P

Pensar

AI-driven continuous penetration testing platform

Security Research Engineer

Full-Time
$120k - $175k/yr+ Equity
Senior
Bachelor's
New York, NY, USA
HybridTravel to customer sites is required as needed.

About the job

Requirements
  • At least 5 years of experience in offensive security, penetration testing, red teaming, or vulnerability research.
  • Strong programming skills in multiple languages, including Python, Go, JavaScript, C, and C++.
  • Deep, hands-on understanding of modern vulnerability classes across web, cloud, and infrastructure.
  • A proven track record of running penetration-testing engagements end-to-end and delivering findings to customers.
  • Experience contributing to or maintaining open-source security tooling.
  • A Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
Responsibilities
  • Run end-to-end penetration-testing engagements for customers using Apex, the open-source offensive-security tool.
  • Curate, triage, and contextualize findings for customer audiences ranging from engineers to executives.
  • Deliver prioritized write-ups and walk customers through results, exploitation paths, and remediation.
  • Set up and configure the Pensar platform inside customer environments, including integrations and workflows.
  • Act as a trusted technical partner for customers throughout onboarding, engagements, and ongoing usage.
  • Travel to customer sites as needed for kickoffs, readouts, and on-site testing.
  • Conduct original offensive-security research across web, cloud, infrastructure, and artificial-intelligence/large-language-model attack surfaces.
  • Develop new exploitation techniques, payloads, and tooling that extend Apex's capabilities.
  • Build automated testing methodologies for emerging vulnerability classes and attacker tradecraft.
  • Track the evolving threat landscape and translate it into concrete detections and capabilities.
  • Lead vulnerability research across high-impact open-source projects and ecosystems.
  • Verify findings, build proof-of-concept exploits, and coordinate responsible disclosure with maintainers.
  • Contribute patches, advisories, and tooling back to the open-source community.
  • Grow Pensar's reputation in the security research community through publications, talks, and contributions.
  • Translate firsthand engagement experience into concrete recommendations for the product roadmap.
  • Partner with engineering and product on capabilities, user experience, and automation that make penetration testing faster and more reliable.
  • Participate in architecture and design reviews with a focus on the pentester's workflow.
  • Help shape Apex's direction as an open-source project alongside the internal platform.
Desired Qualifications
  • Experience with artificial-intelligence/large-language-model-assisted offensive security or building security automation on top of large language models.
  • Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or developer-tools company.
  • Security certifications such as OSCP, OSCE, OSWE, GXPN, or equivalent.
  • Public security research, CVEs, conference talks, or notable open-source contributions.
  • Experience with cloud security using AWS, GCP, or Azure and containerized environments.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and PCI DSS as they relate to penetration testing.

About the company

Pensar provides a continuous penetration testing platform called Apex that integrates into the software development lifecycle to identify, exploit, and remediate security vulnerabilities across deployments from development to staging. It uses AI agents and a dynamic threat model based on a client’s business logic to find novel attack paths rather than replaying known patterns. A key feature is auto-remediation: confirmed vulnerabilities are patched via a pull request for developers to review and merge. The goal is to help enterprises accelerate secure software delivery by embedding proactive security into CI/CD, with support for both blackbox and whitebox testing and reduced false positives.

Company Size

1-10

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2015

Get referred to Pensar

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Pensar closed a seed round in 2026 led by Basis Set Ventures.
  • The 2026 product launch targets every deploy, matching faster AI-generated code release cycles.
  • Pensar's reports and human-reviewed sign-off directly address compliance workflows buyers already fund.

What critics are saying

  • Pensar competes against Horizon3 NodeZero, Pentera, NetSPI, and Bishop Fox in 2026.
  • Open-source Apex lowers switching costs and compresses Pensar's hosted-platform pricing power.
  • If enterprises distrust autonomous exploit agents, sales stall before Pensar reaches durable scale.

What makes Pensar unique

  • Pensar released Apex on 2026-03-16 for continuous AI offensive testing in CI.
  • Apex ships verified exploit chains and patch pull requests, not scan-only findings.
  • Pensar offers blackbox and whitebox pentesting with compliance-ready reports for SOC 2 audits.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Company Equity

Professional Development Budget

Remote Work Options

Flexible Work Hours