At Varicent, we’re not just transforming the Sales Performance Management (SPM) market - we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM, 2023 Ventana Research Revenue Performance Management (RPM) Value Index, Gartner Peer Insights, 2024 Gartner SPM Market Guide, and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here’s why you’ll thrive at Varicent:
- Innovate with Purpose: Build impactful solutions for customers worldwide.
- Join Excellence: Work in a diverse, collaborative, and innovative team.
- Shape the Future: Lead in redefining revenue optimization.
- Grow Together: Unlock your potential in a supportive environment.
Join us at Varicent - where your talent and ambition meet limitless opportunities for success!
We're looking for a Principal Offensive Security engineer to be the senior technical authority for our offensive security practice across applications, cloud environments, enterprise systems, and AI-enabled products.
This is an individual contributor role for a recognized expert. You won't just execute tests. You'll decide which security problems matter most, define how the organization approaches them, and coach others to raise the technical bar. You'll work across Engineering, Product, Security, engineering, Legal & Compliance and security leaders will rely on your judgment when making risk decisions.
What You'll Do
Define the Offensive Security Approach
- Frame the problem space: identify which offensive security risks matter most to the business, and set the technical strategy, frameworks, and priorities that guide how multiple teams address them.
- Shape the multi-year technical roadmap for penetration testing, red teaming, AI security validation, and vulnerability research.
- Define the standards, methodologies, and metrics that make offensive security work measurable and tied to risk reduction.
- Anticipate downstream impact, such as emerging attack techniques, architectural shifts, and AI adoption, and bring it into planning before it becomes an incident.
Lead Complex Security Testing and Validation
- Personally lead the most complex and ambiguous engagements across web, API, mobile, cloud, container, and AI-enabled systems.
- Design and guide red team operations, adversary simulations, and purple team exercises.
- Set technical direction and quality bars for external penetration testing partners and vendors, and review their findings and methodology.
- Evolve attack surface management and continuous security validation into a repeatable, scalable capability.
Secure AI-Enabled Products
- Define the organization's approach to AI red teaming for LLM-enabled products and agentic workflows, including threat models, test methodologies, and risk criteria.
- Work with AI and engineering teams to build security into the AI development lifecycle through architecture and design reviews.
- Create scalable, reusable approaches to AI security testing, validation, and risk assessment that other teams can adopt.
Shape Vulnerability Management
- Set the technical direction for vulnerability triage, prioritization, remediation, and retesting, with risk-based practices adopted across engineering.
- Resolve the hardest triage and severity decisions where the right answer isn't clear.
- Evolve the bug bounty and vulnerability disclosure programs, including scope, policy, and researcher engagement.
Influence Without Authority
- Build formal and informal networks across Engineering, Product, Security Operations, Compliance, and Legal to align groups on security priorities.
- Translate technical findings into business risk and present trends and recommendations to senior leadership.
- Mentor and coach security engineers, set the technical standard for the team, and informally guide those who run day-to-day testing.
- Help shape the future of AI-enabled offensive security across the organization.
What You'll Bring
- 12+ years of related Information Security experience with a Bachelor's degree, including 8+ years in Offensive Security and 4+ years in Development or Engineering.
- A track record as a recognized expert whom others seek out guidance, with demonstrated impact on offensive security programs in SaaS and cloud environments.
- Deep, hands-on expertise in penetration testing, red teaming, vulnerability research, vulnerability management, and security testing of AI-enabled products.
- Strong command of application security, cloud security, attack surface management, and secure development practices.
- Experience with modern cloud environments, APIs, web applications, containers, and AI/LLM technologies.
- Proven ability to work through ambiguous, cross-functional problems with high autonomy, and to define the approach rather than follow one.
- Ability to translate technical findings into business risk and influence stakeholders at all levels, including executives.
- Experience coaching and raising the technical capability of others without formal management authority.
- Relevant certifications such as OSCP, OSWE, GXPN, GPEN, CISSP, CCSP, or cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
- Assess the current offensive security landscape and identify the highest-impact problems, not just the most visible ones.
- Build trusted relationships across engineering, security, and business teams.
- Define the technical roadmap and priorities for continuous security validation.
6+ Months
- Establish scalable AI-enabled offensive security methods and standards that other teams adopt.
- Improve vulnerability management effectiveness and remediation outcomes through clearer prioritization and risk-based practices.
- Raise the technical bar of the security team through coaching, reviews, and shared frameworks.
Long-term (7+ months): Mature, Measure & Reduce Risk
- Guide the scaling of autonomous vulnerability management across critical assets and environments.
- Mature AI-enabled red team capabilities and continuous, threat-informed security validation.
- Demonstrate measurable reductions in organizational risk through AI-enabled offensive security capabilities.
For this role, the estimated annual base salary range is between $138,200.00 - $200,000.00 (CAD). In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.
This posting is for a new vacancy.
This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement - not replace - human decision-making.
Overview of Benefits:
- Health & Wellness - Comprehensive medical, dental, and vision coverage tailored to your local needs
- Time Off - PTO and public holidays to rest, recharge, and do what matters most
- Volunteer Days - Dedicated time to give back and support the communities that matter to you
- Ignite Days - Dedicated learning days to support continuous growth, skill development, and professional learning
- Financial - Compensation that reflects your market and your value
- Retirement - Retirement plans designed to help you build long-term financial security
- Tuition Assistance - Invest in your growth with support for continuing education and professional development
- Flexibility - Work where you thrive, with remote and hybrid options available across most regions
Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com
Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact