Remote job
Offensive Security Engineer
Job details
About this role
Role overview Join an early-stage security startup as an Offensive Security Engineer blending traditional hands-on penetration testing with emerging AI/LLM attack research. The position focuses on performing deep, manual assessments while partnering closely with an automated agentic red-teaming platform to validate and improve its findings. It's a fully remote, US-based, full-time role for a self-directed practitioner who enjoys both exploitation work and product-adjacent tooling.
Responsibilities - Plan and execute end-to-end manual penetration tests against web applications, APIs, cloud environments, and network infrastructure. - Review, validate, and refine vulnerability findings produced by the automated red-teaming system, reducing false positives and surfacing missed issues. - Build custom exploits, proof-of-concept tooling, and new methodologies to uncover complex or novel vulnerabilities. - Author detailed assessment reports with prioritized remediation guidance and walk findings through with customer engineering teams. - Research emerging attack techniques, with a particular emphasis on threats targeting AI/LLM applications and agentic systems.
Requirements - Significant hands-on experience conducting professional penetration tests across modern application and infrastructure stacks. - Deep familiarity with exploitation techniques, vulnerability research, and translating raw findings into actionable engineering guidance. - Strong programming or scripting ability to develop tools, automate reconnaissance, and prototype exploits. - Demonstrated written communication skills for producing client-ready reports and runbooks. - Eligibility to work in the United States; visa sponsorship is not offered for this role.
Nice to have - Background in red-teaming AI systems, prompt injection, model supply-chain threats, or LLM-specific security research. - Contributions to open-source security tools, published CVEs, or conference talks. - Experience collaborating with engineering teams to ship security features into a product.
Benefits and work setup - Fully remote within the United States. - Equal opportunity employer with an explicit commitment to diverse and inclusive hiring. - Interview process includes a founder conversation, a self-paced technical security assessment, and a paid one-week work trial.