10 days ago

Principal Offensive Security Developer

Autodesk

On Site
Full Time
$180,000
Toronto, ON

Job Overview

Job TitlePrincipal Offensive Security Developer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$180,000
LocationToronto, ON

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

Principal Offensive Security Developer at Autodesk

Are you passionate about computers, software, and the art of dismantling code, devices—even cars? Do you love protecting people from digital threats, whether they come from cybercriminals or simple human error? If you’ve ever read 2600 or celebrated the Phrack anniversary edition at DEFCON33, we might have the perfect role for you.

At Autodesk, we’re transforming how the world is designed and built. Our mission is to empower customers to create energy-efficient, low-carbon-footprint buildings through cutting-edge software. We’re leading the Architecture, Engineering, and Construction (AEC) industry into a new era—one powered by AI and connected data platforms. As we grow into the Trusted Partner for the AEC industry, we’re looking for someone who can help keep our innovations secure.

Autodesk is hiring a Principal Offensive Security Developer to join our journey. In this role, you’ll bring your offensive security expertise to a team of passionate technologists. You’ll uncover critical security improvements in our products and identify creative ways to enhance our systems, processes, and practices.

You’ll collaborate across teams and geographies, offering insight and support as they address vulnerabilities. You’ll help mature our Secure Software Development Lifecycle (SSDLC) across AEC teams and improve our vulnerability and zero-day response processes.

We also invest in your growth—this role includes opportunities to attend top security conferences and training sessions throughout the year, so you can sharpen your skills and bring back fresh ideas.

This is a remote position open to candidates in the United States or Canada. (East Coast strongly preferred).

Responsibilities

  • Work with the Senior Distinguished Architect, Trust, to document, maintain, and improve the AEC Secure Software Development Lifecycle.
  • Work with the Trust Organization in various Security Vulnerability Management and 0-day response capacities.
  • Manage and mature the AEC security vulnerability and DoD response processes.
  • Act as primary point of contact for AEC 0-day reports and assist in engaging Researchers and Developers.
  • Proactively fuzz, research, and investigate AEC Products and Processes for Security issues and improvements.
  • Support all AEC Security incident BPM processes.
  • Assist engineering teams in secure code development through expertise.
  • Help with setting up policies, procedures, and standards to improve Security Posture.
  • Engage with AEC developers to establish training, awareness resources, and other mechanisms to dramatically improve the security of AEC products.
  • Partner with other developers across the company to share Software Security practices, lessons learned, and improve transparency and efficiency.
  • Own the various Security metadata components within the Software Catalog, including creation, naming, and maintaining.
  • Attend Trust meetings across the AEC organization (bi-weekly, monthly, and quarterly).
  • Attend industry events and other conventions/conferences to gather new Software Security techniques and to continuously improve this role’s impact.

Minimum Qualifications

  • BS or MS or Equivalent Experience in Cybersecurity/Computer Science (or related technical field).
  • 5+ years of hands-on Offensive Security experience or 7+ years of a mix.
  • Experience with Offensive Security tools, techniques, and methodologies.
  • Experience working with programming languages (Eg. C, C++, C#, Rust, Go, Javascript, Java, Python, Perl, PHP, TypeScript...).
  • Experience collaborating with cross-organizational teams.

Preferred Qualifications

  • Experience with writing reports and communicating complex security concepts to technical personnel.
  • Familiarity with modern software practices including Continuous Integration, Continuous Delivery, and Infrastructure-as-Code.
  • Familiarity with Security Disciplines outside of Offensive Security (Privacy, GRC, Blue Teaming, Awareness).
  • Familiarity with authentication/authorization using OAuth2.0, OICD, SPIFFE, FIDO2, etc.
  • Familiarity with large-scale distributed systems, containing hybrid applications across desktop, mobile, and web.
  • Experience in the AEC industry or other regulated industry.

The Ideal Candidate

  • Easily collaborates with other members of a team to deliver value.
  • Constantly strives to learn new technologies and methodologies.
  • Is adaptable, customer-focused, and seeks new ways to solve hard problems.
  • Is transparent and works in an open sharing manner, leveraging automation.

Key skills/competency

  • Offensive Security
  • Secure Software Development Lifecycle (SSDLC)
  • Vulnerability Management
  • Zero-day Exploits
  • Programming Languages (C, C++, Rust, Python)
  • Threat Intelligence
  • Cybersecurity
  • Incident Response
  • Fuzzing
  • Security Posture

Tags:

Principal Offensive Security Developer
offensive security
vulnerability management
zero-day response
SSDLC
fuzzing
threat research
incident response
security posture
code review
security architecture
C
C++
C#
Rust
Go
Javascript
Java
Python
Perl
PHP
TypeScript
OAuth2.0
OICD
SPIFFE
FIDO2
distributed systems
CI/CD
Infrastructure-as-Code

Share Job:

How to Get Hired at Autodesk

  • Research Autodesk's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight offensive security expertise, SSDLC experience, programming skills, and vulnerability management.
  • Showcase technical prowess: Emphasize practical experience with C, C++, C#, Rust, Go, Javascript, Java, Python, Perl, PHP, TypeScript.
  • Prepare for deep technical interviews: Expect questions on fuzzing, zero-day research, distributed systems, and modern software security practices.
  • Demonstrate collaborative spirit: Discuss successful cross-functional projects and your ability to communicate complex security concepts effectively.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background