1

Offensive Security Jobs in California (NOW HIRING)

Security Engineer

Berkeley, CA · On-site

$285.55 - $503.12/hr

Offensive security: You would be the first person on the team with an offensive security background. You'll run targeted red-team exercises against our own systems and build automated AI red teaming.

Offensive security: You would be the first person on the team with an offensive security background. You'll run targeted red-team exercises against our own systems and build automated AI red teaming.

You'llexecute at the intersection of offensive security and AI, developing novel Red Team capabilities and running operations against AI-powered systems. This roleis responsible forworking with other ...

Help run penetration testing and offensive security exercises against Figma's AI infrastructure, platforms, and products. Platform Security * Perform technical security assessments, code audits, and ...

Senior Security Engineer

San Jose, CA · On-site

$134K - $184K/yr

Identify, validate, and respond to security incidents with minimal oversight Offensive Security / Red Teaming * Perform red team / adversary simulation exercises to test detection and response ...

Lead Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

They are seeking a Lead Application Security Engineer to own the security of the Ivo platform ... Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive ...

The Penetration Tester is a practicing offensive security professional who independently executes client engagements across DeepSeas' core service lines. This role represents the transition from ...

The security stakes are real, and so is the impact. What You'll Do * Own application security ... Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive ...

Help run penetration testing and offensive security exercises against Figma's AI infrastructure, platforms, and products. Platform Security * Perform technical security assessments, code audits, and ...

Required : • 3+ years of full-time experience in security research, offensive security, or related fields. • Experience with finding vulnerabilities in source code • Experience creating PoC ...

Help run penetration testing and offensive security exercises against Figma's AI infrastructure, platforms, and products. Platform Security * Perform technical security assessments, code audits, and ...

A blend of technical acumen and collaborative skills is essential, as you will develop solutions to identified risks, write test cases for security controls, and actively participate in offensive ...

Showing results 41-60

Offensive Security information

See California salary details

$56.3K

$131.2K

$183.6K

How much do offensive security jobs pay per year?

As of Aug 10, 2026, the average yearly pay for offensive security in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

What is offensive security?

An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.

How much do offensive security engineers make?

Offensive security engineers typically earn between $80,000 and $150,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in penetration testing and exploit development can command higher salaries, often exceeding $150,000.

What does a typical day look like for someone working in offensive security?

A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.

What is the salary of offensive security?

Salaries for offensive security professionals vary based on experience, certifications, and location, but typically range from $70,000 to over $130,000 annually. Entry-level roles may start lower, while experienced penetration testers or security consultants can earn higher salaries, especially with advanced skills and certifications like OSCP or CISSP.

What are the key skills and qualifications needed to thrive in offensive security, and why are they important?

To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

What job categories do people searching Offensive Security jobs in California look for? The top searched job categories for Offensive Security jobs in California are:
What cities in California are hiring for Offensive Security jobs? Cities in California with the most Offensive Security job openings:
Infographic showing various Offensive Security job openings in California as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $131,221 per year, or $63.1 per hour.

Security Engineer

METR

Berkeley, CA • On-site

$285.55 - $503.12/hr

Other

PTO

Posted 10 days ago


Job description

About METR

We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.

METR has consistently set precedents for catastrophic AI risk evaluations, including the first independent safety evaluations (working informally with Anthropic and OpenAI in 2022), the first loss-of-control evaluations and first agentic dangerous capability evaluations, the first evaluations using finetuning (mentioned briefly here), the first independent evaluations using internal information about training, the first review partnership for company risk analysis, the first embedded redteaming, and the first evaluations of internal deployments.

We’ve been consulted and/or favorably referenced by groups on opposite ends of various spectra, including a16z, Khosla, Gary Marcus, Obama, and Dean Ball, and are known for producing one of the most positive results on AI capabilities (the time horizon trend) and the most negative (our downlift study). We’re generally referenced as the canonical third party assessor, e.g. as the obvious candidate to verify conditional pause agreements.

We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.

About the role

Security at METR is becoming its own dedicated team, and you would be one of its first hires. It is extremely important that we continue to be an organization that frontier AI labs, governments, and the public trust with sensitive model access and confidential information. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly heavy pressure.

For us, security encompasses managing endpoints and securing development environments, cloud platform security, safely sandboxing agents and evaluations, VPN and VPC networking, application code reviews, account provisioning and access control, and helping ensure we use the best practices across all of our workflows.

What this role looks like
  • Offensive security: You would be the first person on the team with an offensive security background. You'll run targeted red-team exercises against our own systems and build automated AI red teaming.

  • High-context detection and response: You will build AI systems that can quickly triage and respond to threats, both from internal agents and external attackers.

  • Blue-team engineering: Detection engineering, telemetry pipelines, incident response, and hardening across our cloud infrastructure, endpoints, and identity systems.

  • Securing a unique attack surface: METR's evaluation infrastructure runs frontier AI agents. In the past, we've run pre-deployment model evaluations - executing untrusted, model-generated code at scale on multi-day tasks.

  • Enabling bleeding-edge research: You'll work closely with our researchers to make dangerous-capability experiments safe to run. We often face extreme reward hacking and evaluation awareness during our pre-deployment evaluations, and expect internal threats from agents to become more extreme.

Why this role matters
  • METR handles some of the most sensitive artifacts in AI - pre-release frontier model access, confidential lab information, and transcripts with raw chain-of-thought. Labs and policymakers trust us with this because of our security posture, and keeping that trust is necessary for everything else we do.

  • As AI agents are used more aggressively by malicious actors for cyber offense operations, and METR's salience rises in the public eye, we expect to face increasingly sophisticated attacks. Strengthening security at METR can be one of the highest-leverage roles to ensure third parties continue to have access to confidential information necessary to inform the world about current risks.

  • METR is one of the first organizations to see and closely study misalignment incidents that involve models breaking out of sandboxes, attacking our infrastructure, manipulating graders, and more. We also may pursue incident investigations embedded in frontier labs, in which case internal experience with similar failures will be critical.

Required skills
  • Deep security expertise: You have strong fundamentals across systems, networks, cloud, and identity.
  • Offensive security: You have experience acting like an attacker, whether through red teaming, penetration testing, or adversarial research.
  • AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.
  • AWS: You should know AWS very well, including a deep understanding of IAM policies.

We don't screen on certifications, degrees, or years of experience.

Nice to haves
  • Detection engineering at scale: Experience with SIEM/detection pipelines, writing and tuning detections, and threat hunting.

  • Cloud and container security: AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.

  • Incident response: You've led or worked severe incidents, ideally those involving AI agents.

  • AI security research: Familiarity with prompt injection, agent containment, model supply-chain risks, or red teaming AI systems themselves.

  • AWS: cloud-native software platforms
    • EKS
    • Lambda
    • ECS
    • IAM (in-depth)
    • SQS
    • CloudWatch
    • SecurityHub & GuardDuty
  • PostgreSQL: RLS, serverless Aurora
  • Pulumi: IaC
  • DataDog: SIEM
  • Okta: IdP
  • Google Workspace: IdP
  • Tailscale: networking
  • CrowdStrike Falcon: endpoint security

$285,548 - $503,116 a year

METR also has a host of benefits
  • The office: Catered lunch and dinner daily; in-office gym and shower
  • Relocation support: Stipend for moving to the Bay Area
  • Time-off and leave: Unlimited PTO and 21-week parental leave for new parents
  • Commuter benefit: Monthly transit/parking stipend and an annual Uber budget
  • Professional development benefit: for training, courses, conferences, and AI safety education
  • Mental health benefit: for therapy, medication, and other mental health expenses
  • Wellness benefit: for gym memberships and other wellness expenses
  • Work equipment benefit: for home office and workstation equipment expenses
Our Culture

METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters.

Hybrid Preferred

Our technical team members are in our office in Berkeley 3-5 days/week. We would ideally like for you to be in person too, but we are happy to be flexible here. If you lack US work authorization and would like to work in-person, we can likely sponsor a cap-exempt H-1B visa for this role.

We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.

We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions.

#J-18808-Ljbffr