Senior Red Team Operator

 Posted 3 hours ago
  
 Canada
  
 $165K - $180K per year
  
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Plan and execute full-scope adversary emulation and penetration tests across cloud infrastructure, build pipelines, and crypto systems. Collaborate with blue teams and stakeholders to communicate risks and implement practical security mitigations.

You could work anywhere. Why Figment?

Figment powers the future of Web3 through industry-leading blockchain infrastructure. As the leading provider of staking solutions, we help 500+ institutional clients optimize their crypto rewards, including top exchanges, asset managers, wallets, foundations, custodians, and major token holders. Our clients trust Figment for a comprehensive suite of services, including reward optimization, cutting-edge API development, detailed rewards reporting, seamless partner integrations, governance support, and slashing protection.

Backed by a team of passionate and intelligent Figmates, with a 100% remote-first global presence across 12 countries, our company is on a mission to accelerate the adoption, growth, and long-term success of the Web3 ecosystem. We’re building the infrastructure that will power the decentralized future.

As a fast-growing tech company, we’re looking for builders and innovators — people who thrive in the face of uncertainty and are motivated to make an impact. We are also looking for true teammates - people who are genuine, humble, and driven to level up together. If you're excited to shape the future, contribute to an energetic company culture, and work at the cutting edge of blockchain technology, we want you to join our team and help us lead the charge!

About the opportunity

  • As a senior member of the Figment Security Team, you'll plan and run full-scope adversary emulation across all of Figment's products and platforms, from conventional cloud and application infrastructure to build pipelines and crypto systems. You'll own engagements end-to-end: evaluating environments to find vulnerabilities, building the attack scenarios to prove them out, and seeing your findings drive real fixes.
  • This role is as much about partnership as it is about offense. You'll work directly with stakeholders and the blue team to communicate findings clearly, recommend practical mitigations, and help strengthen our overall security posture.

How you will make an impact

  • Plan and execute red team engagements, pentests, and ad-hoc assessments against cloud, development pipelines, web and application layers, source code, and more.
  • Apply attacker tactics, techniques, and procedures safely within Figment environments, including detection-evasion work.
  • Produce clear reports and presentations tailored to both technical and executive audiences.
  • Partner with stakeholders, including technical staff, leadership, and legal counsel, to translate findings into risk-appropriate, actionable recommendations.
  • Collaborate with the blue team to suggest mitigations, validate fixes, and improve defensive coverage.
  • Mentor blue team members and lead cross-team exercises such as purple teaming.
  • Support incident response with offensive security technical expertise and contribute to post-incident action plans.
  • Build and improve red team tooling, scripts, infrastructure, methodologies, and documentation.

What you bring to the team

  • Experience with and strong understanding of cloud platforms, CI/CD pipelines, and supply chains.
  • Demonstrated use of AI tools to accelerate offensive work (LLM-assisted code review, payload generation, recon, report drafting), with sound judgment about where they help versus where manual testing is required.
  • Offensive expertise in container orchestration: attacking and escaping Docker and Kubernetes (container breakout, RBAC abuse, misconfiguration exploitation).
  • Experience performing API and web application assessments.
  • Experience performing source code review for security flaws.
  • Experience building automations that chain red team tooling together, cutting manual effort across recon, exploitation, and reporting.
  • Strong written and verbal communication conveying findings, risk, and remediation to engineers, stakeholders, and executives.

Bonus if you have:

  • Industry certifications such as OSCP/OSCE, OSEP, OSWE, GPEN, GCPN, GWAPT, or GXPN.
  • Solid understanding and experience working with GitHub and GitHub Actions.
  • Programming skills as well as the ability to read and assess applications written in multiple languages such as Go, Rust, and Ruby.
  • Understanding of security risks for blockchain and crypto.

Why you might be excited about us

At Figment, we offer an exciting range of competitive benefits designed to support and empower every member of our team:

  • 100% remote-first environment. Our flagship office is in Toronto, Canada. We also have additional co-working spaces in New York, London, and Singapore. That means if you want to do your thing in the office (if you’re near one), at home, or a bit of both, it’s up to you.
  • 4 weeks of PTO that kick in day one, with an additional 1 week of flex days.
  • Extended company-paid health benefits that kick in day one.
  • Best-in-class parental leave and flexible arrangements.
  • A home office stipend to create a space that you enjoy working in.
  • Monthly Wi-Fi reimbursement.
  • A yearly Learning & Development budget.
  • 401K (US) or RRSP match (Canada).
  • Stock Options in the company.
  • Annual on-site company gatherings and retreats to inspire team bonding, collaboration, and fun!

Other reasons you may love working at Figment:

  • We are a team of under 200 members, which allows for an impactful contribution from day one.
  • We place a strong focus on personal career development to shape a role that fits your goals and interests. Your satisfaction and well-being matter to us, and we’re here to support your ongoing growth.
  • Our culture is one of honesty, professionalism, and risk-taking in a high-growth environment.
  • Our team members themselves recommend working at Figment - with an eNPS score of 54 (which is ranked as ‘great’!).
  • We are also extremely proud to be ranked as one of the top Web3 employers by Talent Titans.

 

Compensation: One of Figment’s core principles is “Making the Invisible Visible” - ensuring transparency and information sharing in all communication. Figment is committed to transparency regarding pay, benefits, and other compensation types for all internal roles as well as all roles being hired for.

Base Salary: The US base salary range for this position is USD $165,000 - $180,000. The CAD base salary range for this position is CAD $165,000 - $180,000. This range reflects base salary only, and does not include additional compensation, sales incentives or benefits. For candidates in other countries, the pay range will be disclosed upon your first interview with Figment (being a globally remote company, the list of salary ranges would simply be too long to note here!). The range displayed reflects the minimum and maximum range for a new hire across all of Canada or the US. A candidate’s specific pay within the range will be determined by various factors including job-related skills, relevant education, and training.

Interview process: At Figment, we try to go above and beyond in making sure that you have the best possible experience interviewing with us. We strive for a smooth, organized, and informative process.

  • During your first Recruiter Call, you will be provided with more information about Figment, the position and what to expect for the rest of the interview process. Please be prepared to discuss why you are interested in joining Figment and what excites you about the position and company.
  • As we go through the process, we work to make sure that you hear back from us in a timely fashion. If we decide at any point that we’re unfortunately not moving forward, we will give you feedback on why it was not a fit.
  • We aim for the entire process to take around 2–4 weeks from initial screen to offer. There can be exceptions on either side of the bell curve here, but as a rule, that’s the time-frame you can expect.

See here for Figment's Privacy Policy and California Employee Privacy Policy.

At Figment, we have a thorough hiring process to verify the identity of all job candidates. This includes checking documents, conducting in-person interviews and completing background checks. Candidates must pass all these steps to be considered for a job with Figment. Anyone who provides false information or tries to skip these steps will be disqualified from the hiring process immediately.

To learn more about Figment, our team, and the amazing work we are doing, visit our website. Are you ready to join us?

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified