Full-Time

Offensive Security Engineer

Agent Harness & Infrastructure, Web & Application Security

Pensar

Pensar

1-10 employees

AI-driven continuous penetration testing platform

No salary listed

New York, NY, USA

In Person

Bachelor's

Category
Cybersecurity (1)
Required Skills
LLM
Rust
Python
JavaScript
Software Testing
Computer Networking
Docker
TypeScript
Go
Observability
Playwright
REST APIs
Penetration Testing
C/C++
Puppeteer
Linux/Unix

Get referred to Pensar

See people who can refer or advise you

Requirements
  • At least 4 years of professional software engineering, security engineering, offensive security engineering, or equivalent experience.
  • Strong software engineering fundamentals and experience building production systems.
  • Strong programming skills in Python, Go, JavaScript or TypeScript, Rust, C or C++, or similar languages.
  • Deep understanding of modern web applications, HTTP, browsers, APIs, authentication, sessions, and application architecture.
  • Working knowledge of common web vulnerability classes and offensive security techniques.
  • Experience building or working with agentic systems, large language model applications, autonomous agents, or complex tool-using artificial intelligence systems.
  • Experience with browser automation technologies such as Playwright, Puppeteer, Chrome DevTools Protocol, or similar tooling.
  • Ability to debug complex systems across application code, infrastructure, networking, and agent behavior.
  • Experience with Linux, containers, cloud infrastructure, and isolated execution environments.
  • Ability to independently investigate ambiguous technical problems and turn findings into production systems.
  • Interest in making autonomous systems reliable in messy real-world environments.
  • A Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
Responsibilities
  • Design and build the agent harness powering autonomous offensive security workflows across Apex and the Pensar platform.
  • Build systems that allow agents to reliably interact with browsers, terminals, HTTP proxies, scanners, APIs, filesystems, and other security tooling.
  • Develop orchestration for long-running, multi-step offensive security tasks involving reconnaissance, exploitation, validation, and reporting.
  • Build abstractions that allow agents to safely and effectively execute tools, inspect results, maintain state, and adapt their approach.
  • Improve agent context management, memory, task decomposition, planning, and execution across complex engagements.
  • Design reliable execution environments for autonomous security agents operating against customer applications and infrastructure.
  • Debug agent trajectories to understand why an agent succeeded, failed, hallucinated, became stuck, or missed an attack path.
  • Build observability and debugging infrastructure for understanding agent behavior at scale.
  • Build autonomous capabilities for discovering and exploiting vulnerabilities in modern web applications and APIs.
  • Develop tooling and workflows around authentication, authorization, session management, API discovery, application state, and complex multi-step attack paths.
  • Enable agents to navigate and understand JavaScript-heavy applications, authenticated applications, APIs, and modern application architectures.
  • Integrate offensive security tooling into autonomous workflows, including proxies, scanners, browsers, custom scripts, and exploitation frameworks.
  • Implement techniques for identifying access control issues, injection vulnerabilities, server-side request forgery, authentication flaws, business logic vulnerabilities, and other application security weaknesses.
  • Translate manual offensive security techniques into primitives and workflows that autonomous agents can execute reliably.
  • Track emerging web exploitation techniques and determine how they can be incorporated into Apex.
  • Build evaluation systems for measuring offensive security agent performance against realistic targets.
  • Develop benchmarks, test environments, and regression suites that measure whether changes improve agent capabilities.
  • Analyze agent trajectories and failure modes across real engagements.
  • Identify systemic weaknesses in agent reasoning, tooling, navigation, and exploitation behavior.
  • Design experiments around prompts, models, tools, context strategies, and orchestration approaches.
  • Work with security researchers to turn newly discovered techniques into reproducible evaluations and agent capabilities.
  • Help establish metrics for autonomous pentesting performance beyond simple vulnerability detection.
  • Contribute directly to Apex, the open source autonomous offensive security tool.
  • Build reusable offensive security primitives shared across Apex and the Pensar platform.
  • Design APIs and internal interfaces for agent execution, tools, environments, and security workflows.
  • Work across the stack when necessary to ship new autonomous capabilities into production.
  • Improve the reliability, performance, and scalability of systems running autonomous security engagements.
  • Collaborate with platform engineers on infrastructure for securely executing large numbers of concurrent agent workloads.
  • Help define the technical architecture of Pensar's autonomous offensive security systems as the platform scales.
  • Work closely with offensive security researchers to understand how experienced human operators approach difficult targets.
  • Convert researcher techniques, workflows, and intuition into software and agent capabilities.
  • Build experimental tooling to test new approaches to autonomous exploitation.
  • Investigate difficult targets where existing agents fail and determine what capabilities are missing.
  • Explore new approaches to browser automation, application understanding, vulnerability discovery, and autonomous exploitation.
  • Contribute to technical research and open source releases around autonomous offensive security.
Desired Qualifications
  • Strong product instincts.

Pensar provides a continuous penetration testing platform called Apex that integrates into the software development lifecycle to identify, exploit, and remediate security vulnerabilities across deployments from development to staging. It uses AI agents and a dynamic threat model based on a client’s business logic to find novel attack paths rather than replaying known patterns. A key feature is auto-remediation: confirmed vulnerabilities are patched via a pull request for developers to review and merge. The goal is to help enterprises accelerate secure software delivery by embedding proactive security into CI/CD, with support for both blackbox and whitebox testing and reduced false positives.

Company Size

1-10

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2015

Get referred to Pensar

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 2026 Console V2 adds continuous reconnaissance and higher-concurrency sandboxing.
  • Pensar claims a broker-dealer with over $100 billion under administration as a customer.
  • Updated August 2026 site shows SOC 2 and OWASP recognition, easing enterprise adoption.

What critics are saying

  • Basis Set-funded seed-stage security startups face brutal competition from Wiz, Snyk, and Tenable.
  • Autonomous exploit generation increases false-positive trust issues; one bad patch damages enterprise credibility fast.
  • If continuous pentesting misses production-only flaws, customers abandon Pensar after the first high-profile breach.

What makes Pensar unique

  • Pensar’s June 2026 Console V2 unifies reconnaissance, threat modeling, and exploitation.
  • Apex verifies working proofs-of-concept, then opens pull requests for remediation.
  • Pensar targets business-logic attack paths, not just scanner-style vulnerabilities, across CI/CD and staging.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Company Equity

Professional Development Budget

Remote Work Options

Flexible Work Hours