Staff II Offensive Security Engineer

Datto, Norwalk, CT, United States

The Total Data Protection Company

As the world’s leading provider of cloud-based software and technology solutions delivered by managed service providers (MSPs), Datto believes there is no limit to what small and medium businesses can achieve with the right technology. Datto offers Unified Continuity, Networking, and Business Management solutions and has created a one-of-a-kind ecosystem of MSP partners. These partners provide Datto solutions to over one million businesses across the globe. Since its founding in 2007, Datto continues to win awards each year for its rapid growth, product excellence, superior technical support, and for fostering an outstanding workplace. With headquarters in Norwalk, Connecticut, Datto has global offices in the United Kingdom, Netherlands, Denmark, Germany, Canada, Australia, China, and Singapore. Learn more at datto.com.

The Offensive Security Engineer identifies weaknesses within our systems, network and applications. You will have proficiency in penetration testing of operating systems and web applications. You’ll also look to perform vulnerability research across a wide range of services which can include source code auditing, web application hacking, reverse engineering and fuzzing.

A Look Inside the Job:

  • Perform penetration tests on dozens of different products built with a wide variety of application stacks.
  • Discover threats, vulnerabilities and exploits through architecture design review, threat modeling, code review, and penetration assessments.
  • Offer remediation guidance to stakeholders for identified issues and serve as an escalation resource for engineering as they reduce issues.
  • Identify unknown attack surface in our products/software
  • Utilize fuzzing tools/frameworks such as AFL++, libfuzzer and jazzer to find complex bugs within software applications
  • Create scripts/tools for automated vulnerability discovery
  • Build process and technology to improve the reporting and prioritization of identified weaknesses.
  • Perform threat actor simulation as part of Purple team exercises

Required Skills:

  • Proficient in different bug classes for web applications that span the OWASP top 10
  • You have several years of hands-on experience as a hacker, and have exercised your skills against both Linux and Windows environments.
  • 2+ years of experience auditing source code in common object oriented programming languages.
  • Strong working knowledge of 1 or more of the following programming languages: Python, PHP, C/C++, C#, Java, Golang (not a programming role, but must be able to read code)
  • 4+ years of experience directly related to offensive/application security work
  • Ability to work independently and be highly self-motivated
  • Strong understanding of operating system concepts such as memory management
  • Knowledge of core concepts related to Active Directory


  • Writer for a security blog or similar
  • Teaching / public speaking experience
  • Published CVEs
  • OSCP (Offensive Security Certified Professional), OSEP (Offensive Security Experiences Penetration Tester), OSCE (Offensive Security Certified Expert)

At Datto, we believe our employees are our greatest asset and offer all full-time employees a wide-ranging benefits package, including:
  • Comprehensive health-care benefits
  • Flexible paid time off policy
  • Generous paid parental leave
  • “Datto University” virtual on-boarding program
  • Access to more than 5,000 courses via LinkedIn Learning
  • Education reimbursement
  • Employee Assistance Program
  • Headspace App
  • Charity match program
  • A dynamic and socially active work culture, including Employee Resource Groups
  • Networking and career development opportunities
  • And more!
Note: We are looking only for candidates willing to join us directly as W2 employees (No 3rd party candidates)
By submitting an application, you acknowledge we will process your data in order to consider you for the position you apply for and for other open positions within our company for which you may be suited. We collect and store your data in accordance with our Recruiting Privacy Practices.

Datto is an equal opportunity employer.

About Datto

About us Datto protects business data and provides secure connectivity for tens of thousands of the world's fastest growing companies. Datto's Total Data Protection solutions deliver uninterrupted access to business data on site, in transit and in the cloud. Thousands of IT service providers globally rely on Datto's combination of pioneering technology and dedicated services to ensure businesses are always on, no matter what. Datto is headquartered in Norwalk, Connecticut and has offices in Rochester, Boston, Portland, Toronto, London, Singapore and Sydney. Learn more at www.datto.com.

Want to learn more about Datto? Visit Datto's website.