This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Senior Security Engineer at Bitwarden, you will be responsible for conducting purple team testing, including threat research and analysis, penetration testing, code audits, security validation testing, and cryptography reviews against Bitwarden’s products and services. In addition, you will be part of the security findings response team, and assist with external inquiry and report response, investigation, and triage. Additional responsibilities include assisting with remediation of any security issues that are identified during internal or external testing and assessments while working alongside our engineering and security operations team members to ensure Bitwarden platform and services are secure and resilient.
Job Responsibility:
Research emerging threats across the surface web, dark web, and deep web
Build threat models, conduct threat hunts, and plan and execute purple team engagements
Coordinate internal red team testing operations that emulate a threat actor
Collaborate with application development teams, platform engineers, and Security Operations Center (SOC) engineers to improve our offensive and defensive security controls
Contribute to vulnerability testing and analysis as well as incident response and analysis
Include testing for web, mobile, CLI, and desktop application security issues across our multi-product portfolio, including Bitwarden Password Manager, Secrets Manager, and Passwordless.dev, our APIs, serverless functions, and database
Participate in code reviews, learning and spreading technical knowledge about security posture
Contribute to resolutions for security-related issues
Coordinate technical validation and leadership review of purple team reports detailing testing results and potential areas of improvement
Conduct internal penetration tests on systems and networks to determine realistic threat vectors
Manage software tools for code scanning, vulnerability identification, and finding reporting
Effectively communicate findings, attack paths, and recommendations to stakeholders
Train others on the adversary simulation tactics and procedures used
Stay informed on current security trends, publications, and advisories
Assist to provide guidance and subject matter expertise as it pertains to all areas of security and technical operations, including analysis of our cloud environments, security testing and documentation, as well as investigations, software research, new technology, services and tools research, and vendor security analysis
Requirements:
Experience with Penetration Testing Tools, such as Burp Suite, NMAP, Nessus, Metasploit, Kali Linux, SQLMap, Owasp ZAP, and manual testing tools
In-depth knowledge of leading vulnerability management tools and strategies
In-depth understanding and usage of application security testing technologies is a plus
Understanding of authentication concepts, including OpenIDConnect, SAML, OAuth, and SSO flows
Strong working knowledge of vulnerability management tools, data and network security technologies
Collaborative and adaptable mindset
Openness and authenticity combined with excellent communication skills
Excitement and enthusiasm for open source and for better internet security
Excellent problem-solving skills
Ability to maintain discretion, handle sensitive information, and maintain security best-practices
Security purple team technocrat at heart, staying current with trends and new technologies
Nice to have:
User of Bitwarden
Experience with C# and TypeScript, the core two languages used to build the Bitwarden platform
Experience in the SecOps world and ability to apply security best practices across the organization