> Markdown version of [/jobs/ext/2634486-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/2634486-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Engineer - **Company:** Menlo Security - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $170,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Business Logic, Software System Penetration Testing, User Authentication, Static Program Analysis, Distributed Systems, Open Web Application Security, Red Team (Cyber Security), Web Applications, Software Security - **Published:** August 4, 2026 - **Apply:** https://www.workingnomads.com/job/go/1769795/ ## About the Role * 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities. * Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10. * Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk. * Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output. * Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams. * A belief that AI is reshaping work, you instinctively use it to accelerate everything you do. ## Description * Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact. * Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis. * Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks. * Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment. * Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities. * Maintain a habit of using AI tools to think, build, and ship faster-it's your default, not an afterthought. Success Looks Like: * Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation. * Security gaps identified that were not detected by existing tools or processes. * High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths. * Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Algorithm That Nearly Killed Me: When Testing Isn't Enough](https://www.wearedevelopers.com/videos/2110-the-algorithm-that-nearly-killed-me-when-testing-isn-t-enough) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)