Skip to main content
Array

Senior Offensive Security Engineer

RemoteUnited States, Canada only
Published
Role
Security
Experience
Senior
Employment
Full-time
$170k+/yr
Check eligibility

Open to US, CA only. Set where you work from to check your eligibility.

No BS summary

Senior offensive security engineer with 5+ years in offensive security, appsec, penetration testing, or red team work. Must be strong in web apps, APIs, auth, distributed systems, OWASP Top 10, PoC exploit development, and AI-assisted vulnerability research. Remote role hiring in the USA or Canada.

Core skills

AIOffensive SecurityPenetration Testing

Required skills

OWASP Top 10

What you'll do

  • Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
  • Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
  • Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
  • Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
  • Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
  • Maintain a habit of using AI tools to think, build, and ship faster—it’s your default, not an afterthought.

What they require

  • 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
  • Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
  • Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
  • Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
  • Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
  • A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.
  • Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
  • Security gaps identified that were not detected by existing tools or processes.
  • High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
  • Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.

Benefits

  • Full medical, dental, and vision, premiums covered at 100% for full-time employees and 70% for dependents
  • Unlimited PTO and sick leave + 14 company holidays to encourage a healthy work-life blend
  • 100% 401k match up to 4% with immediate vesting
  • Generous and competitive parental leave for all parents
  • $1,000 desk setup subsidy to set-up your unique remote office
  • $100/month to subsidize wifi/cell phone expenses
  • Summer Fridays (half-day Fridays) typically from late May to the end of August
  • Commuter benefits for those who choose to go into our New York City or San Francisco office spaces
  • Full time employee compensation includes an Incentive Stock Option (ISO) grant, subject to Board approval.

Array is a financial innovation platform that helps digital brands, financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and identity monitoring tools, privacy protection, and a financial ads marketplace via embeddable widgets or a clean, modern API.

$170k+/yr