2

Remote Exploit Developer Jobs in Oregon (NOW HIRING)

As a remote-first company, we're focused on providing opportunities for high performing individuals ... Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and ...

Red Team Consultant

OR · On-site +1

We're seeking remote, US or Mexico-based hacking professionals focused on red teaming to join our ... Proficiency in multiple programming languages (preferably Python, Golang, JavaScript/TypeScript, C# ...

We're seeking remote, US or Mexico-based hacking professionals focused on red teaming to join our ... Proficiency in multiple programming languages (preferably Python, Golang, JavaScript/TypeScript, C# ...

Remote Exploit Developer information

What is a remote exploit developer?

A Remote Exploit Developer is a cybersecurity professional who specializes in identifying, creating, and testing software exploits that can be executed remotely over a network. Their work typically involves finding vulnerabilities in software or hardware systems and developing code that can take advantage of these flaws without physical access to the target device. This role is essential in both offensive security research and defensive security, as it helps organizations understand and mitigate potential risks. Remote Exploit Developers must have strong programming skills, knowledge of operating systems, and an in-depth understanding of security protocols.

What are the key skills and qualifications needed to thrive as a remote exploit developer?

To thrive as a Remote Exploit Developer, you need advanced knowledge of operating systems, vulnerability research, reverse engineering, and strong programming skills in languages like C, C++, Python, or Assembly, often supported by a relevant degree or certifications in cybersecurity. Familiarity with tools such as IDA Pro, Ghidra, Metasploit, and debuggers, as well as experience with fuzzing frameworks and exploit development environments, is crucial. Exceptional problem-solving, persistence, and attention to detail, along with ethical judgment, set top performers apart in this field. These skills are vital for responsibly identifying and demonstrating vulnerabilities, enabling organizations to improve their security and minimize risk.

What are some common challenges faced by remote exploit developers when working collaboratively with distributed security teams?

Remote Exploit Developers often work closely with global security teams, which can present challenges such as coordinating across different time zones, ensuring secure and clear communication, and managing sensitive information. Collaboration typically involves using encrypted channels, detailed code documentation, and regular virtual meetings to share progress and address vulnerabilities. Adapting to asynchronous workflows and maintaining strong team relationships are essential for overcoming these challenges and delivering effective, timely exploit solutions.

What is the difference between Remote Exploit Developer vs Penetration Tester?

AspectRemote Exploit DeveloperPenetration Tester
CredentialsKnowledge of security vulnerabilities, programming skills, certifications like OSCP or CEHSecurity certifications (OSCP, CEH), testing experience, technical background
Work EnvironmentFocus on developing exploits, testing security flaws, often in a controlled environmentSimulating attacks, assessing security posture, often in client or corporate settings
Industry UsageCybersecurity, software security, vulnerability researchCybersecurity, consulting, IT security teams

While both roles require security knowledge and technical skills, Remote Exploit Developers focus on creating and testing exploits to identify vulnerabilities, whereas Penetration Testers simulate attacks to evaluate security defenses. Both roles are essential in cybersecurity but differ in their primary objectives and methods.

What are popular job titles related to Remote Exploit Developer jobs in Oregon?

For Remote Exploit Developer jobs in Oregon, the most frequently searched job titles are:

Infographic showing various Remote Exploit Developer job openings in Oregon as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution.

Senior Offensive Security Engineer

Array

OR • On-site, Remote

$170K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 21 days ago


Job description

Array is a financial innovation platform that helps digital brands, financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and identity monitoring tools, privacy protection, and a financial ads marketplace via embeddable widgets or a clean, modern API.  Our private label offerings help drive revenue and increase engagement for our customers while empowering millions of consumers to achieve their financial goals.

As a remote-first company, we're focused on providing opportunities for high performing individuals to have deep impact in the fast growing fintech space. A clear mission, a commitment to continuous improvement and a willingness to experiment empower us individually and together deliver the best products for our clients and users.

We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You're a paid hacker; you'll operate with full access to our applications, source code, and infrastructure to identify vulnerabilities that create meaningful business risk-not theoretical findings. AI should be one of your primary tools, enabling you to analyze large codebases, accelerate hypothesis generation, and increase testing coverage while relying on your own judgment to validate results.

You Have:

  • 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
  • Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
  • Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
  • Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
  • Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
  • A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.

You Will:

  • Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
  • Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
  • Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
  • Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
  • Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
  • Maintain a habit of using AI tools to think, build, and ship faster-it's your default, not an afterthought.

Success Looks Like:

  • Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
  • Security gaps identified that were not detected by existing tools or processes.
  • High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
  • Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.

Pay transparency: $170,000 + for base salary, depending on experience. Full time employee compensation includes an Incentive Stock Option (ISO) grant, subject to Board approval.

Expected interview process: Recruiter Conversation - Hiring Manager Interview - Loop round: How We Work, Engineering leadership. 

Array Offers All Full Time Employees the following Benefits and Perks: 

  • Full medical, dental, and vision, premiums covered at 100% for full-time employees and 70% for dependents
  • Unlimited PTO and sick leave + 14 company holidays to encourage a healthy work-life blend
  • 100% 401k match up to 4% with immediate vesting 
  • Generous and competitive parental leave for all parents
  • $1,000 desk setup subsidy to set-up your unique remote office 
  • $100/month to subsidize wifi/cell phone expenses
  • Summer Fridays (half-day Fridays) typically from late May to the end of August
  • Commuter benefits for those who choose to go into our New York City or San Francisco office spaces

Not sure if you meet the Qualifications? We know that folks tend to only apply if they check every box. If you think you have the appropriate qualifications, but don't meet every single one, we encourage you to still apply. We'd love to hear from you.

We are proud to be an equal opportunity workplace; we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Array will provide reasonable accommodations to qualified applicants-if you need an accommodation to participate in the application or interview process, please email talent@array.com to make your request.

Array uses CLEAR to conduct identity verification as part of the application process. We encourage you to review CLEAR's Privacy Notice and Terms of Use to understand how your personal data will be processed.