Staff Offensive Security Engineer @ Box Inc.

1 day ago


Warsaw, Czech Republic Box Inc. Full time

Who you are:

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.

  • 6 years experience in offensive security roles
  • Demonstrated experience in executing offensive security operations of a variety of complexity and in different environments (cloud, network, etc)
  • Proven experience in documenting and presenting findings from operations to technical audiences
  • Ability to collaborate w/ Cyber Intelligence and other Security Engineering Teams to test, report and provide actionable feedback on security posture
  • Detailed understanding of the TCP/IP networking stack, network technologies and covert channels
  • High level understanding of Cloud Environments (AWS, Azure, GCP, etc)
  • Nominal understanding of regular expression and proficient in programming (.NET, C/C++) and scripting languages (e.g. Perl, Java, or Python)
  • Strong collaborative skills and proven ability to work in a diverse global team of security professionals
  • Demonstrated technical experience in several of the following areas:
    • Cloud, network, mobile, web and host penetration testing/assessments
    • Strong understanding of Linux, Mac OS, Windows and kubernetes internals
    • Email, phone, or physical social-engineering assessments
    • Developing, extending, or modifying exploits, shellcode or exploit tools
    • Source code review for control flow and security flaws
    • Bypassing preventative and detective security controls to accomplish operational goals
    • Strong knowledge of tools used for wireless, web application, cloud and network security testing
    • Leading cross functional projects as well as coaching and developing management bench in the team
    • Familiarity with common C2 frameworks such as Cobalt Strike, Mythic, and Metasploit
    • Familiarity with common offensive security tools (burp, Kali, cloud attack scripts; ie S3scanner, Pacu, etc)

**Our compensation structure is the base salary and equity in the form of restricted stock units.

What is Box?

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

Why Box needs you:

The Staff Offensive Security Engineer will be a member of the adversarial services function within the Security Operations Team. This role participates in various operations of different complexities and lengths to test security architecture, security tools, configurations and Incident response. This role will also be expected to partner closely with other security, technical and operational teams. This role will have the opportunity to collaborate across Box as a whole, providing expertise and leadership to product, architecture and operational teams.

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week. Your Recruiter will share more about how we work and company culture during the hiring process. 

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in. If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply

,[Lead purple team activities from an offensive lens, focusing on validating telemetry and detection, and identifying and addressing gaps, Research, develop, and apply offensive tactics, techniques, and procedures (TTP’s), with a strong emphasis on mimicking threat actor behaviors for purple team engagement, Collaborate and partner with Global Security Office Teams and other stakeholders in the organization to identify and prioritize security posture improvements, with a focus on enhancing collaboration between offensive security (Red Team) and Defensive Teams (Incident Response), Work closely and collaborate with the Threat Operations Team (Threat Intelligence & Detection Engineering) to ensure threat analysis and research directly inform defensive strategies, Partner with Engineering and Architecture Teams, driving and advocating for remediation of operation findings, Assist in maintaining Team documentation, processes, resources, tools and findings] Requirements: Cobalt Strike, Burp Suite

  • Warsaw, Czech Republic Box Inc. Full time

    Who you are: Experienced security engineer with 5+ years in application security, DevSecOps, or security tooling, ideally with exposure to AI/ML security challenges. Deep understanding of AI agent architectures, generative AI models, and associated security risks such as prompt injection, adversarial attacks, and autonomous decision-making...


  • Warsaw, Czech Republic Box Inc. Full time

    Who You Are We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box. You have 8+ years of experience in backend development, including leading significant technical initiatives. You’ve worked on mission-critical systems,...


  • Warsaw, Czech Republic Box Inc. Full time

    Lead the technical direction of a large-scale, multi-year React Native migration, transforming legacy systems into a modern, maintainable stack. Design and implement high-impact features that serve enterprise customers with complex use cases and security needs. Define standards and architecture for building frontend-heavy, cross-platform experiences...


  • Warsaw, Czech Republic Box Inc. Full time

    Candidate Profile Essential Skills:  Strong proficiency in Python, including debugging and profiling.  Broad software engineering expertise across multiple languages and paradigms.  Experience with distributed systems, Kubernetes, and cloud environments.  Ability to debug complex system-level issues (threading, networking, VM behavior).  Strong...


  • Warsaw, Czech Republic Box Inc. Full time

    You have 3+ years of experience in backend development. You’ve worked on mission-critical systems, ideally in areas like identity, authentication, OAuth, or access control. You write clean, maintainable code in Java. You have experience operating large-scale distributed systems with high uptime and security expectations. You thrive in a...


  • Warsaw, Czech Republic Box Inc. Full time

    Who you are: We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box. You have 10+ years of professional software development experience. You possess strong knowledge of data structures and software design principles You have...


  • Warsaw, Czech Republic Box Inc. Full time

    Who you are Ideally, you have over 2 years of experience as a software engineering manager, leading teams responsible for high-scale production services. You possess at least 5 years of professional software development experience, contributing to the development of full-stack web applications and/or distributed systems. You excel at aligning and executing...


  • Warsaw, Czech Republic Box Inc. Full time

    Who you are You have 6+ years of experience in software engineering with 2 or more of those years in a management role. You often collaborate with engineering and business leaders across organizations and disciplines. You have led a team of engineers, are able to assess, communicate and drive projects, and deliver strong business outcomes. You have...


  • Warsaw, Czech Republic Box Inc. Full time

    **Our compensation structure is the base salary and equity in the form of restricted stock units. We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box. 5+ years of professional software development experience Have experience...


  • Warsaw, Czech Republic Box Inc. Full time

    Who you are Ideally, you have over 2 years of experience as a software engineering manager, leading teams responsible for high-scale production services. You possess at least 5 years of professional software development experience, contributing to the development of full-stack web applications and/or distributed systems. You excel at aligning and executing...