2

Offensive Security Engineer Remote Jobs (NOW HIRING)

In addition to leading offensive security, you will provide oversight and strategic direction ... Remote work with regular in-person bonding experiences sponsored by the company * Competitive ...

Application Security Engineer- Remote

$60.25 - $80.25/hr

Application Security Engineer - Remote or Hybrid | Cary, North Carolina We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into ...

Security Engineer

Manhattan, NY · Remote

$105K - $125K/yr

Background in offensive security (exploit development, red teaming, adversary simulation ... Fully remote, U.S.-based. * Health Benefits: Comprehensive health, dental, and vision coverage.

Genesis10 is currently seeking a Senior Security Engineer - Remote position with a Global Law Firm located in New York, NY. This is a direct hire opportunity. As a Senior Security Engineer, you will ...

Genesis10 is currently seeking a Senior Security Engineer - Remote position with a Global Law Firm located in New York, NY. This is a direct hire opportunity. As a Senior Security Engineer, you will ...

Senior Application Security Engineer

$117.20K - $160.70K/yr

The Senior Application Security Engineer will lead the development of security measures, ensuring ... offensive security (eg, through bug bounty programs or CTFs) Company : Zip is an intake and ...

New

Network Security Engineer

San Francisco, CA · Remote

$123.10K - $168.50K/yr

Network Security Engineer Remote role Required Skills and Experience (3-5 years): * Strong networking fundamentals: TCP/IP, routing/switching, VLANs, DNS, load balancing concepts, security zones ...

Senior Product Security Engineer

$117.20K - $160.70K/yr

Required : • 5+ years of experience in product security, application security, offensive security, and/or security-focused software engineering • Long track record of identifying and remediating ...

Senior Product Security Engineer

Manhattan, NY · On-site +1

$200K - $250K/yr

Hybrid (3 days in office/2 days remote) - New York, NY or Century City, CA About The Team StubHub ... If you're passionate about offensive security, CI/CD hardening, and driving real impact across ...

Hybrid (3 days in office/2 days remote) - New York, NY or Century City, CA About the Team StubHub ... If you're passionate about offensive security, CI/CD hardening, and driving real impact across ...

next page

Showing results 1-20

Offensive Security Engineer Remote information

See salary details

$61.5K

$152.8K

$205.5K

How much do offensive security engineer remote jobs pay per year?

As of Jun 2, 2026, the average yearly pay for offensive security engineer remote in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Offensive Security Engineer (Remote), and why are they important?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote Offensive Security Engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an Offensive Security Engineer do, especially when working remotely?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

More about Offensive Security Engineer Remote jobs
What cities are hiring for Offensive Security Engineer Remote jobs? Cities with the most Offensive Security Engineer Remote job openings:
What are the most commonly searched types of Offensive Security Engineer jobs? The most popular types of Offensive Security Engineer jobs are:
What states have the most Offensive Security Engineer Remote jobs? States with the most job openings for Offensive Security Engineer Remote jobs include:
What job categories do people searching Offensive Security Engineer Remote jobs look for? The top searched job categories for Offensive Security Engineer Remote jobs are:
Senior Security Engineering Manager, Product Security

Senior Security Engineering Manager, Product Security

Upstart

Remote

$117.20K - $160.70K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 13 days ago


Job description

About Upstart
At Upstart, we're united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence.
As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that's both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 1,800 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress.
We're proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn't mean distant. We're intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City (opening Summer 2026), you'll have the support to work in the way that works best for you.
If you're energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we'd love to hear from you.
The Team:
Upstart's Security Engineering team is passionate about bringing progressive approaches to securing our products, infrastructure, platforms, and enterprise systems. We believe security should empower innovation, move at the speed of business, and embed safety by design into how Upstart builds and operates. Our team's mission is to protect Upstart's core product platforms, cloud infrastructure, enterprise systems, customers, and data by partnering deeply with Engineering, Product, Infrastructure, Risk, Compliance, and Security teams to reduce security risk through automation, collaboration, offensive security, and durable security practices.
As the Senior Security Manager for Product Security Engineering at Upstart, you will lead a team responsible for scaling security engineering practices across application security, infrastructure security, offensive security, and product security. You will set priorities, develop team members, and partner with senior engineering and business leaders to shape Upstart's security engineering strategy, strengthen secure-by-design practices, reduce systemic risk, and improve the security posture of customer-facing products, cloud-native services, internal platforms, APIs, and AI-driven product workflows.
How you'll make an impact
  • Define and lead the Security Engineering roadmap across application security, infrastructure security, offensive security, and product security, aligning priorities with Upstart's business objectives, engineering strategy, regulatory expectations, and risk posture.
  • Manage, coach, and develop a team of security engineers, ensuring clear goals, measurable impact, sustainable execution, effective operating rhythms, and growth opportunities for each team member.
  • Partner with Engineering, Product, Infrastructure, Data, Risk, Compliance, and Audit leaders to identify high-priority security risks, align on pragmatic mitigations, and embed security requirements early in planning, design, development, and operations.
  • Scale secure-by-design practices across the SDLC, including threat modeling, security architecture reviews, secure coding practices, automated security testing, vulnerability management, API security, CI/CD protections, secrets management, and developer security enablement.
  • Strengthen infrastructure and cloud security by partnering with Infrastructure and Platform teams on secure architecture, identity and access controls, Kubernetes and container security, cloud-native security controls, and defense-in-depth across application and infrastructure layers.
  • Build and mature offensive security capabilities, including attack surface management, adversarial testing, security validation, penetration testing coordination, bug bounty intake, and prioritization of findings into durable engineering improvements.
  • Improve product security outcomes by partnering with Product and Engineering teams to identify abuse cases, security requirements, customer-impacting risks, and scalable controls for high-trust product experiences.
  • Drive consistent execution across cross-functional initiatives by setting priorities, clarifying ownership, communicating tradeoffs, and ensuring high-impact security work is delivered with quality and urgency.
  • Establish and improve Security Engineering metrics, operating models, and reporting so leaders can understand risk posture, remediation progress, recurring patterns, program health, and the effectiveness of security investments.
  • Support response to high-severity security issues by coordinating technical investigation, stakeholder communication, root cause analysis, remediation tracking, and durable improvements that prevent repeat issues.
  • Foster a culture where security enables innovation by building trusted partnerships, mentoring engineering leaders, and helping teams adopt practical controls that improve safety without unnecessary friction.

What we're looking for:
  • Minimum requirements:
    • 8+ years of experience in security engineering, software engineering, infrastructure engineering, offensive security, product security, or related technical security roles.
    • 3+ years of experience managing, leading, or formally developing security engineers or technical teams.
    • Experience leading security engineering programs in at least two of the following domains: application security, infrastructure security, offensive security, product security, cloud security, or secure SDLC.
    • Experience partnering with Engineering, Product, Infrastructure, Risk, Compliance, or Audit stakeholders to deliver cross-functional security initiatives.
    • Experience with modern application and infrastructure architectures, including APIs, web applications, cloud-native services, CI/CD pipelines, identity and access controls, and common vulnerability classes.
    • Experience defining roadmaps, priorities, metrics, and operating processes for security programs with cross-functional dependencies.
  • Preferred qualifications:
    • Experience building or scaling a security engineering function, including team operating models, roadmap planning, prioritization frameworks, metrics, and executive-level reporting.
    • Experience managing security work in a regulated environment, financial technology company, or organization with high security, privacy, or compliance requirements.
    • Knowledge of AWS, Kubernetes, containers, CI/CD security, infrastructure-as-code security, identity and access management, vulnerability management, API security, and modern application security testing practices.
    • Experience implementing or scaling security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, attack surface management, bug bounty intake, penetration testing workflows, vulnerability management platforms, or developer security guardrails.
    • Familiarity with security considerations for AI/ML systems, data-intensive applications, lending or financial technology platforms, or other high-trust customer-facing products.
    • Ability to communicate technical risk, tradeoffs, and recommendations clearly to technical, non-technical, and senior leadership audiences.
    • Experience partnering with Engineering, Product, Infrastructure, Legal, Risk, Compliance, and Audit teams to deliver security outcomes without creating unnecessary friction.
    • Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, GIAC, OSCP, or equivalent practical expertise.

Position location This role is available in the following locations: Remote - US
Time zone requirements The team operates on the East/West coast time zones.
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSenior
At Upstart, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location-with our "digital first" philosophy, Upstart uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
In addition, Upstart provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k).
United States | Remote - Anticipated Base Salary Range
$190,600-$263,900 USD
What you'll love
At Upstart, our benefits are designed to support your health, financial well-being, family, and personal growth. Here's what you can expect:
  • Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly
  • Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US, CAD in Canada)
  • Employee Stock Purchase Plan (ESPP) with discounted stock purchase options for eligible employees (US only)
  • Comprehensive health coverage designed to support you and your family, including medical, dental, vision, and wellness resources for US and supplemental health coverage for Canada.
  • Health Savings Account contributions from Upstart for eligible plans (US only)
  • Income protection benefits, including life insurance and disability coverage for added financial security
  • Paid time off, sick leave, and company holidays, in line with local requirements
  • Paid family and parental leave to support caregiving and major life moments (duration varies by country)
  • Family-centered benefits to support fertility, parenthood, and caregiving needs
  • Employee Assistance Program (EAP) offering mental health support and life-centered resources
  • Financial wellness resources, including access to financial planning tools and a financial concierge service (US Only)
  • Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you
  • Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from
  • Connection and community through team events, all-company updates, and employee resource groups (ERGs)
  • Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our offices in the Bay Area, Austin, Columbus, and New York City (opening Summer 2026!)

For roles based in Canada, please note that we are not currently able to hire in Quebec.
Upstart is a proud Equal Opportunity Employer. Just as we are dedicated to improving access to affordable credit for all, we are committed to inclusive and fair hiring practices.
If you require reasonable accommodation in completing an application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please email candidate_accommodations@upstart.com
https://www.upstart.com/candidate_privacy_policy