|
TTM Technologies, Inc. - Publicly Traded US Company, NASDAQ (TTMI) - Top-5 Global Printed Circuit Board Manufacturer
About TTM
TTM Technologies, Inc. is a leading global manufacturer of technology products, including mission systems, radio frequency ("RF") components, RF microwave/microelectronic assemblies, and technologically advanced printed circuit boards ("PCB"s). TTM stands for time-to-market, representing how TTM's time-critical, one-stop design, engineering and manufacturing services enable customers to reduce the time required to develop new products and bring them to market. Additional information can be found at www.ttm.com Job Title: IT Security Vulnerability Assessment Summary We are seeking a hands-on Offensive Security Engineer to join our security team. In this hybrid role, you will operate as a penetration tester, offensive security engineer, and vulnerability validator - proactively identifying, exploiting, and validating weaknesses across our applications, infrastructure, cloud environments, and people. You will partner closely with engineering, DevOps, and detection/response teams to ensure findings are real, prioritized correctly, and remediated effectively. This is an ideal role for someone who loves breaking things, building tooling to break things at scale, and helping defenders close the gap. Duties and Responsibilities:
- Plan and execute penetration tests against web applications, APIs, cloud environments (AWS/Azure/GCP), networks, and internal systems.
- Conduct red team-style engagements simulating real-world adversary tactics, techniques, and procedures (TTPs) aligned with frameworks like MITRE ATT&CK.
- Deliver clear, actionable reports with reproducible steps, business impact, and remediation guidance.
- Offensive Engineering
- Build, maintain, and improve internal offensive security tooling, automation, and attack infrastructure.
- Develop custom exploits, proof-of-concept code, and scripts to test controls at scale.
- Integrate offensive testing into CI/CD pipelines (continuous attack simulation, automated recon, etc.).
- Contribute to purple team exercises to validate and improve detection and response capabilities.
- Vulnerability Validation & Triage
- Validate vulnerabilities reported by scanners, bug bounty programs, third-party assessments, and internal researchers to eliminate false positives and confirm exploitability.
- Reproduce reported issues, assess real-world impact, and assign accurate severity (CVSS, business risk).
- Partner with engineering teams to verify fixes and re-test remediations.
- Help prioritize the vulnerability backlog based on exploitability and business context.
- Collaboration & Enablement
- Work with product and engineering teams to provide secure design guidance and threat modeling support.
- Mentor engineers on secure coding and common attack patterns.
- Contribute to security training, internal write-ups, and lessons learned.
Qualifications
- 2+ years of hands-on experience in penetration testing, red teaming, or offensive security (adjust based on seniority).
- Strong knowledge of web application security (OWASP Top 10), network penetration testing, and common exploitation techniques.
- Proficiency with offensive tooling such as Burp Suite, Metasploit, Nmap, BloodHound, Cobalt Strike (or equivalents), Impacket, etc.
- Scripting/programming experience in at least one of: Python, Go, PowerShell, Bash, or similar.
- Experience validating vulnerabilities from scanners (e.g., Nessus, Qualys, Snyk, Wiz, Burp) and distinguishing true positives from noise.
- Solid understanding of cloud security concepts and at least one major cloud provider (AWS, Azure, or GCP).
- Strong written and verbal communication skills - able to translate technical findings into business risk.
Preferred
- Industry certifications such as OSCP, OSEP, OSWE, CRTO, GPEN, GXPN, or equivalent.
- Experience with container/Kubernetes security, CI/CD pipeline attacks, or IaC review.
- Exploit development, reverse engineering, or malware analysis experience.
- Bug bounty participation, CVE credits, open-source security contributions, or conference talks.
- Familiarity with detection engineering, SIEM, or EDR platforms (for purple teaming).
Compensation and Benefits:
TTM offers a variety of health and well-being benefit programs. Benefit options include medical, dental, vision, 401K, Flexible Spending Account, Health Savings Account, accident benefits, life insurance, disability benefits, paid vacation & holidays. Benefits are available 1st of the month following date of hire. Compensation for roles at TTM Technologies varies depending on a wide array of factors including but not limited to the specific office location, role, skill set and level of experience. As required by local law, TTM provides a reasonable range of compensation for roles that may be hired in New York, California and Colorado. For California-based roles, compensation ranges are based upon specific physical locations. Export Statement: Must comply with TTM Export Control Policies and Procedures and all applicable laws including ITAR, EAR and OFAC including but not limited to: a) being able to identify ITAR product on the manufacturing floor and understand that access to these products and related technical data is restricted to only US Citizens and US Permanent Residents; b) recognition ofForeign Person visitors by badge differentiation; c) understand and follow authorization procedures for bringing foreign visitors into facilities (VAL); d) understand the Export and ITAR requirements for shipments leaving the US; e) manage vendor approvals for ITAR manufacturing and services. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, citizenship, disability or protected veteran status.
|