Principal Offensive Security Engineer

3 weeks ago


Montreal, Canada Autodesk Full time

Are you passionate about computers, software, and the art of dismantling code, devices—even cars? Do you love protecting people from digital threats, whether they come from cybercriminals or simple human error? If you’ve ever read 2600 or celebrated the Phrack anniversary edition at DEFCON33, we might have the perfect role for you. At Autodesk, we’re transforming how the world is designed and built. Our mission is to empower customers to create energy-efficient, low-carbon-footprint buildings through cutting-edge software. We’re leading the Architecture, Engineering, and Construction (AEC) industry into a new era—one powered by AI and connected data platforms. As we grow into the Trusted Partner for the AEC industry, we’re looking for someone who can help keep our innovations secure. Autodesk is hiring a Principal Offensive Security Engineer to join our journey. In this role, you’ll bring your offensive security expertise to a team of passionate technologists. You’ll uncover critical security improvements in our products and identify creative ways to enhance our systems, processes, and practices. You’ll collaborate across teams and geographies, offering insight and support as they address vulnerabilities. You’ll help mature our Secure Software Development Lifecycle (SSDLC) across AEC teams and improve our vulnerability and zero-day response processes. We also invest in your growth—this role includes opportunities to attend top security conferences and training sessions throughout the year, so you can sharpen your skills and bring back fresh ideas. This is a remote position open to candidates in the United States or Canada . (east coast strongly preferred). Responsibilities Work with the Senior Distinguished Architect, Trust; to document, maintain, and improve the AEC Secure Software Development Lifecycle Work with the Trust Organization in various Security Vulnerability Management and 0-day response capacities Manage and mature the AEC security vulnerability and DoD response processes Act as primary point of contact for AEC 0-day reports and assist in engaging Researchers and Engineers Proactively fuzz, research, and investigate AEC Products and Processes for Security issues and improvements Support all AEC Security incident BPM processes Assist engineering teams in secure code development through expertise Help with setting up policies, procedures, and standards to improve Security Posture Engage with AEC engineers to establish training, awareness resources, and other mechanisms to dramatically improve the security of AEC products Partner with other engineers across the company to share Software Security practices, lessons learned, and improve transparency and efficiency Own the various Security metadata components within the Software Catalog, including creation, naming, and maintaining Attend Trust meetings across the AEC organization (bi-weekly, monthly, and quarterly) Attend industry events and other conventions/conferences to gather new Software Security techniques and to continuously improve this roles’ impact Minimum Qualifications BS or MS or Equivalent Experience in Cybersecurity/Computer Science (or related technical field) 5+ years of hands-on Offensive Security experience or 7+ years of a mix Experience with Offensive Security tools, techniques, and methodologies Experience working with programming languages (Eg. C, C++, C#, Rust, Go, Javascript, Java, Python, Perl, PHP, TypeScript...) Experience collaborating with cross-organizational teams Preferred Qualifications Experience with writing reports and communicating complex security concepts to technical personnel Familiarity with modern software practices including Continuous Integration, Continuous Delivery, and Infrastructure-as-Code Familiarity with Security Disciplines outside of Offensive Security (Privacy, GRC, Blue Teaming, Awareness) Familiarity with authentication/authorization using OAuth2.0, OICD, SPIFFE, FIDO2, etc. Familiarity with large-scale distributed systems, containing hybrid applications across desktop, mobile, and web Experience in the AEC industry or other regulated industry Easily collaborates with other members of a team to deliver value Constantly strives to learn new technologies and methodologies Is adaptable, customer-focused, and seek new ways to solve hard problems Is transparent and work in an open sharing manner, leveraging automation Salary is one part of Autodesk’s competitive compensation package. For U.S.-based roles, we expect a starting base salary between $138,100 and $223,300. Offers are based on the candidate’s experience and geographic location, and may exceed this range. In addition to base salaries, our compensation package may include annual cash bonuses, commissions for sales roles, stock grants, and a comprehensive benefits package. Equal Employment Opportunity At Autodesk, we're building a diverse workplace and an inclusive culture to give more people the chance to imagine, design, and make a better world. Autodesk is proud to be an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender, gender identity, national origin, disability, veteran status or any other legally protected characteristic. We also consider for employment all qualified applicants regardless of criminal histories, consistent with applicable law. #J-18808-Ljbffr



  • Montreal (administrative region), Canada Autodesk Full time

    Une entreprise de logiciels novateurs recrute un développeur principal en sécurité offensive. Ce poste, ouvert aux candidats aux États-Unis ou au Canada, nécessite plus de 5 ans d'expérience en sécurité offensive. Vous devez documenter et améliorer le cycle de vie de développement logiciel tout en testant proactivement la sécurité des produits....


  • Montreal (administrative region), Canada Autodesk Full time

    Une entreprise de logiciels novateurs recrute un développeur principal en sécurité offensive. Ce poste, ouvert aux candidats aux États-Unis ou au Canada, nécessite plus de 5 ans d'expérience en sécurité offensive. Vous devez documenter et améliorer le cycle de vie de développement logiciel tout en testant proactivement la sécurité des produits....


  • Montreal (administrative region), Canada Autodesk Full time

    Job Requisition ID # 25WD91774 English translation will follow!/La traduction en anglais suivra! 25WD91774, Développeur principal en sécurité offensive Overview Vous êtes passionné par les ordinateurs, les logiciels et l'art de démonter des codes, des appareils, voire des voitures ? Vous aimez protéger les gens contre les menaces numériques, qu'elles...


  • Montreal (administrative region), Canada Autodesk Full time

    Job Requisition ID # 25WD91774 English translation will follow!/La traduction en anglais suivra! 25WD91774, Développeur principal en sécurité offensive Overview Vous êtes passionné par les ordinateurs, les logiciels et l'art de démonter des codes, des appareils, voire des voitures ? Vous aimez protéger les gens contre les menaces numériques, qu'elles...

  • Senior Consultant

    1 week ago


    Montreal, Canada KPMG Canada Full time

    Join to apply for the Senior Consultant - Cyber Defense - Offensive Security role at KPMG Canada Overview At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause turning insight into opportunity for clients and communities around the world. Are you a talented individual with a proven track record on executing...

  • Senior Consultant

    1 week ago


    Montreal, Canada KPMG Canada Full time

    Join to apply for the Senior Consultant - Cyber Defense - Offensive Security role at KPMG Canada Overview At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause turning insight into opportunity for clients and communities around the world. Are you a talented individual with a proven track record on executing...


  • Montreal (administrative region), Canada Desjardins Group Full time

    Senior Offensive Security Advisor page is loaded## Senior Offensive Security Advisorremote type: The work arrangement for the position is hybrid worklocations: Montréaltime type: Full timeposted on: Posted 7 Days Agojob requisition id: R2516475As a Senior Offensive Security Advisor, you help identify, analyze, eradicate and mitigate threats to...


  • Montreal, Quebec, Canada Desjardins Full time

    Do technical challenges keep you awake at night? Do you want to constantly learn, analyze, understand things and leverage your experience, knowledge and expertise? Our Red Team needs an operator to perform adversary simulation and threat monitoring activities at Desjardins. In this role, you work with high caliber cyber-defence and insider-threat teams...


  • Montreal (administrative region), Canada Desjardins Group Full time

    A major financial services organization in Montreal is seeking a Senior Offensive Security Advisor to identify and mitigate cyber threats across systems. Responsibilities include conducting vulnerability assessments, developing offensive security solutions, and leading workshops. We offer competitive salary, annual bonus, and a comprehensive benefits package...

  • Lead Cyber Defense

    1 week ago


    Montreal, Canada KPMG Canada Full time

    A leading consulting firm in Canada is seeking a Senior Consultant in Cyber Defense with a focus on Offensive Security. The ideal candidate will have expertise in web application security, vulnerability assessments, and penetration testing. Responsibilities include conducting security assessments, documenting findings, and communicating results to clients....