Greenlight is the money and safety app for families. Our mission is to shine a light on the world of money for families and empower parents to raise financially-smart kids.
Millions of parents and…
📋 Job Overview
Greenlight is a family technology company on a mission to help families raise financially smart kids and navigate life together. Its suite of products — including the Greenlight app, debit card, Safe Family GPS trackers, and Family Hub — brings together financial tools, safety features, and everyday family management in one connected experience. Designed for busy families who want convenience without compromise, Greenlight continues to innovate alongside the evolving needs of modern life. Today, more than 6.5 million family members trust Greenlight to stay in sync.
At Greenlight, we're here to make the day-to-day easier and futures brighter, so families can spend less time managing life, and more time living it. That's why we get out of bed every morning.
🏢 About Greenlight
Greenlight is a family technology company on a mission to help families raise financially smart kids and navigate life together. Its suite of products — including the Greenlight app, debit card, Safe Family GPS trackers, and Family Hub — brings together financial tools, safety features, and everyday family management in one connected experience. Designed for busy families who want convenience without compromise, Greenlight continues to innovate alongside the evolving needs of modern life. Today, more than 6.5 million family members trust Greenlight to stay in sync.
🎯 The Role
Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This individual will be responsible for the continuous offensive security validation across our consumer digital platforms, mobile applications, cloud infrastructure, internal corporate environments, and emerging hardware device lines. The Staff Offensive Security Engineer will drive the long-term technical strategy for offensive security, lead complex red teaming and multi-stage adversary simulations, manage deep-dive vulnerability research into high-risk areas, champion a culture of security-minded development across the R&D organization, and establish automated security guardrails and self-healing infrastructure within a fintech environment.
✅ Key Responsibilities
Lead Technical Strategy: Define the long-term vision for offensive security at Greenlight, moving beyond point-in-time testing to continuous security validation.
Red Teaming & Adversary Simulation: Design and execute complex, multi-stage adversary simulations targeting our cloud infrastructure (AWS), mobile applications (iOS/Android), and internal corporate environments.
Vulnerability Research: Conduct deep-dive research into high-risk areas of our ecosystem, identifying zero-day vulnerabilities or sophisticated logic flaws that automated tools miss.
Pave the \"Golden Path\": Partner with DevOps and Engineering to build automated security guardrails and \"self-healing\" infrastructure that prevents common attack vectors from being introduced.
Incident Response Support: Work closely with the Detection and Response team to improve our monitoring capabilities by performing \"purple team\" exercises to validate alert coverage.
Mentorship: Act as a force multiplier by mentoring senior and mid-level engineers, fostering a culture of security-minded development across the entire R&D organization.
📌 Required Qualifications
Expert-level Offensive Skills: 8+ years of experience in offensive security, red teaming, or penetration testing, with a proven track record of uncovering critical vulnerabilities in complex environments.
Cloud Native Expertise: Deep understanding of AWS security architecture, including IAM bypass techniques, container escapes (Kubernetes), and serverless security.
Application Security Depth: Experience with manual code review (Node.js, Python, or Go) and bypass techniques for modern web and mobile security controls.
Automation Mindset: Ability to script in Python, Bash, or Go to automate exploitation chains or integrate security testing into CI/CD pipelines.
Strategic Communication: The ability to translate complex technical risks into business impact for executive stakeholders while remaining a trusted peer to software engineers.
Relevant Certifications (Optional but valued): OSCP/OSCE, GXPN, or equivalent demonstration of deep technical skill.
⭐ Desirable Experience
An Ethical Hacker at Heart: You are curious, persistent, and think outside the box to find ways around traditional security controls.
A Collaborative Partner: You believe that \"breaking things\" is only half the job; the real value is in helping the team build them back stronger.
Owner Mindset: You take pride in your work and feel a deep sense of responsibility for the safety of our families and their finances.
🎁 Benefits
Medical, dental, vision, and HSA match
Paid life insurance, AD&D, and disability benefits
Traditional 401k with company match
Unlimited PTO
Paid company holidays and pop-up bonus holidays
Professional development stipend
Mental health resources
1:1 financial planners
Fertility healthcare
100% paid parental and caregiving leave, plus cleaning service and meals during your leave
Flexible WFH, both remote and in-office opportunities
Fully stocked kitchen, catered lunches, and occasional in-office happy hours
Please let Greenlight know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.