1

Freelance Offensive Security Engineer Jobs in Oregon

We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You're a paid hacker; you'll operate with ...

Senior Security Engineering Manager, Product Security

OR · On-site +1

$114K - $156K/yr

Upstart's Security Engineering team is passionate about bringing progressive approaches to securing ... Build and mature offensive security capabilities, including attack surface management, adversarial ...

Senior Product Security Engineer II

OR · On-site +1

$114K - $156K/yr

Overview About the Role - You will be a key member of the Security Engineering team that is tasked with researching, developing, and conducting offensive security techniques for a suite of Instacart ...

In addition to leading offensive security, you will provide oversight and strategic direction ... Lead BetterHelp's security engineering strategy, with offensive security as the foundation

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

Senior Product Security Engineer The role in a nutshell: You are a deeply technical engineer who ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

Staff Product Security Engineer The role in a nutshell: You are a deeply technical engineer who ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

The Senior Red Team Operator leads advanced offensive security operations designed to assess and ... Serve as a trusted advisor and subject matter expert to security operations, detection engineering ...

Solutions Engineer

OR · On-site +1

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Who You Are and What You'll Do As a Bishop Fox Solutions Engineer, you'll be partnering with ...

Overview Instacart's Detection Engineering team sits at the core of our Security organization ... Background in offensive security or red teaming * Knowledge of machine learning for threat ...

Security-conscious engineering culture. Liftoff's engineering org is a willing and capable partner ... Close the feedback loop between the team's offensive and proactive findings and detection coverage.

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining ... Scripting or programming experience in Python, JavaScript Go, Java, or similar languages

AI Red Team Lead Engineer

Gresham, OR

$108K - $143K/yr

The AI Red Team Lead Engineer leads the execution and evolution of offensive security activities focused on AI/ML systems, platforms, and integrations, in addition to traditional enterprise attack ...

Engineering Manager - IT & Security

OR · On-site +1

$195K - $220K/yr

Who we're looking for At Fieldwire, we're looking for an Engineering Manager, IT & Security, to ... Experience in offensive security engagements. * Familiarity with static code analysis and/or fuzz ...

Lead Engineer, AI Attack Simulation

Portland, OR · On-site +1

$108K - $143K/yr

Lead Engineer, AI Attack Simulation Remote [within the US] ABOUT THE ROLE: HiddenLayer is seeking a ... Cybersecurity product experience or closely related experience in offensive security, attack ...

Red Team Consultant

OR · On-site +1

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Proficiency in multiple programming languages (preferably Python, Golang, JavaScript/TypeScript, C# ...

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Proficiency in multiple programming languages (preferably Python, Golang, JavaScript/TypeScript, C# ...

Penetration Tester

OR · On-site +1

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java ...

next page

Showing results 1-20

Freelance Offensive Security Engineer information

What is a freelance offensive security engineer?

Freelance Offensive Security Engineers are independent cybersecurity professionals who specialize in identifying and exploiting vulnerabilities within computer systems, networks, and applications. They are hired by organizations on a contract basis to conduct penetration testing, red teaming, and security assessments to help improve the organization's defenses. Unlike in-house employees, freelancers work for multiple clients and often bring a diverse range of experience from different industries. Their primary goal is to simulate real-world attacks and provide detailed reports with recommendations to enhance security posture.

What are the key skills and qualifications needed to thrive as a freelance offensive security engineer?

To thrive as a Freelance Offensive Security Engineer, you need deep expertise in penetration testing, vulnerability assessment, and cybersecurity best practices, often backed by certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and scripting languages like Python is typically required. Strong problem-solving skills, self-motivation, and effective client communication set standout professionals apart in this field. These competencies are crucial for identifying and mitigating security risks while maintaining client trust and delivering high-value security assessments.

What are some common challenges faced by freelance offensive security engineers when working with multiple clients?

Freelance Offensive Security Engineers often juggle multiple projects for different clients, which can make time management and prioritization challenging. Each client may have unique security requirements, varying network environments, and distinct expectations for deliverables. Additionally, staying updated on the latest vulnerabilities and attack techniques is crucial, as clients rely on your expertise for thorough assessments. Clear communication and diligent documentation are essential to ensure that findings and recommendations are understood and actionable for each client.

What is the difference between Freelance Offensive Security Engineer vs Penetration Tester?

AspectFreelance Offensive Security EngineerPenetration Tester
CertificationsOSCP, CEH, OSWEOSCP, CEH, GPEN
Work EnvironmentProject-based, remote or on-site, client-specificTypically consulting, testing environments, often on-site or remote
Employer/Industry UsageFreelance, cybersecurity firms, consultingSecurity firms, internal security teams, consulting

Freelance Offensive Security Engineers and Penetration Testers both focus on identifying security vulnerabilities. However, Freelance Offensive Security Engineers often work on broader offensive security projects, including red teaming and security architecture, while Penetration Testers primarily conduct targeted vulnerability assessments. The roles overlap but differ in scope and depth of engagement.

What are the most commonly searched types of Offensive Security Engineer jobs in Oregon?

The most popular types of Offensive Security Engineer jobs in Oregon are:

What job categories do people searching Freelance Offensive Security Engineer jobs in Oregon look for?

The top searched job categories for Freelance Offensive Security Engineer jobs in Oregon are:

Senior Offensive Security Engineer

Array

OR • On-site, Remote

$170K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 16 days ago


Job description

Array is a financial innovation platform that helps digital brands, financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and identity monitoring tools, privacy protection, and a financial ads marketplace via embeddable widgets or a clean, modern API.  Our private label offerings help drive revenue and increase engagement for our customers while empowering millions of consumers to achieve their financial goals.

As a remote-first company, we're focused on providing opportunities for high performing individuals to have deep impact in the fast growing fintech space. A clear mission, a commitment to continuous improvement and a willingness to experiment empower us individually and together deliver the best products for our clients and users.

We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You're a paid hacker; you'll operate with full access to our applications, source code, and infrastructure to identify vulnerabilities that create meaningful business risk-not theoretical findings. AI should be one of your primary tools, enabling you to analyze large codebases, accelerate hypothesis generation, and increase testing coverage while relying on your own judgment to validate results.

You Have:

  • 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
  • Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
  • Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
  • Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
  • Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
  • A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.

You Will:

  • Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
  • Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
  • Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
  • Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
  • Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
  • Maintain a habit of using AI tools to think, build, and ship faster-it's your default, not an afterthought.

Success Looks Like:

  • Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
  • Security gaps identified that were not detected by existing tools or processes.
  • High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
  • Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.

Pay transparency: $170,000 + for base salary, depending on experience. Full time employee compensation includes an Incentive Stock Option (ISO) grant, subject to Board approval.

Expected interview process: Recruiter Conversation - Hiring Manager Interview - Loop round: How We Work, Engineering leadership. 

Array Offers All Full Time Employees the following Benefits and Perks: 

  • Full medical, dental, and vision, premiums covered at 100% for full-time employees and 70% for dependents
  • Unlimited PTO and sick leave + 14 company holidays to encourage a healthy work-life blend
  • 100% 401k match up to 4% with immediate vesting 
  • Generous and competitive parental leave for all parents
  • $1,000 desk setup subsidy to set-up your unique remote office 
  • $100/month to subsidize wifi/cell phone expenses
  • Summer Fridays (half-day Fridays) typically from late May to the end of August
  • Commuter benefits for those who choose to go into our New York City or San Francisco office spaces

Not sure if you meet the Qualifications? We know that folks tend to only apply if they check every box. If you think you have the appropriate qualifications, but don't meet every single one, we encourage you to still apply. We'd love to hear from you.

We are proud to be an equal opportunity workplace; we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Array will provide reasonable accommodations to qualified applicants-if you need an accommodation to participate in the application or interview process, please email talent@array.com to make your request.

Array uses CLEAR to conduct identity verification as part of the application process. We encourage you to review CLEAR's Privacy Notice and Terms of Use to understand how your personal data will be processed.