We are seeking an experienced and skilled Senior Security Engineer, Threat & Offensive Security to join our growing team! As a key security member at Valon, you will help scale and strengthen our offensive security and threat operations, proactively identifying weaknesses in our systems, networks, and applications as the company continues to grow.
🏢 About Valon
Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate. We've transformed mortgage servicing from a 0% margin business into 60%+ margins while dramatically improving customer experience. ValonOS is our unified platform that makes every process structured and programmable and it is perfectly positioned for the AI era.
🎯 The Role
This position requires a deep understanding of adversarial techniques, security testing methodologies, threat intelligence, and incident response, along with the ability to collaborate with cross-functional teams. This role requires an AI and automation-first approach to security work, using modern tools to scale testing, threat management, and response. You will help ensure security is embedded across our environment and that we continue to safeguard our most critical assets and maintain the trust of our customers and stakeholders.
✅ Key Responsibilities
Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities
Manage and implement security testing tools and frameworks to simulate real-world attacks and validate the effectiveness of existing security controls
Design and implement AI-enabled workflows to scale security testing and threat related operations.
Manage and operationalize threat intelligence to anticipate emerging threats and adjust defenses proactively
Partner with external pentesting firms for periodic, independent reviews
Perform security reviews of new systems, features, architectures, and third-party integrations, providing actionable risk-based recommendations
Collaborate with Engineering, IT, Product and other teams to remediate identified vulnerabilities and strengthen security controls
Develop and refine playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response
Monitor and manage security alerts and incidents, analyze data, and respond to security events
Support operational activities including general security reviews, security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and other processes
📌 Required Qualifications
Minimum of 5 years in a security engineering, penetration testing, threat intelligence, or similar role
Proven experience in security engineering, red team, or threat management role, with a focus on penetration testing, security testing, threat intelligence, and/or incident response
Hands-on experience with security testing tools and frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike, or similar)
Demonstrated experience leveraging AI and automation to improve the efficiency and scalability of threat detection, testing, and response operations
Proficient in both manual and automated testing techniques, understanding when manual analysis is needed versus pure automated testing
Strong understanding of common attack techniques, exploitation methods, and MITRE ATT&CK or related
Experience with SIEM, EDR, and other detection/monitoring platforms
Experience with cloud security and environments (GCP, AWS)
Applied knowledge of industry security and testing frameworks (OWASP, NIST, MITRE ATT&CK, CIS, SOC 2/ISO 27001 concepts)
⭐ Desirable Experience
Ability to work autonomously, lead projects, and navigate complex, ambiguous security investigations
Ability to foster strong relationships and partner with stakeholders to drive remediation and results
Excellent communication and collaboration skills, with the ability to explain technical findings and risk to both technical and non-technical stakeholders
Experience or exposure to startup environments is a plus