Senior Offensive Security Engineer
Jobgether · United States · $170K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
The Senior Offensive Security Engineer will proactively identify and validate security risks through realistic attack simulations across applications and infrastructure. They will partner with engineering teams to demonstrate vulnerabilities, validate fixes, and improve the overall security posture using AI-powered workflows.
What they look for
Requirements
The ideal candidate possesses 5+ years of experience in offensive security, penetration testing, or red teaming with deep expertise in modern application environments. They must be proficient in identifying real-world vulnerabilities and leveraging AI tools to accelerate security research and exploit development.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Offensive Security Engineer based in the United States.
This role offers the opportunity to operate at the forefront of application and product security within a fast-growing technology environment. You will think like an attacker to uncover vulnerabilities, validate real-world risks, and strengthen security across critical systems. The position combines offensive security expertise with modern AI-powered workflows to accelerate research, testing, and exploit development. You will work closely with engineering teams to identify impactful security gaps and ensure effective remediation. The role provides broad access to applications, source code, and infrastructure, allowing you to make meaningful security improvements. You will help shape offensive security practices while protecting products used by millions of consumers.
\n
Accountabilities: The Senior Offensive Security Engineer will be responsible for proactively identifying and validating security risks through realistic attack simulations. The role focuses on uncovering vulnerabilities that create meaningful business impact and improving the overall security posture through collaboration and technical expertise.
- Identify, validate, and demonstrate realistic attack paths across applications, infrastructure, and internal systems.
- Analyze complex, multi-language codebases using both manual techniques and AI-assisted approaches to discover vulnerabilities and generate exploit hypotheses.
- Develop safe proof-of-concept exploits demonstrating risks such as unauthorized access, privilege escalation, data exposure, and business logic flaws.
- Partner with engineering teams to validate fixes, confirm vulnerabilities are fully resolved, and identify similar security patterns across the environment.
- Document findings with clear technical evidence, root cause analysis, business impact, and actionable remediation guidance.
- Continuously improve offensive security methodologies, testing coverage, and internal security capabilities.
- Leverage AI tools as part of daily workflows to accelerate security research, analysis, and delivery.
Requirements:
The ideal candidate brings deep offensive security experience, strong technical knowledge of modern application environments, and the ability to communicate complex security findings effectively. You should be comfortable combining security expertise with emerging AI technologies to improve testing efficiency and coverage.
- 5+ years of experience in offensive security, application security, penetration testing, or red team environments with proven success identifying real-world vulnerabilities.
- Strong expertise in web applications, APIs, authentication, authorization, distributed systems, and OWASP Top 10 security risks.
- Experience creating proof-of-concept exploits that demonstrate practical business impact rather than theoretical vulnerabilities.
- Proficiency using AI tools for vulnerability discovery, exploit development, code analysis, and security research while independently validating results.
- Strong understanding of secure development practices and vulnerability remediation strategies.
- Excellent communication skills with the ability to explain technical issues, attack paths, and recommendations to engineering stakeholders.
- A proactive mindset with a strong interest in using AI to improve productivity, problem-solving, and security research.
Benefits:
- Competitive base salary starting at $170,000+, depending on experience.
- Incentive Stock Option (ISO) grant eligibility, subject to approval.
- Fully remote work environment with flexibility across the United States and Canada.
- Comprehensive medical, dental, and vision coverage with premiums fully covered for employees and partially covered for dependents.
- Unlimited paid time off and sick leave, plus 14 company holidays.
- 100% 401(k) match up to 4% with immediate vesting.
- Competitive parental leave benefits for all parents.
- $1,000 remote workspace setup subsidy.
- Monthly $100 allowance for internet and phone expenses.
- Summer Friday half-days during the summer months.
- Commuter benefits for employees who choose to work from office locations.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1