Talent.com
McMaster-Carr
Senior Offensive Security Engineer - Internal AuditMcMaster-Carr • Chicago, IL, United States
Senior Offensive Security Engineer - Internal Audit

Senior Offensive Security Engineer - Internal Audit

McMaster-Carr • Chicago, IL, United States
12 days ago
Job type
  • Full-time
Job description

Senior Offensive Security Engineer - Internal Audit

Chicago, IL (Elmhurst)

Who We Are

McMaster-Carr is a leading e-commerce company that industrial customers have trusted for 125 years. Our products help them get manufacturing lines back up quickly, keep operations running smoothly, and prototype the next generation of innovative solutions. We earn and keep that trust by offering the right products, making them easy to find, and delivering them fast, so customers can solve problems with greater speed, precision, and ease.

Our industry-leading e-commerce experience, indispensable product selection, and world-class service bring hundreds of thousands of customers to mcmaster.com each day. But we're never standing still. Curious, exceptional people are at the heart of our evolution. They turn new challenges and disruptive technologies into opportunities to refine our operations, expand our offering, and deliver a better experience for every customer.

What You Will Do

McMaster-Carr is seeking a Senior Offensive Security Engineer to build and operate an independent security assurance capability within Internal Audit. Using penetration testing, adversary emulation, and purple-team techniques, you will evaluate whether our cybersecurity controls work as intended against realistic scenarios.

This is not a conventional penetration-testing role focused only on finding vulnerabilities. As a member of McMaster-Carr's Internal Audit team, your work will help determine whether controls prevent attacks, whether monitoring produces meaningful alerts, whether response processes work, and where security investments should be strengthened. You will translate technical findings into practical risk insight and solutions for Information Security, business leaders, executive management, and the Audit Committee.

Work is independent yet collaborative with strong governance. You will partner closely with Information Security while remaining organizationally independent from the teams responsible for designing and operating the controls you assess.

  • Design and execute risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments.
  • Test whether preventive, detective, and responsive security controls perform as expected under realistic attack Evaluate attack paths, control weaknesses, detection coverage, alert quality, and the effectiveness of incident-response procedures.
  • Collaborate with Security Operations and other technical teams during purple-team exercises to validate detection and response
  • Develop test plans, objectives, techniques, targets, safeguards, and rules of engagement for management approval before execution.
  • Translate technical findings into risk-based remediation recommendations that help leaders of technical teams, Internal Audit leadership, executive management and the Audit Committee prioritize security improvements and
  • Build a repeatable, continuously improving offensive-security assurance program informed by a growing understanding of our environment.
  • Partner with external security firms when specialist expertise or independent corroboration is

Who You Are

We are seeking bright, curious, and ambitious individuals eager to make an impact. Ideal candidates have:

  • 5+ years of relevant offensive security experience, including at least three recent years conducting penetration tests, red team engagements adversary emulation exercises, or purple team assessments in complex military or civilian environments.
  • A four-year college degree
  • Demonstrated ability to independently scope, plan, execute, document, and clearly communicate technically sophisticated security assessments to both engineering and executive-level audiences.
  • Broad knowledge of enterprise attack surfaces, including hands-on experience with several of the following domains: identity systems (LDAP, IAM), operating systems (Windows and Linux), network infrastructure, cloud platforms, web applications and APIs, endpoint systems, and security monitoring tools.
  • Practical experience identifying and validating exploitable attack chains, bypassing or testing security controls, and determining whether detection and response mechanisms function as intended.
  • Strong scripting or automation skills and the ability to adapt tools and techniques to assess unfamiliar environments effectively.
  • Ability to operate safely and effectively in production-sensitive environments while maintaining strict adherence to rules of engagement and approved scope.
  • Sound judgment, discretion, and a disciplined approach to handling privileged information and sensitive findings.
  • Excellent written and verbal communication skills that translate technical weaknesses into clear business impact and remediation priorities for both engineers and senior leaders.
  • A collaborative style that builds trust with Security and Systems teams while maintaining the objectivity required of an independent assurance function.
  • A track record of taking initiative, identifying high-impact areas for investigation, and driving work through remediation and retesting.

Compensation

Total cash compensation generally ranges from $170,000-$250,000 and includes profit sharing based on company performance.

Growth & Learning

  • 100% tuition reimbursement
  • Informal and formal mentorship
  • Employee resource groups

Health & Wellbeing

  • Medical, dental, pharmacy and vision plans without monthly premiums
  • Inclusive, all-gender benefits

Family & Future

  • Paid parental leave for all new parents
  • Adoption and surrogacy assistance
  • First-time home buyer assistance
  • Industry-leading company-funded retirement accounts

Time Off

  • Paid vacation and personal time

Equal Opportunity Employer

We are proud to be an Equal Opportunity Employer and dedicated to providing employees a workplace with reasonable accommodations and free of discrimination, harassment, and retaliation. At McMaster-Carr, we do not make employment decisions based on age, ethnicity, citizenship status, military status, gender identity and expression, race, religion, disability status, marital status, sexual orientation, or any other legally protected group.

This position is not eligible for work authorization sponsorship by McMaster-Carr.

Data We Collect

We may collect professional, education and employment-related data, and any assessments made throughout the recruiting process, to evaluate candidacy for employment. To communicate with job applicants, we may collect applicant names, contact information, and other personal identifiers, including those outlined in the California customer records statute. Through voluntary disclosure, we may also collect protected classifications under federal or California law (e.g., race, gender, etc.). For additional details about the personal information we collect and its uses, please click here.

Create a job alert for this search

Senior Offensive Security Engineer - Internal Audit • Chicago, IL, United States

Similar jobs

IT Auditor Cloud and Cyber -Chicago, IL -Hybrid

FinTrust Connect LLCChicago, IL, United States
Full-time

IT Auditor Cloud and Cyber -Chicago, IL -Hybrid.Join our Talent Community for Chicago.Banks and broker dealers in this market are hiring auditors with cloud and cyber depth and strong SOX testing e... Show more

 • Promoted

Audit and Compliance Analyst

The Alden NetworkChicago, IL, United States
Full-time

Location: 4200 W Peterson Chicago IL.Hiring Manager: VP of Internal Audit & Finance Compliance.Plan and execute operational, compliance, and financial related audits and reviews.Perform walkthrough... Show more

 • Promoted

Senior Compliance Analyst - FIU

Interactive BrokersChicago, IL, United States
Full-time

Interactive Brokers Group, Inc.Greenwich, CT, USA, with offices in over 15 countries.We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technolo... Show more

 • Promoted

Senior Manager, Security Operations & Engineering

UL Standards and EngagementEvanston, IL, United States
Full-time

Sr Manager Security Operations & Engineering.We have an exciting opportunity for a Sr Manager Security Operations & Engineering at UL Research Institutes and UL Standards & Engagement, based in our... Show more

 • Promoted

Cybersecurity IT Audit Manager

Plante MoranChicago, IL, United States
Full-time

Our "we-care" culture is more than just a motto; it's a promise.From day one, we prioritize your growth, well-being, and success.You can count on us to support your career journey and help you achi... Show more

 • Promoted

Strategic Alliance Manager III, Security, Google Cloud

GoogleChicago, IL, United States
Full-time

Strategic Alliance Manager III, Security, Google Cloud.Advanced experience owning outcomes and decision making, solving ambiguous problems and influencing stakeholders; deep expertise in domain.Min... Show more

 • Promoted

Senior Security Engineer (Remote)

AbbVieChicago, IL, United States
Remote
Full-time

Come to work each day with an inclusive and collaborative technology team.As a Senior Security Engineer in AbbVie Business Technology Solutions (BTS) you will have opportunities to contribute to th... Show more

 • Promoted

Sr Director, Insider Threat Programs

Veracity SolutionsChicago, IL, United States
Full-time

Sr Director, Insider Threat Programs.Bachelor's degree in cybersecurity, computer science, engineering, or a related field preferred.Extensive experience (10+ years) in cybersecurity with a focus o... Show more

 • Promoted

Senior Manager - Blockchain Security & Digital Asset Infrastructure

EYChicago, IL, United States
Full-time

Senior Manager - Blockchain Security & Digital Asset Infrastructure.Location: New York Other locations: Anywhere in Region Salary: Competitive Date: Jul 20, 2026.EY's Blockchain & Digital Assets pr... Show more

 • Promoted

Security Technology Lead

Concord IT SystemsChicago, IL, United States
Full-time

Job Description:Project Overview: Company is looking for an enthusiastic, innovative Privileged Access Management Engineer who can design and development of cybersecurity tools and technology along... Show more

 • Promoted

Senior Auditor

Stepan CompanyNorthbrook, IL, United States
Full-time

Stepan Company is seeking an experienced and motivated Senior or Lead Internal Auditor to join our Internal Audit function.This role plays a critical part in strengthening Stepan's governance, risk... Show more

 • Promoted

Technology Auditor, Internal Audit

GoogleChicago, IL, United States
Full-time

Technology Auditor, Internal Audit.Technology Auditor, Internal Audit.Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowled... Show more

 • Promoted

Security & Risk Consulting Client Engagement Director - 1898 & Co.

Burns & McDonnellChicago, IL, United States
Full-time

Security & Risk Consulting Client Engagement Director - 1898 & Co.Burns & McDonnell, as we lead the charge in securing critical infrastructure and shaping the future of industrial cybersecurity.Our... Show more

 • Promoted

Specialist Solutions Engineer - Security

AHEADChicago, IL, United States
Full-time

AHEAD builds platforms for digital business.By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digi... Show more

 • Promoted

Senior Auditor

FHLBank ChicagoChicago, IL, United States
Full-time

At the Federal Home Loan Bank of Chicago, employees come first - that's why we offer a highly competitive compensation and bonus package, and access to a comprehensive benefits program designed to ... Show more

 • Promoted

Audit Specialist - Risk and Control Enhancement

Northern TrustChicago, IL, United States
Full-time

Audit Services provides independent assurance over how Northern Trust manages risk, strengthens controls, and supports responsible growth.This role will bring deep operational risk and audit expert... Show more

 • Promoted

Information Security Engineer

Gulf Coast Automation GroupChicago, Illinois, United States
$105,000.00–$110,000.00 yearly
Remote
Full-time +1
Quick Apply

Information Security Engineer – Security Automation and Response.TalentFish is casting a line for an Information Security Engineer – Security Automation and Response.This is a Direct Hire role, ful... Show more

Remote Senior Solutions Architect - Enterprise & Security

CloudflareChicago, IL, United States
Remote
Full-time

A leading technology firm in Chicago is seeking a Solutions Architect to drive technical sales and customer success.This senior role requires significant experience in cloud security and enterprise... Show more

 • Promoted

Sr. Director, Information Security & Cloud Operations

ProlaioChicago, IL, United States
Full-time

Director, Information Security & Cloud Operations.Prolaio believes that continuous learning and collaboration can make a significant difference in how heart care is administered.We are creating sma... Show more

 • Promoted

Senior Audit Project Manager - Information Security

U.S. BankChicago, IL, United States
Full-time

Bank, we're on a journey to do our best.Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed.We b... Show more