2

Offensive Security Engineer Remote Jobs (NOW HIRING)

Offensive Security Engineer

Seattle, WA · Remote

$150K - $200K/yr

As an Offensive Security Engineer at Staris AI, you'll be at the vanguard of the application ... Competitive base, meaningful equity, full benefits, and a remote-first culture.

Who We Are Looking For We are looking for an Offensive Security Engineer who operates with clear ownership. You're not just filling a seat. You're setting the standard. You believe great execution ...

Senior Offensive Security Engineer Reports to: Director, Product Security and Incident Response ... Remote Compensation Range: $170,000.00 to $185,000.00 base plus bonus and equity What We Do:

Senior Offensive Security Engineer Reports to: Director, Product Security and Incident Response ... Remote Compensation Range: $170,000.00 to $185,000.00 base plus bonus and equity What We Do:

Senior Offensive Security Engineer

OR · On-site +1

$114.40K - $156.80K/yr

Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing our overall security posture? At Ivanti, we work ...

Senior Offensive Security Engineer

$117.20K - $160.70K/yr

Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing our overall security posture? At Ivanti, we work ...

Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and ... About the Opportunity The College Board is seeking a Lead Offensive Security Engineer who will ...

Senior Offensive Security Engineer

$117.20K - $160.70K/yr

Role Summary TCM Security is hiring a Senior Offensive Security Engineer to grow our penetration testing practice. The ideal candidate brings deep technical expertise, a passion for offensive ...

Remote-first and globally distributed, we work with companies like Nasdaq, IBM, DoorDash, and ... About the Role We are looking for an Offensive Security Engineer to work on Teleport's Red Team.

The Mission Praetorian is an expert-driven offensive security company. Our mission is to prevent ... You're in the work - raising the bar on delivery, developing the engineers around you, and holding ...

This is a remote first role. You will partner closely with teams across the company and focus on ... Help run penetration testing and offensive security exercises against Figma's AI infrastructure ...

next page

Showing results 1-20

Offensive Security Engineer Remote information

See salary details

$61.5K

$152.8K

$205.5K

How much do offensive security engineer remote jobs pay per year?

As of Jun 1, 2026, the average yearly pay for offensive security engineer remote in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Offensive Security Engineer (Remote), and why are they important?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote Offensive Security Engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an Offensive Security Engineer do, especially when working remotely?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

More about Offensive Security Engineer Remote jobs
What cities are hiring for Offensive Security Engineer Remote jobs? Cities with the most Offensive Security Engineer Remote job openings:
What are the most commonly searched types of Offensive Security Engineer jobs? The most popular types of Offensive Security Engineer jobs are:
What states have the most Offensive Security Engineer Remote jobs? States with the most job openings for Offensive Security Engineer Remote jobs include:
What job categories do people searching Offensive Security Engineer Remote jobs look for? The top searched job categories for Offensive Security Engineer Remote jobs are:
Infographic showing various Offensive Security Engineer Remote job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 94% Full Time, and 5% Contract. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Offensive Security Engineer

Staris AI

Seattle, WA • Remote

$150K - $200K/yr

Full-time

Posted 24 days ago


Job description

Description
At Staris AI we believe human-based cyber defense is dead and the dream of security automation is finally within reach. Staris AI is a Series A ventured-backed firm that is reinventing application security with its innovative AI-powered penetration testing that continuously validates and remediates real attack paths in running applications. The Staris Total Context Security platform proves exploitable vulnerabilities in hours, not weeks, with zero false positives and 40:1 efficiency gains over traditional methods.
We're on a mission to transform the indefensible into the impenetrable, advancing applications into a new era of security.
As an Offensive Security Engineer at Staris AI, you'll be at the vanguard of the application security profession. This role goes beyond conventional application security and penetration testing; you'll be instrumental in advancing the field of automated software attack and simulation with your expertise in threat simulation and attack automation.

What You'll Do
  • Own the execution and quality of autonomous security assessments, ensuring results are accurate, validated, and actionable for customers.
  • Drive the continuous improvement of AI-driven attack simulations and automated exploitation workflows to expand coverage, reliability, and assessment depth.
  • Apply offensive security expertise to identify realistic attack paths, validate findings, and reduce false positives across modern application and cloud environments.
  • Partner with engineering and research teams to operationalize new attack techniques and strengthen the platform’s autonomous testing capabilities.
  • Use insights from diverse target environments and customer feedback to improve assessment logic, remediation quality, and overall platform effectiveness.

What You Bring
  • Minimum of 5 years of experience in application security assessment, source code auditing, bug hunting or similar areas
  • Knowledge of offensive application security fundamentals
  • Knowledge of relevant open-source technologies for attack automation (e.g. Tools, Libraries, Frameworks, etc.)
  • Experience working with relevant software assessment technologies (e.g. SAST, DAST, Fuzzing, etc.).
  • Prior emphasis on distributed systems and micro-service architectures
  • Familiarity with prompt engineering, generative AI models, and their APIs
  • Bachelor's degree in a related field (e.g. Computer Science, Information Technology, Cybersecurity, etc.) 
  • Strong English language communication skills

Why Staris
  • Backed by a founding team with deep pedigree, including alumni of Amazon, Accenture, and Palo Alto Networks, who have solved this problem operationally before.
  • A genuine category-defining product. Most AppSec tools create noise while Staris eliminates it with AI-driven proof of exploitability and automated, code-level remediation.
  • Supporting a massive, underserved market. Enterprises invest heavily in AppSec but deeply test only a fraction of their software portfolio.
  • Competitive base, meaningful equity, full benefits, and a remote-first culture.