Security Engineer
Our client is building a digital twin engine that simulates enterprise IT environments (cloud, SaaS, identity, endpoints, networks, security products) with high fidelity, then runs attacks from agentic red teams against them to capture realistic telemetry for AI security training and evaluation.
This is a zero-to-one build — you'll define the architecture and technical direction from scratch.
Who we're looking for
A hybrid of offensive security expert and production software engineer — someone who thinks like an attacker and can turn that into a reliable, scalable system. Not a pure pentester, not a pure backend engineer.
Scope of Work
- Own the architecture and hands-on development of the digital twin engine.
- Build high-fidelity simulations of company stacks — users, networks, cloud, SaaS, identity, endpoints, security products.
- Run attacks from agentic red teams and capture realistic telemetry.
- Adapt environments to customer stacks while protecting privacy, isolation, and authorization boundaries.
- Lead the technical roadmap and engineering standards across contributors.
- Keep the engine reproducible, reliable, scalable, and easy to extend.
Requirements
- Deep offensive/defensive security knowledge, including how security products (EDR/XDR/SIEM) work internally.
- Cloud security experience (AWS/Azure/GCP) and familiarity with anti-forensics techniques.
- Ability to judge whether a scenario and its telemetry are realistic, too easy, or ambiguous.
- Strong software engineering skills — proven experience shipping and operating production systems.
- Experience building cyber ranges, digital twins, security labs, or large-scale simulated environments.
- Strong knowledge of security telemetry and data pipelines (cloud, SaaS, identity, endpoints, networks).
- Comfortable leading ambiguous, zero-to-one development under uncertainty.
- Strong project planning, technical coordination, and code review skills.
Nice to have: AI agents/evals experience (guardrails, reproducibility, human review); conference talks or CTF/red team community involvement; background at BAS companies (Pentera, SafeBreach, Cymulate) or cyber range platforms (CybExer, SimSpace).