The Offensive Security team is the "red" pulse of this organization. We don't just find bugs - we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on ...
The Offensive Security team is the "red" pulse of this organization. We don't just find bugs - we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on ...
Senior Offensive Security Engineer
San Mateo, CA · On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the ...
Senior Offensive Security Engineer
San Mateo, CA · On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the ...
Senior Manager, Offensive Security
Charlotte, NC · On-site
$108K - $146K/yr
The Senior Manager, Offensive Security leads our advanced offensive security program within the Offensive Security & Fraud Testing (OSFT) team. This role oversees all offensive security operations ...
Senior Manager, Offensive Security
Charlotte, NC · On-site
$108K - $146K/yr
The Senior Manager, Offensive Security leads our advanced offensive security program within the Offensive Security & Fraud Testing (OSFT) team. This role oversees all offensive security operations ...
Manager, Offensive Security
Warren, MI · On-site
$104K - $140K/yr
The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback ...
Manager, Offensive Security
Warren, MI · On-site
$104K - $140K/yr
The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback ...
Senior Manager, Offensive Security
Dallas, TX · On-site
$109K - $148K/yr
The Senior Manager, Offensive Security leads our advanced offensive security program within the Offensive Security & Fraud Testing (OSFT) team. This role oversees all offensive security operations ...
Senior Manager, Offensive Security
Dallas, TX · On-site
$109K - $148K/yr
The Senior Manager, Offensive Security leads our advanced offensive security program within the Offensive Security & Fraud Testing (OSFT) team. This role oversees all offensive security operations ...
Application Offensive Security Consultant Location: Jersey City, NJ Duration: 6 Months Contract-to-Hire Position Overview: We are seeking an experienced Application Offensive Security Consultant to ...
Quick apply
Application Offensive Security Consultant Location: Jersey City, NJ Duration: 6 Months Contract-to-Hire Position Overview: We are seeking an experienced Application Offensive Security Consultant to ...
Manager, Offensive Security
Austin, TX · On-site
$110K - $148K/yr
The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback ...
Manager, Offensive Security
Austin, TX · On-site
$110K - $148K/yr
The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback ...
Offensive Security Consultant
Kansas City, MO · On-site
$83K - $128K/yr
Overview Offensive Security Consultant Hack. Discover. Advise. Make an Impact. Are you passionate about breaking things to make them stronger? Do you thrive on uncovering vulnerabilities before ...
Offensive Security Consultant
Kansas City, MO · On-site
$83K - $128K/yr
Overview Offensive Security Consultant Hack. Discover. Advise. Make an Impact. Are you passionate about breaking things to make them stronger? Do you thrive on uncovering vulnerabilities before ...
Senior Principal Engineer, Offensive Security
$190K - $240K/yr
Senior Principal Engineer, Offensive Security (2026-345) Location: San Jose, CA Role Overview Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is ...
Senior Principal Engineer, Offensive Security
$190K - $240K/yr
Senior Principal Engineer, Offensive Security (2026-345) Location: San Jose, CA Role Overview Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is ...
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced adversary emulation operations to replicate cybersecurity threats targeting the firm.
The Offensive Security Team consists of highly skilled and qualified members who conduct advanced adversary emulation operations to replicate cybersecurity threats targeting the firm.
Senior Offensive Security Engineer
San Mateo, CA · On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the ...
Senior Offensive Security Engineer
San Mateo, CA · On-site
$130K - $178K/yr
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the ...
Offensive Security Manager
Washington, DC · On-site
$125K - $169K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Offensive Security Manager
Washington, DC · On-site
$125K - $169K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Senior Offensive Security Engineer
$116K - $145K/yr
Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses * Hands-on Active Directory and internal ...
Senior Offensive Security Engineer
$116K - $145K/yr
Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses * Hands-on Active Directory and internal ...
Senior Offensive Security Engineer
Saint Louis, MO · Remote
$116K - $145K/yr
Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses * Hands-on Active Directory and internal ...
Senior Offensive Security Engineer
Saint Louis, MO · Remote
$116K - $145K/yr
Expert command of offensive security tools including Burp Suite, Kali Linux toolset, and manual exploitation techniques including bypassing modern defenses * Hands-on Active Directory and internal ...
Senior Manager, Offensive Security
$185K - $225K/yr
The Senior Manager, Offensive Security will embrace the opportunity to work across diverse platforms with a variety of tools and will play a key role as we continually improve our capabilities ...
Senior Manager, Offensive Security
$185K - $225K/yr
The Senior Manager, Offensive Security will embrace the opportunity to work across diverse platforms with a variety of tools and will play a key role as we continually improve our capabilities ...
Senior Engineer, Offensive Security
Tampa, FL · On-site
$108K - $148K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Senior Engineer, Offensive Security
Tampa, FL · On-site
$108K - $148K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Senior Engineer, Offensive Security
Washington, DC · On-site
$129K - $177K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Senior Engineer, Offensive Security
Washington, DC · On-site
$129K - $177K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Senior Engineer, Offensive Security
Atlanta, GA · On-site
$110K - $151K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Senior Engineer, Offensive Security
Atlanta, GA · On-site
$110K - $151K/yr
As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on ...
Offensive Security Manager
Cleveland, OH · On-site
$107K - $145K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Offensive Security Manager
Cleveland, OH · On-site
$107K - $145K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Offensive Security Manager
Austin, TX · On-site
$110K - $148K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Offensive Security Manager
Austin, TX · On-site
$110K - $148K/yr
As an Offensive Security Manager, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk ...
Offensive Security information
See salary details
$57K - $68.7K
1% of jobs
$68.7K - $80.5K
4% of jobs
$80.5K - $92.2K
5% of jobs
$92.2K - $103.9K
9% of jobs
$110.4K is the 25th percentile. Wages below this are outliers.
$103.9K - $115.6K
11% of jobs
$115.6K - $127.4K
10% of jobs
The median wage is $131.9K / yr.
$127.4K - $139.1K
28% of jobs
$145.9K is the 75th percentile. Wages above this are outliers.
$139.1K - $150.8K
14% of jobs
$150.8K - $162.5K
11% of jobs
$162.5K - $174.3K
4% of jobs
$174.3K - $186K
4% of jobs
$57K
$133K
$186K
How much do offensive security jobs pay per year?
What is offensive security?
An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.
What does a typical day look like for someone working in offensive security?
A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.
What are the key skills and qualifications needed to thrive in offensive security, and why are they important?
To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.
What cities are hiring for Offensive Security jobs?
Cities with the most Offensive Security job openings:
What states have the most Offensive Security jobs?
States with the most job openings for Offensive Security jobs include:
What job categories do people searching Offensive Security jobs look for?
The top searched job categories for Offensive Security jobs are:

Full-time
Medical, PTO
Re-posted 3 days ago
Job description
Postman is the world's leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration-enabling users to create better APIs, faster.
The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.
P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.
About the Team
The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.
The Offensive Security team is the "red" pulse of this organization. We don't just find bugs - we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.
The Opportunity
We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program - including building out a dedicated Offensive AI Security capability from the ground up - and operate as a key partner to CISO leadership on threat-informed defense strategy.
This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.
You will lead a team that doesn't just "report" vulnerabilities but "demonstrates" them, using live exploits to build a deep, visceral security culture across the entire engineering organization.
What You'll Do
Strategy & Program Ownership
- Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
- Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.
- Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape - OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems - translating external research into internal red team playbooks and detection hypotheses for Security Operations.
- Red Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines - targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
- Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.
- Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
- Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers - including specialized AI red team operators - providing mentorship, career development, and succession planning.
- Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML - a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.
- Drive Security Culture through "The Show": Lead live "Exploitable Demonstrations" - technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.
- Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).
- Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings - especially from AI red team engagements - drive measurable improvements in detection, response, and architecture.
- Experience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.
- AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems - whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.
- Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.
- Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments - extended to AI-native architectures.
- AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.
- Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain - including an AI-specific attack path - to a room of developers in a way that is inspiring, not condescending.
- Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.
- Industry Presence: Track record of contributions to the offensive security or AI security community - conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.
- Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.
- Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.
- API Security Depth: Experience with API-specific attack methodologies - BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation - reflecting Postman's core product domain.
- Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.
The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.
What Else?
In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We're building a long-term company with an inclusive culture where everyone can be the best version of themselves.
At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, New York City, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.
Our Values
At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
Equal opportunity
Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.
About Postman
Sourced by ZipRecruiter
Industry
Software development
Company size
501 - 1,000 Employees
Headquarters location
San Francisco, CA, US
Year founded
2014