1

Exploit Developer Jobs in California (NOW HIRING)

STR is hiring a Principal Software Reverse Engineer who has a passion for research and analysis of ... Performing vulnerability weaponization, exploit development, payload development, and exploit ...

Utilize reverse engineering, fuzzing, exploit development, dynamic instrumentation, and firmware analysis tools (e.g., Ghidra, IDA Pro, Frida, AFL, libFuzzer, or similar technologies) to support ...

... Engineer to design and build the multi-target runtime for their AI compiler stack. This role ... exploit highly optimized execution paths. • Rapidly prototype and data-drive exploration of new ...

Senior Reverse Engineer

San Diego, CA · On-site

$134K - $184K/yr

STR is hiring a Senior Reverse Engineer who has a passion for research and analysis of ... Performing vulnerability weaponization, exploit development, payload development, and exploit ...

Reverse engineering complex software or firmware targets, ranging from typical Windows/Linux ... Performing vulnerability weaponization, exploit development, payload development, and exploit ...

Reverse engineering complex software or firmware targets, ranging from typical Windows/Linux ... Performing vulnerability weaponization, exploit development, payload development, and exploit ...

Reverse engineering complex software or firmware targets, ranging from typical Windows/Linux ... Performing vulnerability weaponization, exploit development, payload development, and exploit ...

Develop safeguards to prevent misuse of AI systems in exploit development or unintended security ... Proficiency in programming languages such as Python, Java, C++, or similar. * Experience developing ...

Showing results 41-60

Exploit Developer information

See California salary details

$16

$52

$80

How much do exploit developer jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for exploit developer in California is $52.15, according to ZipRecruiter salary data. Most workers in this role earn between $39.86 and $63.80 per hour, depending on experience, location, and employer.

What is an exploit developer?

An Exploit Developer is a cybersecurity professional who researches and develops exploits to identify security vulnerabilities in systems, applications, or networks. They analyze software and hardware for weaknesses, create proof-of-concept exploits, and work with security teams to patch vulnerabilities before malicious hackers can exploit them. This role requires deep knowledge of programming, reverse engineering, and security protocols. Some exploit developers work in ethical hacking or penetration testing, while others conduct research for security firms, government agencies, or cybersecurity vendors.

What skills and qualifications are needed to thrive as an exploit developer?

To thrive as an Exploit Developer, you need a strong background in computer science, reverse engineering, low-level programming (C/C++, Assembly), and vulnerability analysis. Familiarity with tools such as IDA Pro, Ghidra, Metasploit, and debuggers, along with relevant certifications like OSCP or GREM, is highly beneficial. Analytical thinking, persistence, excellent problem-solving, and clear documentation skills set outstanding professionals apart in this field. These abilities are essential for identifying and leveraging system weaknesses effectively and collaborating securely within advanced security teams.

What are common challenges faced by exploit developers, and how do teams typically address them?

Exploit Developers often encounter complex and evolving security architectures, which require continuous learning and adaptation to stay ahead of new safeguards and patch mechanisms. Collaborative troubleshooting, regular knowledge sharing, and working closely with security researchers and penetration testers are common approaches teams use to overcome obstacles. Many organizations foster a supportive environment, providing access to the latest research, tools, and test labs to encourage innovation and success. This collaborative and dynamic atmosphere helps Exploit Developers keep their skills sharp and deliver high-impact results.

What are the most commonly searched types of Exploit Developer jobs in California?

The most popular types of Exploit Developer jobs in California are:

What job categories do people searching Exploit Developer jobs in California look for?

The top searched job categories for Exploit Developer jobs in California are:

Infographic showing various Exploit Developer job openings in California as of August 2026, with employment types broken down into 87% Full Time, and 13% Part Time. Highlights an 100% In-person job distribution, with an average salary of $108,466 per year, or $52.1 per hour.

Security engineer, application security

Jobright.ai

San Francisco, CA • On-site

$140 - $200/hr

Other

Medical, Dental, Vision, Retirement

Posted 7 days ago


Job description

WRITER is seeking an Application Security Engineer with deep expertise in AppSec, DevSecOps automation, and red team operations to secure their AI and AGI applications. The role involves integrating security into development pipelines, conducting penetration testing, and collaborating with cross‑functional teams to safeguard AI solutions.

H1B Sponsor Likely

Responsibilities
  • Embed security in the build pipeline — Own pre‑deployment application security, including automated vulnerability scanning, container scanning, and custom security gates in CI/CD
  • Conduct advanced application penetration testing — Perform comprehensive testing on AI applications, APIs, and model endpoints, simulating adversarial attacks to validate controls
  • Automate security testing at scale — Develop scripts, tools, and frameworks for continuous security assessment, including SAST, DAST, and SCA integration
  • Lead application‑layer red team exercises — Plan and execute engagements that mimic sophisticated adversary techniques targeting AI systems
  • Hunt and validate vulnerabilities — Discover, reproduce, and chain vulnerabilities into realistic attack paths, providing actionable remediation guidance
  • Advise on security architecture — Review designs for weaknesses, create secure patterns, and identify systemic issues across applications
  • Collaborate across boundaries — Partner with Cloud/Infrastructure on deployment/runtime security, AI Security on threat modeling, and Detection & Response on defensive validation
Qualification
  • Application security Penetration testing DevSecOps automation CI/CD integration Vulnerability discovery SAST tools DAST tools API security Exploit development Security architecture Purple team operations Collaboration
Required
  • 8+ years in application security, with a strong focus on hands‑on testing
  • 5+ years conducting penetration tests and security assessments
  • Proven record of finding and exploiting critical vulnerabilities
  • Deep experience integrating security into DevOps workflows and CI/CD pipelines
  • Strong programming skills for exploit development and security automation
  • Expertise in web application and API security, including cloud‑native architectures
  • Proficient with penetration testing tools (e.g., Burp Suite, OWASP ZAP, custom scripts)
  • Skilled in SAST, DAST, and SCA tools
  • Strong understanding of application‑layer attack techniques and exploitation
  • Experience with supply chain security and build pipeline hardening
  • Demonstrated ability to identify vulnerabilities others missProven track record of automating security testing in fast‑paced development cycles
  • Ability to translate red team findings into concrete defensive measures
  • History of effective collaboration with engineering teams
Preferred
  • Background in software development or DevOps
  • Experience testing AI/ML applications
  • Security certifications such as OSCP, OSWE, or GWAPT
  • Published security research or CVEs
  • Experience with purple team operations
  • Medical, dental, and vision coverage for you and your family
  • Paid parental leave for all parents (12 weeks)
  • Fertility and family planning support
  • Early‑detection cancer testing through Galleri
  • Flexible spending account and dependent FSA options
  • Health savings account for eligible plans with company contribution
  • Annual work‑life stipends for: + Home office setup, cell phone, internet + Wellness stipend for gym, massage/chiropractor, personal training, etc. + Learning and development stipend
  • Company‑wide off‑sites and team off‑sites
  • Competitive compensation, company stock options and 401k
Company Writer Corporation

Relocations, information management, payment services, and realty services.

Writer Corporation has a track record of offering H1B sponsorships. Please note that this does notguarantee sponsorship for this specific role. Below presents additional info for yourreference. ( Data Powered by US Department of Labor)

Distribution of Different Job Fields Receiving Sponsorship

92 %

Represents job field similar to this job

Application security Penetration testing DevSecOps automation CI/CD integration Vulnerability discovery

#J-18808-Ljbffr