Offensive Security Engineer
Replit
Offensive Security Engineer
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence" for Replit's cloud-native platform. At Replit, security isn't just about perimeter defense; it's about the integrity of the code that powers millions of environments.
In this role, you will lead advanced "whitebox" penetration testing engagements—diving deep into our source code to identify systemic weaknesses, logic flaws, and architectural gaps. You will simulate sophisticated adversary tactics across our web applications, APIs, and containerized infrastructure, ensuring that our AI-integrated development environment remains the most secure place for the world's software to live.
What You'll Do
Lead Whitebox Penetration Testing: Execute end-to-end testing with full access to source code. You will perform manual code-level inspections to uncover complex logic flaws and authorization bypasses that automated tools miss.
Simulate Adversarial Attacks: Conduct Red and Purple team engagements across our cloud-native stack (K8s, Docker), simulating how a sophisticated actor might move from a code-level exploit to infrastructure-wide impact.
Secure AI-Enabled Systems: Perform offensive testing on LLM-backed applications and agentic AI workflows, focusing on prompt injection, data leakage, and abuse of AI-driven components.
Vulnerability Research & Chaining: Identify, exploit, and demonstrate realistic business risk by chaining vulnerabilities—from the application layer down through our internal trust boundaries.
Build Offensive Tooling: Contribute to internal security frameworks and build AI-assisted testing tools to automate the discovery of common bug classes while maintaining deep manual testing depth.
Partner with Engineering: Work closely with product teams and security architects to explain root causes, influence design guardrails, and triage high-priority findings from our Bug Bounty (HackerOne) program.
Required Skills & Experience
Experience: 7+ years of hands-on experience in penetration testing, offensive security, or vulnerability research.
Code Fluency: You are a practitioner of whitebox testing. You can navigate large codebases and have a deep understanding of modern application architectures and secure coding pitfalls.
Cloud-Native Context: You are comfortable in a cloud-native environment. While your focus is the code, you understand how it interacts with Kubernetes, Docker, and hybrid cloud infrastructure.
Engineering Skills: Strong proficiency in Go, Python, or TypeScript. You should be capable of writing custom scripts, payloads, and proof-of-concept exploits.
Adversarial Mindset: You enjoy the "hunt" and have a proven track record of manual exploitation beyond automated scanners.
Communicator: You can translate a complex code-level exploit into a clear narrative that helps engineering teams understand risk and prioritize fixes.
Bonus Qualifications
Public recognition on platforms like HackerOne or Bugcrowd.
Experience building or extending AI-based security testing tools.
Background in incident response or detection engineering from the defensive side.
Published CVEs or security research in the cloud-native or AI space.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
Competitive Salary & Equity
401(k) Program with a 4% match (US Only)
Health, Dental, Vision and Life Insurance
Short Term and Long Term Disability
Paid Parental, Medical, Caregiver Leave
Flexible Time Off (FTO) + Holidays
Commuter Benefits (In-Office Only)
Monthly Wellness Stipend
Autonomous Work Environment
In Office Set-Up Reimbursement (In-Office Only)
Quarterly Team Gatherings
In Office Amenities (In-Office Only)
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
- ...are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program... ...platform. You will own the lifecycle of security vulnerabilities affecting our products... ...Pentesting background or exposure to offensive security work. Familiarity with compliance...SuggestedFull timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$180k - $220k
...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative AI infrastructure. Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry. We've been independently benchmarked...Suggested$200k - $300k
...Staff+ Security Engineer, IT and Corporate Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security...SuggestedFull timeWork visaFlexible hoursShift work$269.17k - $326.06k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone. The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable...SuggestedFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$100k - $300k
...Embedded Security Engineer San Mateo Company Overview At Skild AI, we are building the world's first general purpose robotic intelligence... ...cases for security controls, and actively participate in offensive security assessments. Responsibilities Conduct...Suggested- ...Mid-Level Appsec Vulnerability Management Engineer We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong... ...development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify...Full timeTemporary workWork at officeImmediate startMonday to FridayFlexible hours
- ...Job Description: We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Network Security Engineer will support the implementation, maintenance...Remote work
$64 - $74 per hour
...JOB TITLE: Network Security Engineer LOCATION: Foster City, CA (Onsite) PAY RANGE: $64 - $74/hr. DURATION: 6 Months TOP 3 SKILLS: 4+ years of Network Security Engineer experience supporting production environments 4+ years of IT systems/application...Hourly payFull timeRemote work- ...Senior Security Engineer We're a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer, more efficient, and more capable. Backed by top investors, we've secured a dozen Department of Defense contracts and partnered with...Permanent employmentFull timeLocal areaRemote work3 days per week
$80 per hour
...Our client, a leading organization in autonomous mobility, is seeking a dedicated Network Security Engineer to join their dynamic team. As a Network Security Engineer, you will be integral to supporting the security infrastructure that safeguards our customers, staff,...Weekly payTemporary workRemote workFlexible hours- ...to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance...Full timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
$326.06k - $385.05k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$269.17k - $326.06k
...unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$195k - $300k
...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology for plaintiff law firms, and we're building... ...with the evolving security landscape, especially AI-enabled offensive and defensive techniques, and translating that judgment into...Temporary workWork at officeLocal areaFlexible hours$130k - $280k
...platform that includes solutions for video security, access control, air quality sensors,... ...About the role As an embedded security engineer on the Device Security Team, you'll work... ...best practices. Perform red team/offensive assessments against firmware & devices....Full timeWork visaFlexible hoursShift work- ...'s degree in computer science, Cybersecurity, or related field • 8+ years of combined experience in software development, security engineering and security regulatory and compliance, with at least 5 years of experience in security engineering • Strong understanding...
$190k - $230k
...Security isn't just a checkbox at Delight.ai. It's the foundation everything else is built on. If you believe security should accelerate... ...understood, seen, and remembered. Why Enterprise Security Engineer We're building AI that handles real customer conversations...Temporary workWork at officeRemote workFlexible hoursShift work3 days per week$200k - $240k
...largest organizations to empower scientists, engineers, financial experts, product creators,... ...About the Role We are seeking a Security Engineer to evolve Snorkel's security posture... ...and Response (SOAR) playbooks Offensive security : penetration testing, red team...Local area$137.86k - $240k
...Product Security Engineer, Operating System San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role We are seeking a Product Security Engineer with expertise in operating...Local area$293.8k - $343.34k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security strategy by shaping and evolving security architecture in alignment with...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$137.86k - $240k
...Product Security Engineer, Cryptography & PKI San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As a Product Security Engineer specializing in cryptography...Local areaRemote work- ...Bloom Talent Partners is seeking a Cloud Security Engineer in San Mateo, California. The ideal candidate will focus on automating security measures and developing secure coding practices within cloud environments. This role requires expertise in Docker, Kubernetes, and...
$158.9k - $238.3k
...excellence and creativity. We are looking for an inspirational and hardworking person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team of innovative engineers who are unified in their mission to make PlayStation the best...$180k - $235k
...Senior Cloud Security Architect, Security Engineering San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As the Senior Cloud Security Architect, you will design...Local area$216.68k - $269.17k
...and helping to create safer, more civil shared experiences for everyone. Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to ensure the security of our platform. You will work on scaling vulnerability...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$145k - $240k
...SuperDial is building the automation engine that fixes revenue cycle management. We work with leading MSOs, DSOs, RCM vendors, and health... ...into enterprise environments and mission critical workflows, security is a first-principles priority. We are hiring a Senior...$137.86k - $240k
...Product Security Engineer, Cloud & Infrastructure San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As a Product Security Engineer focused on cloud and infrastructure...Local area$230k - $275k
...centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those... ...startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team...InternshipWork at officeLocal area$130k - $280k
...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and... ...training and information sharing * Partner closely with engineering and product teams to improve the security of Verkada’s products...Full timeWork visaFlexible hoursShift work$200k - $300k
...Staff Backend Engineer - Device Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their... ...build stronger and more resilient products through our offensive security evaluation efforts. If you love building scalable...Full timeWork visaFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
- senior application security engineer San Mateo, CA
- sr information security engineer San Mateo, CA
- security engineer San Mateo, CA
- aws cloud security engineer San Mateo, CA
- network security engineer San Mateo, CA
- senior cloud security engineer San Mateo, CA
- IT security engineer San Mateo, CA
- information technology security engineer San Mateo, CA
- security software engineer San Mateo, CA
- information system security engineer

