Array
Array

Senior Offensive Security Engineer

engineeringfull-timeRemote - USA or Canada
SALARY
$170k+/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
fintech
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

About the Role

We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You’re a paid hacker; you'll operate with full access to our applications, source code, and infrastructure to identify vulnerabilities that create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze large codebases, accelerate hypothesis generation, and increase testing coverage while relying on your own judgment to validate results.

You Have

  • 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
  • Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
  • Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
  • Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
  • Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
  • A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.

You Will

  • Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
  • Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
  • Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
  • Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
  • Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
  • Maintain a habit of using AI tools to think, build, and ship faster—it’s your default, not an afterthought.

Success Looks Like

  • Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
  • Security gaps identified that were not detected by existing tools or processes.
  • High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
  • Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.

Pay Transparency

$170,000 + for base salary, depending on experience. Full time employee compensation includes an Incentive Stock Option (ISO) grant, subject to Board approval.

✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now