1

Offensive Security Jobs in Arizona (NOW HIRING)

Offensive Security Engineer

Tempe, AZ ยท On-site

$100K - $120K/yr

The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is responsible for proactively identifying ...

Knowledge of offensive security, with the ability to think like an adversary when hunting and responding to incidents * Knowledge and understanding of security analytics including: incident response ...

Our offensive security operations include thorough security assessments of enterprise-connected assets including physical hosts, network devices, applications, virtual machines, cloud infrastructure ...

They are seeking an experienced Penetration Tester to conduct advanced offensive security operations, identifying vulnerabilities and strengthening cyber capabilities across various systems.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

This role plays a critical part in building and scaling the organization's offensive security capability and ensuring the company stays ahead of emerging threats in an evolving risk landscape.

next page

Showing results 1-20

Offensive Security information

See Arizona salary details

$53.1K

$123.9K

$173.3K

How much do offensive security jobs pay per year?

As of Jul 26, 2026, the average yearly pay for offensive security in Arizona is $123,906.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,400.00 and $139,800.00 per year, depending on experience, location, and employer.

What is an Offensive Security job?

An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.

What is the job description of offensive security?

Offensive security involves simulating cyberattacks to identify vulnerabilities in computer systems and networks. Professionals in this field perform penetration testing, exploit development, and vulnerability assessments using tools like Kali Linux and Metasploit, often holding certifications such as OSCP. The role requires strong knowledge of networking, security protocols, and programming skills to help organizations improve their defenses.

How much do offensive security specialists make?

Offensive security specialists, also known as penetration testers or ethical hackers, typically earn between $70,000 and $130,000 annually, depending on experience, certifications like OSCP or CEH, and the complexity of the security environment. Senior professionals with advanced skills and certifications can earn higher salaries, especially in high-demand industries or locations with a strong cybersecurity market.

What does a typical day look like for someone working in Offensive Security?

A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.

Can I make $200,000 a year in cyber security?

Offensive security professionals, such as penetration testers and ethical hackers, can potentially earn $200,000 or more annually with extensive experience, advanced certifications like OSCP or CISSP, and specialized skills in tools like Kali Linux and Metasploit. High salaries are often found in senior roles, consulting, or in organizations with complex security needs, but reaching this level typically requires years of expertise and a strong professional reputation.

Is 40 too old for cyber security?

Offensive security professionals can be successful at any age, as the field values skills, certifications, and experience over youth. Many individuals transition into cybersecurity later in life, bringing valuable problem-solving and analytical skills. Continuous learning and staying current with tools like penetration testing frameworks are important regardless of age.

What are the key skills and qualifications needed to thrive in the Offensive Security position, and why are they important?

To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

What job categories do people searching Offensive Security jobs in Arizona look for? The top searched job categories for Offensive Security jobs in Arizona are:
What cities in Arizona are hiring for Offensive Security jobs? Cities in Arizona with the most Offensive Security job openings:
Infographic showing various Offensive Security job openings in Arizona as of July 2026, with employment types broken down into 92% Full Time, 5% Part Time, 1% Temporary, and 2% Contract. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $123,906 per year, or $59.6 per hour.

Offensive Security Engineer

RunBuggy OMI Inc.

Tempe, AZ โ€ข Hybrid

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 21 days ago


Job description

Description

About Us:

RunBuggy is the most technically advanced automotive logistics platform on the market. Period.


Backed by Porsche Ventures and Hearst Ventures, RunBuggy is transforming the way cars move. Our cutting-edge technology is trusted by some of the largest OEMs, captive finance companies, and automotive lenders in the world to streamline vehicle transportation at scale.


RunBuggy's end-to-end platform connects car shippers and haulers in real time - eliminating the friction of traditional load boards and costly custom software. For shippers, RunBuggy integrates directly into existing management systems, reducing transportation costs and accelerating delivery timelines. For transporters, we offer a smarter, more profitable way to find, accept, and manage loads - all from a single app.


Since launching in 2019, RunBuggy has grown to over 190 team members, facilitated the movement of hundreds of thousands of vehicles, and attracted tens of thousands of transporters across the U.S.


We're not just building a better logistics platform - we're redefining the future of automotive transportation.



About the Role:

The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is responsible for proactively identifying, exploiting, and validating vulnerabilities while also partnering with engineering teams to design, implement, and improve security controls across the environment.ย 


This position reports to our Cybersecurity Manager and is a hybrid role (3 days in office per week).ย 


What You Will Be Doing:

  • Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS), and be able to give hardening suggestions.ย 
  • Conduct offensive security engagements, including Red Team operations, threat-based evaluations, and vulnerability research and exploitation against both internal and external-facing systems.
  • Plan and execute black-box, grey-box, and white-box web application penetration tests against RunBuggy production and staging environments.ย 
  • Maintain tooling (Burp, Metasploit, C2 frameworks, custom scripts) for exploitation, detection validation, and security assessments.
  • Conduct API security testing (REST, GraphQL) including authentication bypass, injection, broken object-level authorization (BOLA/IDOR), and business logic flaws.ย 
  • Perform cloud configuration reviews (AWS) and assess infrastructure-level exposure where it intersects with web application attack surfaces.ย 
  • Produce clear, risk-ranked findings reports with reproducible proof-of-concept and actionable remediation guidance for both technical and non-technical audiences.ย 
  • Collaborate with engineering to validate fixes and re-test remediated vulnerabilities.ย 
  • Perform social engineering exercises (phishing, credential harvesting), where applicable.
  • Contribute to bug bounty triage, third-party assessment coordination, and security tooling selection.ย 
  • Support compliance efforts (SOC 2, PCI DSS) by providing evidence and attestation tied to pen test scope and outcomes.ย 
  • Stay current on emerging attack techniques and translate threat intelligence into test cases relevant to RunBuggy's stack.ย 
  • Other duties as assigned.


Requirements

What You Bring to the Team by Way of Skills and Experience:

  • Bachelor's degree in Cybersecurity or related field required.ย 
  • 3+ years of hands-on web application penetration testing experience in a professional or consulting capacity.ย 
  • Passion and demonstrated experience for challenging security assumptions.
  • Deep familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for LLMs.ย 
  • Proficiency with standard tooling: Burp Suite, OWASP ZAP, Nmap, Metasploit, SQLmap, Nikto.ย 
  • Demonstrated ability to exploit and document authentication/authorization flaws, injection vulnerabilities, XXE, SSRF, deserialization issues, and insecure direct object references.ย 
  • Strong written communications: findings reports must be usable by both developers and executives.ย 
  • Experience testing RESTful and/or GraphQL APIs.ย 
  • Experience with AWS environment security assessment (IAM misconfiguration, S3 exposure, Lambda attack surface).ย 
  • Scripting proficiency in Python, Bash, or JavaScript for custom tooling and automation.ย 
  • Familiarity with automotive, logistics, or fintech regulatory requirements (PCI DSS, SOC 2 Type II).ย 
  • Prior experience in a startup or high-growth SaaS environment where speed and security have to coexist.ย 


Certificates, Licenses, and/or Registrations:ย 

  • OSCP, GWAPT, eWPT, or equivalent. CEH is accepted but is less weighted than practical certs.ย 



What is in it for You and Why you Should Apply:

  • Market-competitive pay based on education, experience, and location.ย 
  • Highly competitive medical, dental, vision, Life w/ AD&D, Short-Term Disability insurance, Long-Term Disability insurance, pet insurance, identity theft protection, and a 401(k) retirement savings plan.
  • Employee wellness program.ย 
  • Employee rewards, discounts, and recognition programs.
  • Generous company-paid holidays (12 per year), vacation, and sick time.
  • Paid paternity/maternity leave.
  • Monthly connectivity/home office stipend if working from home 5 days a week.
  • A supportive and positive space for you to grow and expand your career.



Pay Range Disclosure:ย 

The advertised range represents the expected pay range for this position at the time of posting based on education, experience, skills, location, and other factors.ย 



To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


RunBuggy is an equal-opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination, harassment, and retaliation on the basis of race, color, religion, sex (including gender identity and sexual orientation), pregnancy, parental status, national origin, age, disability, genetic information, or any other status protected under federal, state, or local law.



Unsolicited resumes sent via email or LinkedIn Messenger will not be considered.


No agencies, please.