The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing ...
The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing ...
The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing ...
The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing ...
Senior Offensive Security Engineer
Naperville, IL · On-site
$114K - $156K/yr
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical ...
Senior Offensive Security Engineer
Naperville, IL · On-site
$114K - $156K/yr
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical ...
Senior Offensive Security Engineer
Naperville, IL · On-site
$114K - $156K/yr
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical ...
Senior Offensive Security Engineer
Naperville, IL · On-site
$114K - $156K/yr
The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical ...
Senior Offensive Security Engineer - Pentester
Chicago, IL · On-site
$118K - $161K/yr
... engineers, and assist with monitoring and response functions, so those teams can practice and ... Minimum of 5+ years of professional offensive security experience * Must be able to critically ...
Senior Offensive Security Engineer - Pentester
Chicago, IL · On-site
$118K - $161K/yr
... engineers, and assist with monitoring and response functions, so those teams can practice and ... Minimum of 5+ years of professional offensive security experience * Must be able to critically ...
Security Engineer
Chicago, IL · On-site
$145K - $195K/yr
About The Role We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack ...
Security Engineer
Chicago, IL · On-site
$145K - $195K/yr
About The Role We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack ...
Senior Penetration Testing Engineer
Chicago, IL · Hybrid
$92K - $144K/yr
Perform hands‑on offensive security testing to identify, validate, and drive remediation of ... Work with software engineering, application security, and cyber threat mitigation teams to ...
Quick apply
Senior Penetration Testing Engineer
Chicago, IL · Hybrid
$92K - $144K/yr
Perform hands‑on offensive security testing to identify, validate, and drive remediation of ... Work with software engineering, application security, and cyber threat mitigation teams to ...
Artificial Intelligence Senior Security Engineer
Chicago, IL · On-site
$118K - $161K/yr
... Senior Engineer to drive the integration of advanced AI technologies into our cyber defense ... The ideal candidate will have deep expertise in AI/ML, offensive and defensive security operations ...
Artificial Intelligence Senior Security Engineer
Chicago, IL · On-site
$118K - $161K/yr
... Senior Engineer to drive the integration of advanced AI technologies into our cyber defense ... The ideal candidate will have deep expertise in AI/ML, offensive and defensive security operations ...
Senior Application Security Engineer
$130K - $180K/yr
Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing ... Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH ...
Senior Application Security Engineer
$130K - $180K/yr
Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing ... Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH ...
Artificial Intelligence Senior Security Engineer
Chicago, IL · On-site
$118K - $161K/yr
... and engineering teams to drive AI integration into cyber defense. This security focused subject ... The ideal candidate will have deep expertise in AI/ML, offensive and defensive security operations ...
Artificial Intelligence Senior Security Engineer
Chicago, IL · On-site
$118K - $161K/yr
... and engineering teams to drive AI integration into cyber defense. This security focused subject ... The ideal candidate will have deep expertise in AI/ML, offensive and defensive security operations ...
Senior Application Security Engineer
Chicago, IL · On-site
$130K - $180K/yr
Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing ... Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH ...
Senior Application Security Engineer
Chicago, IL · On-site
$130K - $180K/yr
Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing ... Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH ...
Senior Penetration Testing Engineer
Chicago, IL · On-site
$92K - $144K/yr
Perform hands-on offensive security testing to identify, validate, and drive remediation of ... Work with software engineering, application security, and cyber threat mitigation teams to ...
Senior Penetration Testing Engineer
Chicago, IL · On-site
$92K - $144K/yr
Perform hands-on offensive security testing to identify, validate, and drive remediation of ... Work with software engineering, application security, and cyber threat mitigation teams to ...
The Senior Red Team Operator leads advanced offensive security operations designed to assess and ... Serve as a trusted advisor and subject matter expert to security operations, detection engineering ...
The Senior Red Team Operator leads advanced offensive security operations designed to assess and ... Serve as a trusted advisor and subject matter expert to security operations, detection engineering ...
Aikido builds developer-first security products that reduce real risk without getting in the way of ... Basic offensive security knowledge: understand concepts like RCE, SSRF, and session handling * Able ...
Aikido builds developer-first security products that reduce real risk without getting in the way of ... Basic offensive security knowledge: understand concepts like RCE, SSRF, and session handling * Able ...
Lead Penetration Test Engineer
Chicago, IL · Hybrid
$135K/yr
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...
New
Lead Penetration Test Engineer
Chicago, IL · Hybrid
$135K/yr
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...
New
Lead Penetration Test Engineer
Chicago, IL · Hybrid
$135K/yr
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...
Lead Penetration Test Engineer
Chicago, IL · Hybrid
$135K/yr
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...
We are seeking a mid-level professional to join our Vulnerability Management & Offensive Security (VMOS) team, where you will gain hands-on experience in vulnerability management, penetration testing ...
We are seeking a mid-level professional to join our Vulnerability Management & Offensive Security (VMOS) team, where you will gain hands-on experience in vulnerability management, penetration testing ...
Senior Application Security & DevSecOps Engineer
Chicago, IL · On-site
$60.50 - $80.75/hr
Offensive Security & Penetration Testing * Run internal penetration tests and red-team-style ... Reverse engineering / binary analysis (Ghidra, Hopper, IDA). What Success Looks Like * Critical and ...
Senior Application Security & DevSecOps Engineer
Chicago, IL · On-site
$60.50 - $80.75/hr
Offensive Security & Penetration Testing * Run internal penetration tests and red-team-style ... Reverse engineering / binary analysis (Ghidra, Hopper, IDA). What Success Looks Like * Critical and ...
Conduct original research and experimentation on agentic AI applied to offensive and defensive ... Respective years of experience in cybersecurity, security engineering, or security research -- with ...
Conduct original research and experimentation on agentic AI applied to offensive and defensive ... Respective years of experience in cybersecurity, security engineering, or security research -- with ...
Conduct original research and experimentation on agentic AI applied to offensive and defensive ... Respective years of experience in cybersecurity, security engineering, or security research -- with ...
Quick apply
Conduct original research and experimentation on agentic AI applied to offensive and defensive ... Respective years of experience in cybersecurity, security engineering, or security research -- with ...
Weekend Offensive Security Engineer information
What is the difference between Weekend Offensive Security Engineer vs Penetration Tester?
| Aspect | Weekend Offensive Security Engineer | Penetration Tester |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | OSCP, CEH, GPEN |
| Work Environment | Part-time, project-based, often remote | Full-time, consulting or in-house roles |
| Industry Usage | Security firms, tech companies, freelance | Security firms, consulting, internal security teams |
The Weekend Offensive Security Engineer and Penetration Tester roles share similar certifications and skills, focusing on identifying vulnerabilities. However, the Weekend Offensive Security Engineer typically works part-time or on a flexible schedule, often remotely, while Penetration Testers usually hold full-time positions. Both roles are vital in cybersecurity, but the engineer role emphasizes a flexible, project-based approach, whereas Penetration Testers often work within organizations or consulting firms on scheduled assessments.
- Remote Penetration Test
- Freelance Endpoint Security Engineer
- Physical Security Engineer
- Flex Cloud Monitoring
- Remote Infrastructure Security Engineer
- Senior Network Security Engineer
- Director Offensive Security Engineer
- Freelance Offensive Security Engineer
- Flexible Application Security Engineer
- Overnight Wiz Cloud Security

Ecolab rating
7.5
Based on 209 frontline employees who took The Breakroom Quiz
58th of 100 rated chemical manufacturers
Job description
What you will do:
- Lead and perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.
- Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.
- Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
- Develop repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.
- Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.
- Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.
- Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.
- Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.
- Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.
- Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.
- Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.
- Help improve Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.
- Coordinate with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.
- Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.
- Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.
Minimum Qualifications:
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.
- 8+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.
- Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.
- Experience leading offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.
- Experience leading a small technical team, workstream, or group of security engineers while remaining directly involved in hands-on testing and analysis.
- Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.
- Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.
- Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.
- Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.
- Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.
- Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.
- Strong interpersonal, analytical, problem-solving, organizational, and written/verbal communication skills.
- Ability to communicate technical findings clearly to software engineers, architects, cybersecurity leaders, product owners, and non-technical business stakeholders.
- Ability to accommodate a flexible work schedule for supporting global activities.
Preferred Qualifications:
- Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications.
- Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.
- Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.
- Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.
- Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.
- Experience developing testing playbooks, reporting templates, engagement standards, risk-rating models, and remediation validation procedures.
- Experience with AI-enabled products, AI integrations, or the security implications of AI/ML capabilities in commercial software environments.
- Ability to influence without authority and drive security improvements across globally distributed engineering, product, and technology teams.
Annual or Hourly Compensation Range
The base salary range for this position is $120,500.00 - $180,700.00. This position is eligible for annual bonus pay based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.
Benefits
Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits.
If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.
Potential Customer Requirements Notice
To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:
- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.
Americans with Disabilities Act (ADA)
Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.
About Ecolab
Sourced by ZipRecruiter
Ecolab is a global sustainability leader offering water, hygiene and infection prevention solutions and services that protect people and the resources vital to life.
Industry
Manufacturing
Company size
10,000+ Employees
Headquarters location
Saint Paul, MN, US
Year founded
1923