Offensive Security Engineer
RunBuggy
Offensive Security Engineer
RunBuggy is the most technically advanced automotive logistics platform on the market. Period. Backed by Porsche Ventures and Hearst Ventures, RunBuggy is transforming the way cars move. Our cutting-edge technology is trusted by some of the largest OEMs, captive finance companies, and automotive lenders in the world to streamline vehicle transportation at scale.
RunBuggy's end-to-end platform connects car shippers and haulers in real time - eliminating the friction of traditional load boards and costly custom software. For shippers, RunBuggy integrates directly into existing management systems, reducing transportation costs and accelerating delivery timelines. For transporters, we offer a smarter, more profitable way to find, accept, and manage loads - all from a single app.
Since launching in 2019, RunBuggy has grown to over 190 team members, facilitated the movement of hundreds of thousands of vehicles, and attracted tens of thousands of transporters across the U.S.
We're not just building a better logistics platform - we're redefining the future of automotive transportation.
About the Role
The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is responsible for proactively identifying, exploiting, and validating vulnerabilities while also partnering with engineering teams to design, implement, and improve security controls across the environment.
This position reports to our Cybersecurity Manager and is a hybrid role (3 days in office per week).
What You Will Be Doing
- Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS), and be able to give hardening suggestions.
- Conduct offensive security engagements, including Red Team operations, threat-based evaluations, and vulnerability research and exploitation against both internal and external-facing systems.
- Plan and execute black-box, grey-box, and white-box web application penetration tests against RunBuggy production and staging environments.
- Maintain tooling (Burp, Metasploit, C2 frameworks, custom scripts) for exploitation, detection validation, and security assessments.
- Conduct API security testing (REST, GraphQL) including authentication bypass, injection, broken object-level authorization (BOLA/IDOR), and business logic flaws.
- Perform cloud configuration reviews (AWS) and assess infrastructure-level exposure where it intersects with web application attack surfaces.
- Produce clear, risk-ranked findings reports with reproducible proof-of-concept and actionable remediation guidance for both technical and non-technical audiences.
- Collaborate with engineering to validate fixes and re-test remediated vulnerabilities.
- Perform social engineering exercises (phishing, credential harvesting), where applicable.
- Contribute to bug bounty triage, third-party assessment coordination, and security tooling selection.
- Support compliance efforts (SOC 2, PCI DSS) by providing evidence and attestation tied to pen test scope and outcomes.
- Stay current on emerging attack techniques and translate threat intelligence into test cases relevant to RunBuggy's stack.
- Other duties as assigned.
Requirements
What You Bring to the Team by Way of Skills and Experience:
- Bachelor's degree in Cybersecurity or related field required.
- 3+ years of hands-on web application penetration testing experience in a professional or consulting capacity.
- Passion and demonstrated experience for challenging security assumptions.
- Deep familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for LLMs.
- Proficiency with standard tooling: Burp Suite, OWASP ZAP, Nmap, Metasploit, SQLmap, Nikto.
- Demonstrated ability to exploit and document authentication/authorization flaws, injection vulnerabilities, XXE, SSRF, deserialization issues, and insecure direct object references.
- Strong written communications: findings reports must be usable by both developers and executives.
- Experience testing RESTful and/or GraphQL APIs.
- Experience with AWS environment security assessment (IAM misconfiguration, S3 exposure, Lambda attack surface).
- Scripting proficiency in Python, Bash, or JavaScript for custom tooling and automation.
- Familiarity with automotive, logistics, or fintech regulatory requirements (PCI DSS, SOC 2 Type II).
- Prior experience in a startup or high-growth SaaS environment where speed and security have to coexist.
Certificates, Licenses, and/or Registrations:
- OSCP, GWAPT, eWPT, or equivalent. CEH is accepted but is less weighted than practical certs.
What is in it for You and Why you Should Apply
- Market-competitive pay based on education, experience, and location.
- Highly competitive medical, dental, vision, Life w/ AD&D, Short-Term Disability insurance, Long-Term Disability insurance, pet insurance, identity theft protection, and a 401(k) retirement savings plan.
- Employee wellness program.
- Employee rewards, discounts, and recognition programs.
- Generous company-paid holidays (12 per year), vacation, and sick time.
- Paid paternity/maternity leave.
- Monthly connectivity/home office stipend if working from home 5 days a week.
- A supportive and positive space for you to grow and expand your career.
Pay Range Disclosure: The advertised range represents the expected pay range for this position at the time of posting based on education, experience, skills, location, and other factors.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
RunBuggy is an equal-opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination, harassment, and retaliation on the basis of race, color, religion, sex (including gender identity and sexual orientation), pregnancy, parental status, national origin, age, disability, genetic information, or any other status protected under federal, state, or local law.
Unsolicited resumes sent via email or LinkedIn Messenger will not be considered.
No agencies, please.
- ...seeking a highly technical, hands‑on Senior Non-Human Identity Engineer to lead the engineering, automation, onboarding, remediation, and... ...teams to ensure non-human identities are properly secured, monitored, and managed throughout their lifecycle. The ideal...SuggestedTemporary workWork at officeHome officeFlexible hours3 days per week
- ...employees and gives the opportunity to truly make a difference in the world. What We’re Looking For: Are you an experienced Security Engineer who thrives at the intersection of cybersecurity and AI? If so, we have an amazing opportunity for you! Iridium is seeking a Senior...SuggestedWork experience placementWork at officeRemote workHome office3 days per week
- A leading satellite communications firm is seeking a Senior Security Engineer to leverage AI for enhancing security capabilities across their unique ground network. The role involves designing AI-augmented security workflows, developing detection-as-code pipelines, and...Suggested
- ...Principal Security Engineer - Temporary We are seeking a visionary Principal Security Engineer - Temporary to architect the next generation of Identity at Achieve. In the evolving Fintech landscape, Identity is no longer just a perimeterit is our primary security fabric...SuggestedTemporary workRemote workWork from home
- ...Security Engineer - Application Security Locations: Charlotte NC, Chandler AZ, Westlake TX (Hybrid), (3 days onsite) Duration: 12+ Months Contract W2 Contract Only Required Qualifications: ~5+ years of Application Security Engineering experience, or equivalent...SuggestedContract workWork experience placement
- ...and vision to protect consumers and help them grow, manage and secure their digital and financial lives. We’re always looking for... ...security framework obligations into prioritised, testable tasks for engineering and platform teams. Define concrete technical control...Flexible hours
$75 - $87 per hour
Title: Sr. Application Security Engineer (Threat Modeler) Location: Onsite based in Tampa, FL; Tempe, AZ; Jersey City, NJ Duration: 12+ months Long Term Project Compensation: $75.00-87.00/hr Work Requirements: US Citizen, GC Holders, or Authorized to Work in the U.S...Contract workFlexible hours- ...Title: Security EngineerLocation: Chandler, AZ - Hybrid 2+ years of Windows Administration experience 2+ years of hands on CrowdStrike... ...business hours Deliver high-quality technical artifacts, engineering solutions aligned with business objectives Desired...
- ...Information Security Engineer This position provides coverage on a weekend shift schedule (Friday Monday, 10:30am 8:30pm AZ Time) in a... ...incident response / threat hunting a plus ~ Knowledge of offensive security, with the ability to think like an adversary when hunting...Work experience placementWork at officeRemote workShift workWeekend work
- Job Title: Active Directory Security Engineer Location: Chandler, AZ (Hybrid) Duration: 18 Month contract Rate: $85-$89/hour W2 Overview We are seeking a senior Active Directory Security Engineer to join a highly specialized engineering team responsible for the design...Contract work
- Matlen Silver is seeking a Senior Active Directory Security Engineer in Chandler, AZ (hybrid). This role focuses on designing and securing large-scale Active Directory environments, leading initiatives for GPO cleanup, and maintaining security best practices. The ideal...
- ...next at Avnet! Job Summary Develops, maintains, and enhances secure cloud platform solutions in support of Business Cloud Services... ...platforms. Works directly with BCS developers, architects, and engineering teams to coordinate remediation activities and resolve...Temporary workWork experience placementLive inFlexible hoursShift work
- Avnet is seeking a Cloud Security Specialist in Tempe, Arizona, to develop and maintain secure cloud platform solutions. The specialist will work with BCS developers and security teams to ensure the secure design and operation of cloud services. The position involves hands...
- Edward Jones is seeking a Solutions Engineer focused on Security in Tempe, AZ. This role involves engineering and scaling security platforms for automated detection and response, while collaborating closely with cross-functional teams. The ideal candidate will have at...
$105k - $185k
...Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made... ...Role Overview We are seeking a forward-thinking Security Engineer to join our team, focusing on SecOps for the cloud architecture...Local areaRemote workShift work- ...Load Balancing Service Fulfillment Engineer, Core Technology Infrastructure Job Description Summary Responsible for... ...designs based on industry best practices, engineering standards and security principles Ensure security controls are implemented and...Work experience placement
- ...service partner. Job Description We are seeking a highly skilled and experienced Director, Information Security for our Security Engineering and Operations team. In this role, you will be responsible for ensuring the security and integrity of our organization...Contract workRemote workWork from home
- ...The Salt River Project (SRP) is seeking an Operational Technology Cyber Security Analyst to join their Security Operations Center in Tempe, Arizona. This role focuses on detecting and responding to cyber security events in SRP's operational technology environments and...Remote work
- Telework Eligible No Major Duties Performs a wide range of duties to include plans, analysis, development, and coordination, as well as evaluation of current NSEP and contingency telecommunications plans (D-16-1). Serves as the primary subject matter technical...Full timeTemporary workRemote work
- ...backups, developing disaster recovery documentation, and administering servers. The ideal candidate will ensure system reliability, security, and performance while assisting with network design and onboarding of new acquisitions. This position offers opportunities for...
- Sentinel Technologies Inc. is seeking a talented and experienced Network Engineer in Tempe, AZ. The ideal candidate will design, implement, and deploy solutions for client organizations' infrastructures while showcasing their experience with various network technologies...Remote jobLocal area
- Salt River Project (SRP) seeks a skilled network engineer to support Water SCADA OT networks, including LANs, WANs, FANs and radio systems. You will design secure networks, interface with IT, manage firewalls, and oversee network monitoring in a hybrid Arizona workplace...
- Kforce Inc is seeking a Senior Network Engineer in Tempe, AZ to design, implement, and support complex enterprise networks. The role involves ensuring the performance and security of LAN, WAN, and wireless environments with a strong focus on reliability. The ideal candidate...
$41.06 - $45 per hour
$41.06 - $45 / hr Information Security Engineer 2 - Chandler, AZ (Hybrid) Contract Duration: 18 Months Required Skills & Experience 2+... ...applied to incident response/threat hunting. Knowledge of offensive security, with the ability to think like an adversary when hunting...Contract workWork at office- Operational Technology Cyber Security Analyst job at SRP. Tempe, AZ. Requisition ID : 18887 Summary The Cyber Security Analyst will work in SRP's Security Operations Center (SOC) which is responsible for detection, response, and remediation of cyber security events across...H1bLocal areaRemote workVisa sponsorshipWork visa3 days per week
$152k - $187k
Waymo is seeking a Security Architect for its Global Security team. The role involves designing security protocols for public engagements and ensuring safety standards are met. The ideal candidate will have 5+ years in corporate security, with a strong focus on event security...- Edward Jones in Tempe, AZ is looking for an Embedded Security Architect to collaborate with solution architecture teams and influence security designs in cloud-native and hybrid solutions. Candidates should have at least 8 years of experience in cybersecurity and must...Flexible hours
$64.35k - $83.65k
...Summary Information Technology Services (ITS) at MCCCD is seeking a vigilant and analytical Cybersecurity Analyst to join our dynamic security team. This role serves as a frontline defender, focusing on the detection, investigation, and containment of security incidents...Full timeTemporary workSummer workWork at officeLocal areaVisa sponsorshipWork visaMonday to FridayFlexible hours- LPL Financial is looking for a Principal Security Architect in Tempe, Arizona. This role involves securing APIs and ensuring compliance with industry standards. The ideal candidate will have extensive experience in security architecture and a strong technical background...
- ...TITLE: Information Security Engineer LOCATION: Chandler, AZ (No relocation assistance offered.) COMPANY DESCRIPTION: Our client is a diversified financial services company providing banking, insurance, investments, mortgage, and consumer and commercial finance...Relocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
- IT security engineer Tempe, AZ
- information technology security engineer Tempe, AZ
- application security engineer Tempe, AZ
- senior application security engineer Tempe, AZ
- aws cloud security engineer Tempe, AZ
- security engineer Tempe, AZ
- senior security operations engineer Tempe, AZ
- senior cloud security engineer Tempe, AZ
- network security engineer Tempe, AZ
- sr information security engineer Tempe, AZ



