Offensive Security Engineer

Casco (YC X25)

United States

On-site

USD 180,000 - 220,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Equity package
Learning budget
Modern tech stack
Collaborative environment

Job summary

Casco (YC X25) is seeking an Offensive Security Engineer to lead in AI-assisted penetration testing efforts. Located in the United States, this remote-first position offers a competitive salary of $200,000 and equity package. The ideal candidate has over 3 years in offensive security and strong programming skills with an emphasis on AI security. You will work collaboratively to refine security methodologies, produce thorough assessments, and develop cutting-edge security tools, greatly impacting product security and customer trust.

Qualifications

  • 3+ years of professional penetration testing or offensive security experience.
  • Hands-on experience with AI/LLM security techniques.
  • Proficiency in at least two programming languages including TypeScript.

Responsibilities

  • Conduct white-glove manual penetration tests across various environments.
  • Collaborate with engineering to improve automated security capabilities.
  • Produce clear, actionable security assessment reports.

Skills

Penetration testing experience
AI/LLM security knowledge
Software engineering skills
Understanding of OWASP Top 10
Common penetration testing tools

Tools

Burp Suite
Metasploit
Cobalt Strike

Job description

About The Role

We're seeking an exceptional Offensive Security Engineer to join our fast-growing startup and help shape the future of security testing. This role uniquely combines traditional penetration testing excellence with cutting-edge AI/LLM security expertise. You'll conduct sophisticated manual penetration tests while also working alongside our automated agentic red teaming systems, bridging the gap between human expertise and AI-driven security assessment.

What You’ll Do

Core Responsibilities

  • Execute comprehensive, white-glove manual penetration tests across web applications, APIs, cloud infrastructure, and network environments
  • Review, validate, and enhance findings generated by our agentic red teaming platform
  • Develop custom exploits, tools, and methodologies to identify complex security vulnerabilities
  • Contribute to the development of security-focused software and tooling within our engineering team
  • Collaborate with our engineering team to improve and refine our automated security testing capabilities
  • Produce detailed, actionable security assessment reports with clear remediation guidance
  • Partner with customer engineering teams to ensure security findings are properly understood and addressed
  • Research emerging attack vectors, particularly those involving AI/LLM systems and applications
Technical Leadership
  • Drive innovation in offensive security methodologies, especially at the intersection of traditional pentesting and AI-assisted security assessment
  • Mentor team members on advanced penetration testing techniques
  • Contribute to the company's security strategy and roadmap
  • Participate in the continuous improvement of our security testing frameworks and processes
What We’re Looking For

Required Qualifications

  • 3+ years of professional penetration testing or offensive security experience with a proven track record of identifying critical vulnerabilities
  • Hands-on experience with AI/LLM security, including prompt injection, model manipulation, data poisoning, or other AI-specific attack vectors
  • Strong software engineering skills with proficiency in at least two programming languages, including TypeScript
  • Deep understanding of OWASP Top 10, MITRE ATT&CK framework, and modern attack methodologies
  • Experience with common penetration testing tools (Burp Suite, Metasploit, Cobalt Strike, custom tooling)
  • Expertise in at least two of the following domains:
  • Web application security
  • Cloud security (AWS, Azure, GCP)
  • Network penetration testing
  • API security testing

Preferred Qualifications

  • Experience building or contributing to security tools and frameworks
  • Knowledge of machine learning security, adversarial ML, or AI red teaming
  • Relevant certifications (OSCP, OSWE, OSEP, GPEN, or equivalent)
  • Experience with container security and Kubernetes environments
  • Background in vulnerability research or exploit development
  • Contributions to open-source security projects
  • Experience working in fast-paced startup environments
Skills & Attributes
  • Hacker mindset: Creative, persistent, and always thinking outside the box
  • Technical depth: Ability to dive deep into complex systems and understand their security implications
  • Communication excellence: Can translate technical findings into business risk for various stakeholders
  • Self-directed: Thrives in a startup environment with minimal supervision
  • Continuous learner: Passionate about staying current with evolving threats and technologies
  • Collaborative spirit: Works effectively with cross-functional teams including engineers, product managers, and leadership
What We Offer
  • Remote-first culture: Work from anywhere within the United States
  • Competitive compensation:
    • Base salary: $200,000
    • Equity package with high growth potential
  • Cutting-edge work: Be at the forefront of AI-assisted security testing
  • Growth opportunities: Shape the security posture of a rapidly scaling startup
  • Learning budget: Annual allocation for training, certifications, and conferences
  • Modern tech stack: Access to the latest tools and technologies
  • Impact: Your work directly influences product security and customer trust
  • Collaborative environment: Work alongside talented engineers and security professionals
About Our Security Philosophy

Our mission is to make all software effortlessly secure. We believe the future of security testing lies at the intersection of human expertise and AI capabilities. Our offensive security engineers don't just find vulnerabilities—they help build the next generation of security assessment tools. You'll work in an environment that values both deep technical skills and creative problem-solving, where your insights directly shape how we approach security challenges.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

WebApp Offensive Security Software Engineer
WebApp Offensive Security Software Engineer

Horizon3 • United States

Hybrid
USD 170,000 - 260,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
AI Security Engineer AI Security Unit
AI Security Engineer AI Security Unit

Check Point Software Technologies • Washington

On-site
USD 135,000 - 195,000
Principal Offensive Security Engineer
Principal Offensive Security Engineer

Postman • San Francisco (CA)

On-site
USD 150,000 - 200,000
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software Technologies • Austin (TX)

On-site
USD 140,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • San Francisco (CA)

On-site
USD 150,000 - 210,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Denver (CO)

On-site
USD 120,000 - 190,000
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Triwill Group • United States

On-site
USD 140,000 - 200,000
Remote-first
Competitive salary
Unlimited PTO
+2
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Seattle (WA)

On-site
USD 180,000 - 240,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Washington

On-site
USD 140,000 - 190,000