1

Director Offensive Security Engineer Jobs in California

As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... You thrive working with your direct team and cross-functional partners, especially in bridging the ...

Senior Offensive Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

They are seeking a Senior Offensive Security Engineer to lead their Offensive Security program, focusing on identifying security issues through proactive attacks on services, applications, and ...

Senior Offensive Security Engineer

San Mateo, CA · On-site

$130K - $178K/yr

As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... You thrive working with your direct team and cross-functional partners, especially in bridging the ...

Security Engineer

San Francisco, CA · On-site

$200K - $230K/yr

Security Engineer LiteLLM is the world's most popular AI Gateway, trusted by top companies like ... You'll oversee application-level security, maintain secure CI/CD processes, and focus on offensive ...

Offensive Security Researcher, SEAR Apple's Security Engineering & Architecture (SEAR) organization is responsible for the security of all Apple products. Passionate about safeguarding our users, we ...

Our offensive security operations include thorough security assessments of enterprise-connected ... You will join a DevOps team of Information Security professionals responsible for developing ...

Apple's Security Engineering & Architecture (SEAR) organization is responsible for the security of ... You will help to build offensive capabilities against autonomous systems and anticipate how ...

next page

Showing results 1-20

Director Offensive Security Engineer information

What is the difference between Director Offensive Security Engineer vs Security Architect?

AspectDirector Offensive Security EngineerSecurity Architect
CertificationsOSCP, CISSP, CEHCISSP, SABSA, TOGAF
Work EnvironmentLeading offensive security teams, penetration testing, red teamingDesigning security frameworks, architecture, and policies
Employer & Industry UsageTech companies, cybersecurity firms, government agenciesOrganizations seeking secure infrastructure, enterprise IT

The main difference is that the Director Offensive Security Engineer focuses on offensive security operations like penetration testing and red teaming, while the Security Architect designs overall security frameworks and infrastructure. Both roles require certifications like CISSP, but their responsibilities and focus areas differ significantly.

What are the most commonly searched types of Offensive Security Engineer jobs in California? The most popular types of Offensive Security Engineer jobs in California are:
What are popular job titles related to Director Offensive Security Engineer jobs in California? For Director Offensive Security Engineer jobs in California, the most frequently searched job titles are:
What job categories do people searching Director Offensive Security Engineer jobs in California look for? The top searched job categories for Director Offensive Security Engineer jobs in California are:
What cities in California are hiring for Director Offensive Security Engineer jobs? Cities in California with the most Director Offensive Security Engineer job openings:
Infographic showing various Director Offensive Security Engineer job openings in California as of June 2026, with employment types broken down into 1% As Needed, 79% Full Time, 15% Part Time, 4% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Senior Offensive Security Engineer

Roblox

San Mateo, CA

$130K - $178K/yr

Full-time

Posted 14 days ago


Job description

As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements.

You Have:

  • 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration.
  • Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management.
  • Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems.
  • Platform expertise: implementing and managing breach attack simulation platforms while working with detection engineering teams to validate and improve detection coverage.
  • Deep understanding: of OWASP Top 10 vulnerabilities; common attack techniques; exploit development; post-exploitation methodologies; security assessment frameworks (MITRE ATT&CK, PTES); BAS methodologies; and modern detection stack components (EDR, SIEM, XDR).
  • Knowledge: of security concepts including reverse engineering, cloud security (AWS/Azure/GCP), container security, CI/CD pipeline security, API security, and security metrics development.
  • Certifications: such as OSCP, OSCE, GXPN, or equivalent practical experience.
  • Organizational skills: strong analytical and problem-solving abilities; excellent technical writing for detailed reports; ability to clearly communicate complex technical concepts; self-motivated with a passion for offensive security and detection engineering.

You Will:

  • Perform offensive security assessments: conducting full-stack security assessments across our entire technology stack, including web applications, APIs, cloud infrastructure, and backend systems.
  • Drive detection engineering partnerships: collaborating with detection engineers through purple team exercises, attack simulations, and threat emulation to validate and improve detection coverage.
  • Develop custom tools and frameworks: creating and maintaining security testing tools, BAS frameworks, and automation scripts that enable repeatable testing and quantifiable security improvements.
  • Build security metrics: designing and implementing frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
  • Research and innovate: staying current with latest attack techniques, tools, and methodologies while contributing to both offensive and defensive security improvements.
  • Broadly collaborate: sharing knowledge across security teams and fostering a culture of continuous security improvement.

You Are:

  • Collaborative: You thrive working with your direct team and cross-functional partners, especially in bridging the gap between offensive operations and detection engineering.
  • Thoughtful of build vs. buy decisions: Comfortable with deploying and configuring Open Source software, but you also review what tools are available in the market to make informed decisions about tool selection and development.
  • Comfortable with ambiguity: You can gather data and make informed decisions when there is no clear answer, especially when dealing with novel attack scenarios or detection challenges.
  • Security-minded educator: You excel at translating complex technical findings into actionable insights for various stakeholders across the organization.
  • Metrics-driven: You understand the importance of measuring security improvements and can develop frameworks to quantify the effectiveness of security controls and detection capabilities.
  • Improvement-oriented: You actively seek opportunities to enhance both offensive capabilities and detection coverage, always thinking about the bigger security picture.
  • Adaptable: You stay current with evolving threats and defense mechanisms, adjusting your approach as the security landscape changes.