About the job
At Veeam Software, we are committed to being the leading Data and AI Trust Company. Our focus is on empowering organizations to effectively manage, secure, and understand their data and AI capabilities, ensuring resilience and enabling safe AI scalability. As pioneers in data resilience and security posture management, we are strategically positioned at the intersection of identity, data, security, and AI risk. With our headquarters in Seattle and a presence in over 30 countries, we proudly protect more than 550,000 customers globally, earning their trust to keep their operations running seamlessly. Join us in our journey to innovate and make a significant impact for some of the world's most prominent brands.
About the Role
As a Lead Application Security Engineer (Offensive Testing), you will spearhead penetration testing and Dynamic Application Security Testing (DAST) for our Veeam Data Cloud offerings. Utilizing Burp Suite and the latest web/API testing methodologies, you will identify genuine exploitable vulnerabilities, prioritize risks, and collaborate closely with engineering teams to ensure effective remediation.
Your role will also involve enhancing testing tools and methodologies to streamline processes, helping teams avert recurring vulnerabilities, particularly in areas such as authentication, authorization, session management, and tenant isolation.
What You’ll Do
- Lead offensive testing initiatives: strategize the scope, depth, and frequency of tests; generate clear, consistent reports, and develop reusable playbooks.
- Conduct manual penetration testing (primary focus): assess web applications and APIs, especially around authentication/authorization, multi-tenant boundaries, and critical workflows; simulate realistic attack paths by chaining vulnerabilities.
- Utilize Burp Suite on a daily basis: replicate and validate findings using advanced features; create and maintain repeatable scopes, macros, and authenticated flows.
- Enhance and execute DAST processes: perform and refine authenticated scans, minimize false positives, and collaborate with CI/platform teams to scale scanning efforts and manage credentials efficiently.
- Drive vulnerability remediation: produce high-quality documentation, partner with engineering teams for fixes and retesting, and assist in preventing regressions; ensure that findings are logged with appropriate severity and SLAs.
- Contribute to long-term security improvement: identify recurring patterns and collaborate with teams to establish prevention strategies through standards, libraries, platform controls, and contributions to threat modeling/design reviews.
What You’ll Bring
- Robust experience in web and API penetration testing, with a strong emphasis on authorization vulnerabilities (IDOR/BOLA, privilege escalation, etc.).

