security awareness
- Identify, validate, and track vulnerabilities with owners to remediation
- Present engagement results and risk narratives to technical teams and senior leadership
- Stay current on threat landscape and offensive tooling; contribute to DRW’s defensive posture
- Assess security of AI/LLM-integrated systems and harden them
- Leverage AI-assisted tooling to accelerate reconnaissance, vulnerability discovery, and exploit development
- Help define and mature DRW’s offensive security methodology, standards, and tooling, and mentor others
Key requirements
- 5+ years in offensive security, penetration testing, or red teaming
- Strong scripting/programming ability for tooling
- Solid networking, Windows, macOS, Linux, identity providers, and cloud fundamentals
- Experience with offensive security tools (Cobalt Strike, Metasploit, BloodHound, Burp Suite, Nmap) and building custom ones
- Working knowledge of MITRE ATT&CK, adversary emulation, and detection evasion
- Proven ability to report clearly and translate findings to risk for engineers and executives
- Experience with smart contract auditing and blockchain security
- Familiarity with AI/ML security risks and LLM-powered tooling
- Collaborative mindset toward improving organization security
- clear and precise communication
- collaborative mindset
- risk-minded storytelling
- Cobalt Strike
- Metasploit
- BloodHound
…
