Offensive Security Engineer

RunBuggy OMI, LLC
Tempe, AZ, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Amazon Web Services Amazon S3 Business Logic Software System Penetration Testing Bash Shell Burp Suite Software as a Service Cyber Security White-Box Testing Identity and Access Management Python (Programming Language)
+16 more
Nmap Open Web Application Security PCI Data Security Standards Phishing Red Team (Cyber Security) Web Applications Scripting Large Language Models Software Security Mitre Att&ck GWAPT Kubernetes Metasploit Graphql Restful APIs Docker

Job description

The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is responsible for proactively identifying, exploiting, and validating vulnerabilities while also partnering with engineering teams to design, implement, and improve security controls across the environment.

This position reports to our Cybersecurity Manager and is a hybrid role (3 days in office per week).

What You Will Be Doing:

  • Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS), and be able to give hardening suggestions.
  • Conduct offensive security engagements, including Red Team operations, threat-based evaluations, and vulnerability research and exploitation against both internal and external-facing systems.
  • Plan and execute black-box, grey-box, and white-box web application penetration tests against RunBuggy production and staging environments.
  • Maintain tooling (Burp, Metasploit, C2 frameworks, custom scripts) for exploitation, detection validation, and security assessments.
  • Conduct API security testing (REST, GraphQL) including authentication bypass, injection, broken object-level authorization (BOLA/IDOR), and business logic flaws.
  • Perform cloud configuration reviews (AWS) and assess infrastructure-level exposure where it intersects with web application attack surfaces.
  • Produce clear, risk-ranked findings reports with reproducible proof-of-concept and actionable remediation guidance for both technical and non-technical audiences.
  • Collaborate with engineering to validate fixes and re-test remediated vulnerabilities.
  • Perform social engineering exercises (phishing, credential harvesting), where applicable.
  • Contribute to bug bounty triage, third-party assessment coordination, and security tooling selection.
  • Support compliance efforts (SOC 2, PCI DSS) by providing evidence and attestation tied to pen test scope and outcomes.
  • Stay current on emerging attack techniques and translate threat intelligence into test cases relevant to RunBuggy’s stack.
  • Other duties as assigned.

Requirements

Do you have a Bachelor’s degree?, What You Bring to the Team by Way of Skills and Experience:

  • Bachelor’s degree in Cybersecurity or related field required.
  • 3+ years of hands-on web application penetration testing experience in a professional or consulting capacity.
  • Passion and demonstrated experience for challenging security assumptions.
  • Deep familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for LLMs.
  • Proficiency with standard tooling: Burp Suite, OWASP ZAP, Nmap, Metasploit, SQLmap, Nikto.
  • Demonstrated ability to exploit and document authentication/authorization flaws, injection vulnerabilities, XXE, SSRF, deserialization issues, and insecure direct object references.
  • Strong written communications: findings reports must be usable by both developers and executives.
  • Experience testing RESTful and/or GraphQL APIs.
  • Experience with AWS environment security assessment (IAM misconfiguration, S3 exposure, Lambda attack surface).
  • Scripting proficiency in Python, Bash, or JavaScript for custom tooling and automation.
  • Familiarity with automotive, logistics, or fintech regulatory requirements (PCI DSS, SOC 2 Type II).
  • Prior experience in a startup or high-growth SaaS environment where speed and security have to coexist.

Certificates, Licenses, and/or Registrations:

  • OSCP, GWAPT, eWPT, or equivalent. CEH is accepted but is less weighted than practical certs., To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Benefits & conditions

Pulled from the full job description

  • Pet insurance
  • Paid parental leave
  • AD&D insurance
  • Parental leave
  • Health insurance
  • Vision insurance
  • Dental insurance, * Highly competitive medical, dental, vision, Life w/ AD&D, Short-Term Disability insurance, Long-Term Disability insurance, pet insurance, identity theft protection, and a 401(k) retirement savings plan.
  • Employee wellness program.
  • Employee rewards, discounts, and recognition programs.
  • Generous company-paid holidays (12 per year), vacation, and sick time.
  • Paid paternity/maternity leave.
  • Monthly connectivity/home office stipend if working from home 5 days a week.
  • A supportive and positive space for you to grow and expand your career.

About the company

RunBuggy is the most technically advanced automotive logistics platform on the market. Period.

Backed by Porsche Ventures and Hearst Ventures, RunBuggy is transforming the way cars move. Our cutting-edge technology is trusted by some of the largest OEMs, captive finance companies, and automotive lenders in the world to streamline vehicle transportation at scale.

RunBuggy’s end-to-end platform connects car shippers and haulers in real time - eliminating the friction of traditional load boards and costly custom software. For shippers, RunBuggy integrates directly into existing management systems, reducing transportation costs and accelerating delivery timelines. For transporters, we offer a smarter, more profitable way to find, accept, and manage loads - all from a single app.

Since launching in 2019, RunBuggy has grown to over 190 team members, facilitated the movement of hundreds of thousands of vehicles, and attracted tens of thousands of transporters across the U.S.

We’re not just building a better logistics platform - we’re redefining the future of automotive transportation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

3:12 min

Configuring Docker images, networking protocols, and persistent storage volumes

Francesco Ciulla Francesco Ciulla · World Congress 2024

Videos

See all

Related articles

See all