Haystack
← Back to Jobs
Technology
PT

Security Engineer Offensive Security | Bug Bounty | Penetration Testing | AI Security

Projas Technologies, LLCSan Diego, CA🇺🇸United StatesPosted Sep 17, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
San Diego, CA, United States
Posted
22 hours ago
OWASPLLMPenetration TestingPythoniOSAndroid

Job Description

Security Engineer Offensive Security | Bug Bounty | Penetration Testing | AI Security | Remote

About the Role

We are seeking a skilled Security Engineer Offensive Security to join our Offensive Security Group. In this highly collaborative role, you will work directly with security researchers, product engineering teams, and internal security stakeholders to identify, validate, prioritize, and drive remediation of security vulnerabilities across products and services.

This position is ideal for a security professional with experience in bug bounty programs, vulnerability disclosure, penetration testing, application security, and AI/LLM security testing. You will play a critical role in protecting customers and products against emerging threats while helping strengthen security posture across the organization.

Key Responsibilities

  • Triage and validate incoming bug bounty and vulnerability disclosure submissions.
  • Analyze reported vulnerabilities, assess severity, impact, exploitability, and business risk.
  • Reproduce reported security findings and validate proof-of-concept exploits.
  • Create high-quality vulnerability reports with clear remediation guidance for engineering teams.
  • Track vulnerabilities through remediation and verify fixes.
  • Partner with product teams, security teams, and external security researchers to ensure timely resolution of security issues.
  • Serve as a liaison between internal stakeholders and external security researchers.
  • Conduct security testing across web applications, APIs, desktop applications, mobile applications, and emerging AI technologies.
  • Support Responsible AI security initiatives and penetration testing efforts involving LLM and AI-enabled applications.
  • Collaborate with offensive security team members on vulnerability analysis and security assessments.
  • Maintain awareness of emerging attack techniques, zero-day vulnerabilities, exploit trends, and offensive security tools.
  • Contribute to security testing projects and additional offensive security initiatives as needed.

Required Qualifications

  • 3+ years of experience in cybersecurity with at least 2+ years focused on offensive security.
  • Hands-on experience in one or more of the following:
    • Web Application Security Testing
    • API Security Testing
    • Mobile Application Security Testing
    • Desktop Application Security Testing
    • Source Code Review / Secure Code Assessment
    • AI / LLM Security Testing
  • Experience triaging and validating vulnerability reports from bug bounty or vulnerability disclosure programs.
  • Strong understanding of vulnerability exploitation techniques and remediation practices.
  • Deep knowledge of OWASP Top 10 vulnerabilities and common application security risks.
  • Experience using penetration testing methodologies, vulnerability scanners, and security assessment tools.
  • Experience with Python or similar scripting languages for automation and security testing.
  • Familiarity with Claude Code, Codex, or AI-assisted development/security tooling.
  • Strong analytical, investigative, and troubleshooting skills.
  • Experience communicating technical security risks to technical and non-technical audiences.
  • Excellent written communication and vulnerability report writing skills.
  • Experience working with ticketing and vulnerability management systems.

Preferred Qualifications

  • Experience within FinTech or highly regulated industries.
  • Participation in bug bounty programs and responsible disclosure initiatives.
  • Active involvement in the security community through research, blogs, talks, presentations, or published findings.
  • Experience testing mobile platforms including Android and iOS.
  • Development experience related to mobile applications or security tooling.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related discipline.
  • Industry certifications such as OSCP, GPEN, GWAPT, GXPN, or equivalent offensive security certifications.

Why Apply?

  • Work alongside leading security researchers and offensive security professionals.
  • Gain exposure to modern application, cloud, and AI security challenges.
  • Participate in bug bounty, vulnerability disclosure, and penetration testing programs.
  • Contribute to responsible AI security initiatives and emerging technology assessments.
  • Make a direct impact on the security of products used by customers worldwide.

Offensive Security, Application Security, AppSec, Penetration Testing, Pentesting, Vulnerability Assessment, Vulnerability Management, Vulnerability Disclosure, Bug Bounty, Security Research, Security Testing, Web Application Security, API Security, Mobile Security, Android Security, iOS Security, Desktop Application Security, Source Code Review, Source Code Auditing, Secure Code Review, OWASP, OWASP Top 10, Vulnerability Analysis, Exploit Development, Proof of Concept, POC Validation, Responsible Disclosure, Threat Modeling, Security Engineering, Ethical Hacking, Red Team, Red Teaming, Offensive Security Engineer, Python, Scripting, Security Automation, Claude Code, Codex, AI Security, LLM Security, Responsible AI, GenAI Security, AI Red Teaming, Security Researcher, Vulnerability Triage, Security Assessment, Dynamic Testing, Static Analysis, SAST, DAST, Secure SDLC, FinTech Security


Offensive Security Engineer, Application Security Engineer, AppSec Engineer, Senior Application Security Engineer, Penetration Tester, Pen Tester, Security Consultant, Offensive Security Consultant, Red Team Operator, Red Team Engineer, Vulnerability Researcher, Security Researcher, Security Engineer, Product Security Engineer, Product Security Consultant, Cybersecurity Engineer, Ethical Hacker, Offensive Security Analyst, Security Analyst, Application Security Analyst, Vulnerability Management Engineer, Bug Bounty Hunter, Security Assessment Engineer, Threat Researcher, AI Security Engineer, LLM Security Engineer, GenAI Security Engineer, Mobile Security Engineer, Web Security Engineer, API Security Engineer, Secure Code Reviewer, Secure Software Security Engineer, Offensive Security Specialist, Cyber Security Engineer, Information Security Engineer


Security Engineer | Offensive Security | AppSec | Penetration Testing | Bug Bounty | Remote

  • Offensive Security Engineer
  • Application Security Engineer (AppSec)
  • Penetration Tester / Security Researcher
  • Product Security Engineer
  • Offensive Security Consultant
  • AI Security Engineer | AppSec
  • Vulnerability Researcher | Offensive Security
  • Security Engineer | Vulnerability Management & Penetration Testing

Similar jobs