Offensive Security Engineer San Francisco, CA

Parameter

San Francisco (CA)

Hybrid

USD 150,000 - 210,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Parameter builds AI agents that perform offensive security work, running autonomous penetration tests against production apps and cloud environments to find IDORs, broken access control, XSS, and misconfigurations.

As a member of a small team, you’ll turn your methodology into agent capabilities, lead customer engagements, and contribute to vulnerability research while working onsite in San Francisco.

Qualifications

  • 3+ years of hands-on offensive security: web app pentesting, red teaming, or bug bounty work.
  • Deep knowledge of web vulnerability classes, especially access control, authentication, and business logic flaws.
  • Cloud security experience across AWS or GCP: IAM, misconfiguration, escalation paths.
  • You write code and build your own tooling; we care about what you build.
  • Ability to write clearly for engineers and executives; unclear findings won’t get fixed.
  • Bonus: OSCP, OSWE, CVEs, bug bounty leaderboard, talks.

Responsibilities

  • Run manual penetration tests against customer web applications, APIs, and cloud infrastructure.
  • Translate your methodology into agent capabilities: new attack modules, detection logic, and verification steps.
  • Validate and triage agent findings before they reach customers; you are the quality bar.
  • Lead the technical side of customer engagements, including scoping calls and findings walkthroughs.
  • Contribute to vulnerability research and responsible disclosure work, a core part of our market approach.

Skills

Web pentesting
Red teaming
Bug bounty
Cloud security

Tools

TypeScript

Job description

Parameter builds AI agents that do offensive security work. Our agents run autonomous penetration tests against production applications and cloud environments, finding IDORs, broken access control, XSS, and infrastructure misconfigurations that scanners miss and that human pentest firms only look for once or twice a year.

We are not a theoretical security company. Our team has responsibly disclosed real, high-severity vulnerabilities to well-known technology companies, and our findings are the front door to most of our customer relationships.

You are the person whose expertise gets encoded into the product. You'll do real offensive work against customer environments, then turn your methodology into agent capability.

The title points at where you'll spend most of your time. Expect the rest of the week to go wherever the work is: agent systems one day, the product the next, a customer call or a report that has to go out after that. We are small enough that everyone works across every product, and we hire people who want that.

What you’ll do
  • Run manual penetration tests against customer web applications, APIs, and cloud infrastructure
  • Translate your methodology into agent capabilities: new attack modules, detection logic, and verification steps
  • Validate and triage agent findings before they reach customers. You are the quality bar
  • Lead the technical side of customer engagements, including scoping calls and findings walkthroughs
  • Contribute to our vulnerability research and responsible disclosure work, which is a core part of how we go to market
What we’re looking for
  • 3+ years of hands‑on offensive security: web application pentesting, red teaming, or serious bug bounty work
  • Deep knowledge of web application vulnerability classes, particularly access control, authentication, and business logic flaws
  • Cloud security experience across AWS or GCP: IAM, misconfiguration, privilege escalation paths
  • You write code and build your own tooling rather than only running other people's. We're a TypeScript shop, but we care more that you build than what you've built in
  • Ability to write clearly for both engineers and executives. Findings that nobody understands do not get fixed
  • Bonus: OSCP, OSWE, published CVEs, bug bounty leaderboard placement, or conference talks
Interview process
  • Intro call with a founder (30 minutes)
  • Technical deep dive on your past work (60 minutes)
  • Paid work trial or take-home, scoped to roughly one day
  • Onsite in San Francisco with the team
  • References and offer

We move quickly. Our target is an offer within two weeks of first contact. Small team, high trust, extremely fast. If you want to see your work in front of customers within days, this is that.

This role is onsite in San Francisco. You must be authorized to work in the US; we are not able to sponsor visas at this time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Member of Technical Staff, Generalist San Francisco, CA
Member of Technical Staff, Generalist San Francisco, CA

Parameter • San Francisco (CA)

Hybrid
USD 140,000 - 180,000
Member of Technical Staff, Infrastructure San Francisco, CA
Member of Technical Staff, Infrastructure San Francisco, CA

Parameter • San Francisco (CA)

Hybrid
USD 180,000 - 230,000
Lead Offensive Security Engineer — Real-World Pen Testing
Lead Offensive Security Engineer — Real-World Pen Testing

Parameter • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Sales Development Representative San Francisco, CA
Sales Development Representative San Francisco, CA

Parameter • San Francisco (CA)

Hybrid
USD 60,000 - 90,000
Member of Technical Staff, AI Engineer San Francisco, CA
Member of Technical Staff, AI Engineer San Francisco, CA

Parameter • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Offensive Security Engineer
Offensive Security Engineer

Calif • United States

Remote
USD 120,000 - 180,000
Equipment allowance
Annual fun allowance
Internet/data allowance
+4
Autonomous Offensive AI Engineer for Pentest Agents
Autonomous Offensive AI Engineer for Pentest Agents

Parameter • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Offensive Security Engineer - Red Team
Offensive Security Engineer - Red Team

ClearanceJobs • Washington

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Offensive Security & Code Analysis Engineer
Offensive Security & Code Analysis Engineer

Districttechgroup • Washington

On-site
USD 80,000 - 120,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+1