Analyze agent trajectories and failure modes across real engagementsIdentify systemic weaknesses in ... Build reusable offensive security primitives that can be shared across Apex and the Pensar platform
Analyze agent trajectories and failure modes across real engagementsIdentify systemic weaknesses in ... Build reusable offensive security primitives that can be shared across Apex and the Pensar platform
Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities. * Develop repeatable red team and ...
Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities. * Develop repeatable red team and ...
Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities. * Develop repeatable red team and ...
Lead a small internal offensive security team while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities. * Develop repeatable red team and ...
Senior Offensive Security Engineer
$114K - $156K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Senior Offensive Security Engineer
$114K - $156K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Senior Offensive Security Engineer
Naperville, IL Β· On-site
$114K - $156K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Senior Offensive Security Engineer
Naperville, IL Β· On-site
$114K - $156K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
As an Offensive Security Analyst II , you'll provide consultative and hands on services by performing technical planning and testing of Digital assets, systems, processes, and employees. Location
As an Offensive Security Analyst II , you'll provide consultative and hands on services by performing technical planning and testing of Digital assets, systems, processes, and employees. Location
Senior Offensive Security Engineer
Naperville, IL Β· On-site
$113K - $155K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Senior Offensive Security Engineer
Naperville, IL Β· On-site
$113K - $155K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
As an Offensive Security Analyst II , you'll provide consultative and hands on services by performing technical planning and testing of Digital assets, systems, processes, and employees. Location
As an Offensive Security Analyst II , you'll provide consultative and hands on services by performing technical planning and testing of Digital assets, systems, processes, and employees. Location
$84K - $115K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
$84K - $115K/yr
Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.
Senior Offensive Security Engineer
San Mateo, CA Β· On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... Organizational skills: strong analytical and problem-solving abilities; excellent technical writing ...
Senior Offensive Security Engineer
San Mateo, CA Β· On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... Organizational skills: strong analytical and problem-solving abilities; excellent technical writing ...
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... Product Security Analyst Remote Locations - Boston, MA - Austin, TX - Washington, DC - Seattle, WA ...
New
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... Product Security Analyst Remote Locations - Boston, MA - Austin, TX - Washington, DC - Seattle, WA ...
New
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... Product Security Analyst Remote Locations - Boston, MA - Austin, TX - Washington, DC - Seattle, WA ...
New
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... Product Security Analyst Remote Locations - Boston, MA - Austin, TX - Washington, DC - Seattle, WA ...
New
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... As a Product Security Analyst, you will join HackerOne's Technical Services organization and work ...
Offensive security is no longer optional - it is the standard for forward-thinking companies that ... As a Product Security Analyst, you will join HackerOne's Technical Services organization and work ...
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced ... analysis. * Experience with security tools and technologies, such as SIEM, next generation ...
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced ... analysis. * Experience with security tools and technologies, such as SIEM, next generation ...
Senior Offensive Security Engineer
San Mateo, CA Β· On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... Organizational skills: strong analytical and problem-solving abilities; excellent technical writing ...
Senior Offensive Security Engineer
San Mateo, CA Β· On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in ... Organizational skills: strong analytical and problem-solving abilities; excellent technical writing ...
Position Specific Description NextEra Energy is seeking an experienced Offensive Security Analyst with exceptional hands-on technical skills and a strong background in utilizing red team toolsets.
Position Specific Description NextEra Energy is seeking an experienced Offensive Security Analyst with exceptional hands-on technical skills and a strong background in utilizing red team toolsets.
Senior Principal Engineer, Offensive Security
San Jose, CA Β· On-site
$190K - $240K/yr
Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world ... Mentor security engineers and elevate offensive security capability across the organization
Senior Principal Engineer, Offensive Security
San Jose, CA Β· On-site
$190K - $240K/yr
Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world ... Mentor security engineers and elevate offensive security capability across the organization
Role Summary As a member of our Offensive Security Team, you will be challenged to test assumptions and make the unknown known. Working closely with our Incident Response and Cyber Threat Intel teams ...
Role Summary As a member of our Offensive Security Team, you will be challenged to test assumptions and make the unknown known. Working closely with our Incident Response and Cyber Threat Intel teams ...
Information Security Analyst
Boise, ID Β· On-site
Undergraduate Certificates Security analysts can enhance their credentials with certifications like CompTIA PenTEST+ , Certified Ethical Hacker ( CEH ) and Offensive Security Certified Professional ...
Information Security Analyst
Boise, ID Β· On-site
Undergraduate Certificates Security analysts can enhance their credentials with certifications like CompTIA PenTEST+ , Certified Ethical Hacker ( CEH ) and Offensive Security Certified Professional ...
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced ... analysis. * Experience with security tools and technologies, such as SIEM, next generation ...
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced ... analysis. * Experience with security tools and technologies, such as SIEM, next generation ...
Offensive Security Analyst information
See salary details
$39.5K - $48.7K
1% of jobs
$48.7K - $58K
3% of jobs
$58K - $67.2K
4% of jobs
$67.2K - $76.4K
5% of jobs
$76.4K - $85.6K
6% of jobs
$92.9K is the 25th percentile. Wages below this are outliers.
$85.6K - $94.9K
6% of jobs
$94.9K - $104.1K
5% of jobs
The median wage is $109.5K / yr.
$104.1K - $113.3K
32% of jobs
$113.3K - $122.5K
3% of jobs
$125.1K is the 75th percentile. Wages above this are outliers.
$122.5K - $131.8K
32% of jobs
$131.8K - $141K
2% of jobs
$39.5K
$107.3K
$141K
How much do offensive security analyst jobs pay per year?
What is the difference between Offensive Security Analyst vs Penetration Tester?
| Aspect | Offensive Security Analyst | Penetration Tester |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | OSCP, CEH, GPEN |
| Work Environment | Security teams, internal assessments | External engagements, client sites |
| Industry Usage | Cybersecurity firms, corporate security | Consulting firms, security vendors |
Both roles focus on identifying vulnerabilities, often requiring similar certifications like OSCP and CEH. An Offensive Security Analyst typically works within an organizationβs security team to analyze and improve defenses, while a Penetration Tester conducts external assessments for clients. The main difference lies in their scope and environment, but both roles are essential for proactive security measures.
What cities are hiring for Offensive Security Analyst jobs?
Cities with the most Offensive Security Analyst job openings:
What states have the most Offensive Security Analyst jobs?
States with the most job openings for Offensive Security Analyst jobs include:
What are popular job titles related to Offensive Security Analyst jobs?
For Offensive Security Analyst jobs, the most frequently searched job titles are:

Offensive Security Agent Engineer
On-site
Other
Medical, Dental, Vision
Posted 7 days ago
Job description
We are seeking an Offensive Security Agent Engineer to build the systems that power autonomous offensive security across Apex and the Pensar platform. You'll work at the intersection of software engineering, offensive security, and AI agents, building the harnesses, tools, execution environments, and workflows that allow autonomous agents to discover and exploit vulnerabilities in real-world applications.
This is an engineering role focused heavily on web security and agentic systems. You'll work on everything surrounding the model itself: how agents interact with browsers, terminals, proxies, scanners, and custom security tools; how they maintain context and reason across long-running engagements; how they explore complex applications; and how we evaluate whether they are actually becoming better offensive security operators.
You'll work closely with our security researchers, AI engineers, and product engineers to turn offensive security techniques into reliable autonomous capabilities. When an agent fails to find a vulnerability, gets stuck in an application, uses a tool incorrectly, or takes an inefficient attack path, you'll dig into why and build the systems that make it better.
The ideal candidate is a strong software engineer who understands how modern web applications break, is deeply interested in agentic systems, and wants to build autonomous security infrastructure rather than simply use existing AI tooling.
Key Responsibilities Agent Harness & Infrastructure- Design and build the agent harness powering autonomous offensive security workflows across Apex and the Pensar platform
- Build systems that allow agents to reliably interact with browsers, terminals, HTTP proxies, scanners, APIs, filesystems, and other security tooling
- Develop orchestration for long-running, multi-step offensive security tasks involving reconnaissance, exploitation, validation, and reporting
- Build abstractions that allow agents to safely and effectively execute tools, inspect results, maintain state, and adapt their approach
- Improve agent context management, memory, task decomposition, planning, and execution across complex engagements
- Design reliable execution environments for autonomous security agents operating against customer applications and infrastructure
- Debug agent trajectories to understand why an agent succeeded, failed, hallucinated, became stuck, or missed an attack path
- Build observability and debugging infrastructure for understanding agent behavior at scale
- Build autonomous capabilities for discovering and exploiting vulnerabilities in modern web applications and APIs
- Develop tooling and workflows around authentication, authorization, session management, API discovery, application state, and complex multi-step attack paths
- Enable agents to navigate and understand JavaScript-heavy applications, authenticated applications, APIs, and modern application architectures
- Integrate offensive security tooling into autonomous workflows, including proxies, scanners, browsers, custom scripts, and exploitation frameworks
- Implement techniques for identifying vulnerability classes such as access control issues, injection vulnerabilities, SSRF, authentication flaws, business logic vulnerabilities, and other application security weaknesses
- Translate manual offensive security techniques into primitives and workflows that autonomous agents can execute reliably
- Track emerging web exploitation techniques and determine how they can be incorporated into Apex
- Build evaluation systems for measuring offensive security agent performance against realistic targets
- Develop benchmarks, test environments, and regression suites that measure whether changes actually improve agent capabilities
- Analyze agent trajectories and failure modes across real engagementsIdentify systemic weaknesses in agent reasoning, tooling, navigation, and exploitation behavior
- Design experiments around prompts, models, tools, context strategies, and orchestration approaches
- Work with security researchers to turn newly discovered techniques into reproducible evaluations and agent capabilities
- Help establish metrics for autonomous pentesting performance beyond simple vulnerability detection
- Contribute directly to Apex, our open source autonomous offensive security tool
- Build reusable offensive security primitives that can be shared across Apex and the Pensar platform
- Design APIs and internal interfaces for agent execution, tools, environments, and security workflows
- Work across the stack when necessary to ship new autonomous capabilities into production
- Improve the reliability, performance, and scalability of systems running autonomous security engagements
- Collaborate with platform engineers on infrastructure for securely executing large numbers of concurrent agent workloads
- Help define the technical architecture of Pensar's autonomous offensive security systems as the platform scales
- Work closely with offensive security researchers to understand how experienced human operators approach difficult targets
- Convert researcher techniques, workflows, and intuition into software and agent capabilities
- Build experimental tooling to test new approaches to autonomous exploitation
- Investigate difficult targets where existing agents fail and determine what capabilities are missing
- Explore new approaches to browser automation, application understanding, vulnerability discovery, and autonomous exploitation
- Contribute to technical research and open source releases around autonomous offensive security
CTO
We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.
- 4+ years of professional software engineering, security engineering, offensive security engineering, or equivalent experience
- Strong software engineering fundamentals and experience building production systems
- Strong programming skills in Python, Go, JavaScript/TypeScript, Rust, C/C++, or similar languages
- Deep understanding of modern web applications, HTTP, browsers, APIs, authentication, sessions, and application architecture
- Working knowledge of common web vulnerability classes and offensive security techniques
- Experience building or working with agentic systems, LLM applications, autonomous agents, or complex tool-using AI systems
- Experience with browser automation technologies such as Playwright, Puppeteer, Chrome DevTools Protocol, or similar tooling
- Ability to debug complex systems across application code, infrastructure, networking, and agent behavior
- Comfortable working with Linux, containers, cloud infrastructure, and isolated execution environments
- Ability to independently investigate ambiguous technical problems and turn findings into production systems
- Strong product instincts and an interest in making autonomous systems reliable in messy real-world environments
- Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience
- Comprehensive health, dental, and vision insurance
- Direct ownership of core autonomous offensive security infrastructure
- Opportunity to build agentic security systems operating against real-world applications
- Work directly with offensive security researchers and engineers pushing the capabilities of autonomous pentesting
- Professional development budget for conferences, training, and certifications
- Support for publishing research, open source work, and presenting at industry conferences
- Direct, visible impact on Apex and the Pensar platform