Source Job

$165,000–$200,000/yr
US Unlimited PTO

  • Lead the long-term technical strategy for offensive security, including red teaming and adversary simulations.
  • Conduct deep-dive vulnerability research and partner with DevOps to build automated security guardrails.
  • Mentor senior and mid-level engineers to foster a security-minded development culture.

Offensive Security AWS Security Application Security Automation

20 jobs similar to Staff Offensive Security Engineer

Jobs ranked by similarity.

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

Global Unlimited PTO

  • Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.

Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.

North America Unlimited PTO

  • Identify and validate realistic attack paths across applications and infrastructure.
  • Develop safe proof-of-concept exploits to demonstrate security risks.
  • Partner with engineering teams to validate fixes and improve security posture.

A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.

Canada 4w PTO

  • Lead complex offensive security projects and adversary simulation activities.
  • Develop stealthy tools and automation to continuously evolve offensive capabilities.
  • Collaborate with cyber defense and insider threat teams to improve detection and response.

The company operates at the forefront of offensive cybersecurity within a large, complex enterprise environment. They emphasize continuous learning, innovation, and collaboration across diverse teams.

$129,500–$144,300/yr
Canada Unlimited PTO

  • Lead security architecture across AWS and colocation, defining secure patterns and controls.
  • Partner with engineering teams to threat model, review designs, and promote secure-by-design.
  • Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.

NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.

$120,000–$150,000/yr
US Unlimited PTO

  • Plan and conduct offensive security engagements, effectively communicating findings to stakeholders.
  • Build scripts, tools, or methodologies to enhance services and stay current with adversary tradecraft.
  • Serve as a subject matter expert and mentor less experienced staff while contributing to training courses.

SpecterOps provides offensive security assessment services, including red team assessments and penetration tests, for large commercial enterprises. The company fosters a culture of passionate curiosity and continuous improvement, with a remote team that values empathy and transparency.

$145,000–$170,000/yr
US Unlimited PTO

  • Plan and conduct offensive security engagements of varying size, scope, and focus.
  • Communicate findings and recommendations to technical and executive stakeholders through reports and presentations.
  • Build scripts, tools, or methodologies to enhance offensive services and mentor less experienced staff.

SpecterOps is an offensive security consultancy that delivers red team assessments, penetration tests, and adversary simulation services to large commercial enterprises. The company fosters a culture of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency.

$140,000–$165,000/yr
US

  • Own cloud security posture across AWS environment using Wiz and AWS-native services.
  • Harden CI/CD pipelines, manage vulnerability intake, prioritization, and remediation.
  • Build automation, instrument telemetry, and operate WAF for cloud and application security.

Beyond Finance helps everyday Americans escape debt through compassionate, individualized care and supportive technology. They are a rapidly growing organization with over 1 million clients served and a culture focused on compliance and ethics.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

$141,000–$221,000/yr
US Unlimited PTO

  • Review system designs and implementations to identify security issues and align with best practices.
  • Develop cloud security architecture and implement automated security testing tools.
  • Promote DevSecOps principles through CI pipeline integration and Infrastructure as Code scanning.

Iterable is the leading AI-powered customer engagement platform that helps brands like Redfin and SeatGeek create dynamic experiences. With nearly 1,200 clients globally and a diverse workforce, we foster a culture of innovation and inclusion, recognized as one of Inc's Best Workplaces.

LATAM

  • Plan and execute realistic attack scenarios simulating sophisticated threat actors' TTPs.
  • Perform penetration testing of networks, applications, and systems using tools like Burp Suite, Metasploit, Cobalt Strike.
  • Prepare detailed reports and collaborate with blue teams to improve incident detection and response.

Insight Assurance is a global audit firm delivering next-generation cybersecurity and compliance services across SOC 2, ISO 27001, PCI DSS, and more. With 170+ professionals, it is one of the fastest-growing global audit firms serving nearly 2,000 clients.

$120,000–$150,000/yr
US Unlimited PTO

  • Plan and execute red team assessments, penetration tests, and advanced security engagements for large organizations.
  • Communicate attack paths, findings, and strategic insights to technical and executive stakeholders.
  • Develop scripts, tools, and methodologies to improve offensive security capabilities and service delivery.

They are a specialized consulting firm focused on adversary simulation and offensive security. They maintain a remote-first culture with an emphasis on continuous improvement, transparency, and empathy.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

Germany

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
  • Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.

Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.

US Unlimited PTO

  • Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
  • Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
  • Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.

Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.

$140,000–$140,000/yr
US Unlimited PTO

  • Conduct sophisticated security assessments across client environments, identifying vulnerabilities missed by conventional approaches.
  • Develop targeted attack plans based on bespoke hypotheses and client-specific objectives.
  • Produce actionable, threat-based reports that translate technical discoveries into meaningful security improvements.

Jobgether uses AI-powered matching to connect candidates with roles. It is a platform focused on efficient, objective hiring, with a culture emphasizing technical excellence, radical candor, and collaboration.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$191,250–$258,750/yr
US

  • Architect and automate security workflows across CI/CD and compliance operations.
  • Integrate and monitor security tooling within automated pipelines.
  • Build automation for compliance and ATO artifacts.

Our partner is a technology company that builds secure, automated cloud environments for mission-critical programs. They offer a fully remote work model with a focus on autonomy and work-life balance.

UK

  • Improve and maintain AWS security configurations including IAM, GuardDuty, and CloudTrail.
  • Manage security tooling across the organization including EDR, MDM, DLP, and respond to SOC alerts.
  • Lead vulnerability management activities, coordinate patching, and support compliance assessments.

This company is a fully remote, international technology firm specializing in cloud and operational security. It has a diverse team of over 40 nationalities and a culture that values curiosity, ownership, and continuous improvement.