1

Director Offensive Security Engineer Jobs in California

As a Security Engineer you will identify and drive impactful projects to improve the security of ... Help run penetration testing and offensive security exercises against Figma's AI infrastructure ...

Security Engineer

San Francisco, CA · On-site

$230K - $390K/yr

... offensive security. You can apply that expertise across unfamiliar systems and emerging threats ... Software Engineering and Systems Thinking. You're comfortable reading and writing code ...

As a Security Engineer in AAI, you will apply deep domain expertise to solve hard, real-world ... offensive security, mobile/platform security, or digital forensics * Extensive knowledge of ...

Showing results 41-60

Director Offensive Security Engineer information

What is the difference between Director Offensive Security Engineer vs Security Architect?

AspectDirector Offensive Security EngineerSecurity Architect
CertificationsOSCP, CISSP, CEHCISSP, SABSA, TOGAF
Work EnvironmentLeading offensive security teams, penetration testing, red teamingDesigning security frameworks, architecture, and policies
Employer & Industry UsageTech companies, cybersecurity firms, government agenciesOrganizations seeking secure infrastructure, enterprise IT

The main difference is that the Director Offensive Security Engineer focuses on offensive security operations like penetration testing and red teaming, while the Security Architect designs overall security frameworks and infrastructure. Both roles require certifications like CISSP, but their responsibilities and focus areas differ significantly.

How much do Director Offensive Security Engineers make?

Director Offensive Security Engineers typically earn between $130,000 and $200,000 annually, depending on experience, certifications, and the size of the organization. They often oversee security teams, develop penetration testing strategies, and require advanced skills in cybersecurity tools and methodologies.

What are the most commonly searched types of Offensive Security Engineer jobs in California?

The most popular types of Offensive Security Engineer jobs in California are:

What are popular job titles related to Director Offensive Security Engineer jobs in California?

For Director Offensive Security Engineer jobs in California, the most frequently searched job titles are:

What job categories do people searching Director Offensive Security Engineer jobs in California look for?

The top searched job categories for Director Offensive Security Engineer jobs in California are:

What cities in California are hiring for Director Offensive Security Engineer jobs?

Cities in California with the most Director Offensive Security Engineer job openings:

Infographic showing various Director Offensive Security Engineer job openings in California as of June 2026, with employment types broken down into 1% As Needed, 79% Full Time, 15% Part Time, 4% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Offensive Security Contributor: AI Red Teaming and Penetration Testing

Cobalt

Alameda, CA • On-site

Other

Posted 3 days ago

New


Job description

About the role:

Cobalt is seeking experienced offensive security practitioners to contribute expert reasoning, adversarial testing, and evaluation data used to train and assess frontier AI models.

This opportunity is suited to people who have worked as penetration testers, red team operators, security researchers, vulnerability researchers, exploit developers, application security engineers, or bug bounty hunters, in consultancies, internal security teams, or independently. Both traditional offensive security experience and experience probing AI systems are relevant, and you do not need both.

You do not need prior experience in data annotation or AI research. You must, however, be able to find and reason about real weaknesses in software or in model behavior unaided, and you must be comfortable documenting your approach clearly in writing.

All work is performed against sandboxed environments, purpose-built targets, and model endpoints supplied by us or by the lab. We do not accept work performed against systems you are not authorized to test, and we do not accept material obtained without authorization.


What you'll do:

Depending on the project, you may:

  • Produce written attack traces on security tasks, capturing how you form and test hypotheses, what you rule out and why, and how you arrive at a working approach, rather than only the end result
  • Adversarially test model behavior, probing for prompt injection, unsafe tool use, data exfiltration paths, and failures of refusal or policy adherence, and document reproducible cases
  • Author novel security problems, capture-the-flag style challenges, and evaluation scenarios with verifiable success criteria
  • Evaluate model-generated security content and code: rank responses, explain what makes the stronger one stronger, and identify the specific step at which the reasoning or the exploit logic breaks down
  • Design rubrics and partial-credit criteria for scoring multistep offensive and defensive tasks

Projects follow their own guidelines, scope rules, and quality standards, and you will work with feedback from reviewers and lab research teams.


Required qualifications:

  • Demonstrable offensive security experience, evidenced by professional penetration testing or red team engagements, published vulnerability research or CVEs, a substantive bug bounty record, competitive CTF results, or comparable work
  • Strong hands-on coding ability in at least one of Python, C, C++, Go, Rust, or JavaScript, sufficient to read unfamiliar codebases and write your own tooling
  • Depth in at least one area, for example web and API security, cloud and container security, network and infrastructure testing, binary exploitation and reverse engineering, or AI and LLM security
  • Ability to explain each step of your reasoning clearly in writing, and to produce documentation another practitioner could reproduce
  • Willingness to work strictly within defined scope and authorization, and to sign a confidentiality agreement covering project materials

Certifications such as OSCP, OSWE, OSEP, GPEN, or GXPN are useful but not required, as is prior experience with AI red teaming, model evaluation, or safety research.


Why Join Cobalt AI:

  • Advance frontier AI where it counts. Apply your offensive expertise to data that frontier labs cannot obtain any other way, where your judgment directly shapes how the next generation of models handles security reasoning and resists misuse.
  • Grow professionally. Expand your influence through evaluation projects, advisory roles, and research collaborations, while developing a working understanding of how frontier models are trained and assessed.
  • Work with a top-tier network. Collaborate with security researchers and practitioners from leading organizations on high-impact, flexible work.
  • Set your own schedule. Flexible 10 to 40 hour weeks that fit around your existing engagements and your life.
  • Competitive pay. Rates vary by project and are determined by a number of factors, including scope, skillset, and experience.