2

Remote Exploit Developer Jobs (NOW HIRING)

Utilize advanced GEOINT tools to analyze and exploit remotely sensed data to produce and ... utilizing engineering principles and a physics-based analytical approach * Perform algorithm ...

VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is ... This is a 100% remote role. We're primarily looking for candidates in Greater Boston (MA), Greater ...

... exploit them in the wild. You will lead a high-performing team of Attack Engineers operating at the ... Deep, practical knowledge of vulnerability classes (e.g., remote code execution, authentication ...

As a remote-first company, we're focused on providing opportunities for high performing individuals ... Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and ...

Senior Offensive Security Engineer

OR · On-site +1

$170K/yr

As a remote-first company, we're focused on providing opportunities for high performing individuals ... Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and ...

VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is ... Although this is a 100% remote role, candidates are preferred to be based in the Greater Boston ...

Get to Know Us Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of ... Background in traditional exploit development or vulnerability research. * CTF experience ...

next page

Showing results 1-20

Remote Exploit Developer information

See salary details

$17

$52

$81

How much do remote exploit developer jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for remote exploit developer in the United States is $52.84, according to ZipRecruiter salary data. Most workers in this role earn between $40.38 and $64.66 per hour, depending on experience, location, and employer.

What is a remote exploit developer?

A Remote Exploit Developer is a cybersecurity professional who specializes in identifying, creating, and testing software exploits that can be executed remotely over a network. Their work typically involves finding vulnerabilities in software or hardware systems and developing code that can take advantage of these flaws without physical access to the target device. This role is essential in both offensive security research and defensive security, as it helps organizations understand and mitigate potential risks. Remote Exploit Developers must have strong programming skills, knowledge of operating systems, and an in-depth understanding of security protocols.

What are the key skills and qualifications needed to thrive as a remote exploit developer?

To thrive as a Remote Exploit Developer, you need advanced knowledge of operating systems, vulnerability research, reverse engineering, and strong programming skills in languages like C, C++, Python, or Assembly, often supported by a relevant degree or certifications in cybersecurity. Familiarity with tools such as IDA Pro, Ghidra, Metasploit, and debuggers, as well as experience with fuzzing frameworks and exploit development environments, is crucial. Exceptional problem-solving, persistence, and attention to detail, along with ethical judgment, set top performers apart in this field. These skills are vital for responsibly identifying and demonstrating vulnerabilities, enabling organizations to improve their security and minimize risk.

What are some common challenges faced by remote exploit developers when working collaboratively with distributed security teams?

Remote Exploit Developers often work closely with global security teams, which can present challenges such as coordinating across different time zones, ensuring secure and clear communication, and managing sensitive information. Collaboration typically involves using encrypted channels, detailed code documentation, and regular virtual meetings to share progress and address vulnerabilities. Adapting to asynchronous workflows and maintaining strong team relationships are essential for overcoming these challenges and delivering effective, timely exploit solutions.

What is the difference between Remote Exploit Developer vs Penetration Tester?

AspectRemote Exploit DeveloperPenetration Tester
CredentialsKnowledge of security vulnerabilities, programming skills, certifications like OSCP or CEHSecurity certifications (OSCP, CEH), testing experience, technical background
Work EnvironmentFocus on developing exploits, testing security flaws, often in a controlled environmentSimulating attacks, assessing security posture, often in client or corporate settings
Industry UsageCybersecurity, software security, vulnerability researchCybersecurity, consulting, IT security teams

While both roles require security knowledge and technical skills, Remote Exploit Developers focus on creating and testing exploits to identify vulnerabilities, whereas Penetration Testers simulate attacks to evaluate security defenses. Both roles are essential in cybersecurity but differ in their primary objectives and methods.

More about Remote Exploit Developer jobs

What cities are hiring for Remote Exploit Developer jobs?

Cities with the most Remote Exploit Developer job openings:

What are the most commonly searched types of Exploit Developer jobs?

The most popular types of Exploit Developer jobs are:

What states have the most Remote Exploit Developer jobs?

States with the most job openings for Remote Exploit Developer jobs include:

What are popular job titles related to Remote Exploit Developer jobs?

For Remote Exploit Developer jobs, the most frequently searched job titles are:

Infographic showing various Remote Exploit Developer job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution, with an average salary of $109,905 per year, or $52.8 per hour.

Software Engineer (Web Platform)

San Francisco, CA • Remote

Full-time

Posted 22 days ago


Job description

About Hinoki Security

AI is collapsing the cost of offense. What used to require a skilled exploit developer can increasingly be automated, and defenders are still working from tooling that was designed two decades ago: tools that produce endless lists of findings without telling anyone what actually matters or what to do about it.

Hinoki is building the AI-native platform that fixes this. We continuously map an enterprise's real exposure, figure out what is genuinely dangerous in the customer's specific environment, and drive the remediation through to verified resolution. Old scanners produce lists. We produce fixes.

We're backed by Andreessen Horowitz and led by a second-time security founder, most recently from Google. The platform is already in production at Fortune 500 enterprises.

 The role

This is a critical engineering hire to own our frontend end-to-end. You'll be responsible for the product surface our customers interact with every day. That includes the verification flows where analysts confirm our agents' work, investigative features where security engineers confirm vulnerabilities on remote assets using AI agents, and the reporting surfaces where investigations turn into reports.

We are looking for someone who treats frontend as a specialty and pushes the boundary of frontend performance. If optimizing React and diving into the latest RSC innovations excite you, then you would find this role very fun.

What we're looking for

Three to six years of engineering experience, plus:

  • Deep React expertise. You should be the person other engineers come to when they hit a wall in React. Reasoning about the rendering model and hook internals shouldn't require a trip to the docs, and you've spent enough time in DevTools to know what a bad render trace looks like at a glance. Bonus if you've been following the RSC work closely or have strong opinions on Suspense boundaries.

  • A point of view on performance. Tell us what you measure and why, and walk us through a piece of performance work you're proud of.

  • Product sense. Show us something you shipped where the small details actually show. Things like empty states that don't feel like an afterthought, tiny shortcuts that users naturally discover, motion that helps comprehension instead of decorating.

  • AI-native workflow. Claude Code, Codex, or Cursor is in your daily loop. You can articulate where these tools help and where they don't.

  • High agency. You read a plan doc and ship. You don't wait for design tickets. You fix what's broken regardless of whose code it is.

  • Taste for small, reversible changes. You know when to extract a component and when to keep markup inline. You don't ship 800-line refactors when 30 lines would do.

We work in TypeScript and C++ but care more about engineering depth than specific languages. No security background required. We'll teach you the domain.