Talent.com
Pensar
Offensive Security Agent EngineerPensar • New York, NY, US
Offensive Security Agent Engineer

Offensive Security Agent Engineer

Pensar • New York, NY, US
4 days ago
Job type
  • Full-time
  • Quick Apply
Job description

We are seeking an Offensive Security Agent Engineer to build the systems that power autonomous offensive security across Apex and the Pensar platform. You'll work at the intersection of software engineering, offensive security, and AI agents, building the harnesses, tools, execution environments, and workflows that allow autonomous agents to discover and exploit vulnerabilities in real-world applications.

This is an engineering role focused heavily on web security and agentic systems. You'll work on everything surrounding the model itself: how agents interact with browsers, terminals, proxies, scanners, and custom security tools; how they maintain context and reason across long-running engagements; how they explore complex applications; and how we evaluate whether they are actually becoming better offensive security operators.

You'll work closely with our security researchers, AI engineers, and product engineers to turn offensive security techniques into reliable autonomous capabilities. When an agent fails to find a vulnerability, gets stuck in an application, uses a tool incorrectly, or takes an inefficient attack path, you'll dig into why and build the systems that make it better.

The ideal candidate is a strong software engineer who understands how modern web applications break, is deeply interested in agentic systems, and wants to build autonomous security infrastructure rather than simply use existing AI tooling.

Key Responsibilities

Agent Harness & Infrastructure

  • Design and build the agent harness powering autonomous offensive security workflows across Apex and the Pensar platform
  • Build systems that allow agents to reliably interact with browsers, terminals, HTTP proxies, scanners, APIs, filesystems, and other security tooling
  • Develop orchestration for long-running, multi-step offensive security tasks involving reconnaissance, exploitation, validation, and reporting
  • Build abstractions that allow agents to safely and effectively execute tools, inspect results, maintain state, and adapt their approach
  • Improve agent context management, memory, task decomposition, planning, and execution across complex engagements
  • Design reliable execution environments for autonomous security agents operating against customer applications and infrastructure
  • Debug agent trajectories to understand why an agent succeeded, failed, hallucinated, became stuck, or missed an attack path
  • Build observability and debugging infrastructure for understanding agent behavior at scale

Web & Application Security

  • Build autonomous capabilities for discovering and exploiting vulnerabilities in modern web applications and APIs
  • Develop tooling and workflows around authentication, authorization, session management, API discovery, application state, and complex multi-step attack paths
  • Enable agents to navigate and understand JavaScript-heavy applications, authenticated applications, APIs, and modern application architectures
  • Integrate offensive security tooling into autonomous workflows, including proxies, scanners, browsers, custom scripts, and exploitation frameworks
  • Implement techniques for identifying vulnerability classes such as access control issues, injection vulnerabilities, SSRF, authentication flaws, business logic vulnerabilities, and other application security weaknesses
  • Translate manual offensive security techniques into primitives and workflows that autonomous agents can execute reliably
  • Track emerging web exploitation techniques and determine how they can be incorporated into Apex

Agent Evaluation & Improvement

  • Build evaluation systems for measuring offensive security agent performance against realistic targets
  • Develop benchmarks, test environments, and regression suites that measure whether changes actually improve agent capabilities
  • Analyze agent trajectories and failure modes across real engagements
  • Identify systemic weaknesses in agent reasoning, tooling, navigation, and exploitation behavior
  • Design experiments around prompts, models, tools, context strategies, and orchestration approaches
  • Work with security researchers to turn newly discovered techniques into reproducible evaluations and agent capabilities
  • Help establish metrics for autonomous pentesting performance beyond simple vulnerability detection

Apex & Platform Engineering

  • Contribute directly to Apex, our open source autonomous offensive security tool
  • Build reusable offensive security primitives that can be shared across Apex and the Pensar platform
  • Design APIs and internal interfaces for agent execution, tools, environments, and security workflows
  • Work across the stack when necessary to ship new autonomous capabilities into production
  • Improve the reliability, performance, and scalability of systems running autonomous security engagements
  • Collaborate with platform engineers on infrastructure for securely executing large numbers of concurrent agent workloads
  • Help define the technical architecture of Pensar's autonomous offensive security systems as the platform scales

Offensive Security Research

  • Work closely with offensive security researchers to understand how experienced human operators approach difficult targets
  • Convert researcher techniques, workflows, and intuition into software and agent capabilities
  • Build experimental tooling to test new approaches to autonomous exploitation
  • Investigate difficult targets where existing agents fail and determine what capabilities are missing
  • Explore new approaches to browser automation, application understanding, vulnerability discovery, and autonomous exploitation
  • Contribute to technical research and open source releases around autonomous offensive security

Reports To

CTO

We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.

Requirements

  • 4+ years of professional software engineering, security engineering, offensive security engineering, or equivalent experience
  • Strong software engineering fundamentals and experience building production systems
  • Strong programming skills in Python, Go, JavaScript/TypeScript, Rust, C/C++, or similar languages
  • Deep understanding of modern web applications, HTTP, browsers, APIs, authentication, sessions, and application architecture
  • Working knowledge of common web vulnerability classes and offensive security techniques
  • Experience building or working with agentic systems, LLM applications, autonomous agents, or complex tool-using AI systems
  • Experience with browser automation technologies such as Playwright, Puppeteer, Chrome DevTools Protocol, or similar tooling
  • Ability to debug complex systems across application code, infrastructure, networking, and agent behavior
  • Comfortable working with Linux, containers, cloud infrastructure, and isolated execution environments
  • Ability to independently investigate ambiguous technical problems and turn findings into production systems
  • Strong product instincts and an interest in making autonomous systems reliable in messy real-world environments
  • Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience

Benefits

  • Comprehensive health, dental, and vision insurance
  • Direct ownership of core autonomous offensive security infrastructure
  • Opportunity to build agentic security systems operating against real-world applications
  • Work directly with offensive security researchers and engineers pushing the capabilities of autonomous pentesting
  • Professional development budget for conferences, training, and certifications
  • Support for publishing research, open source work, and presenting at industry conferences
  • Direct, visible impact on Apex and the Pensar platform
Create a job alert for this search

Offensive Security Agent Engineer • New York, NY, US

Similar jobs

Cyber Security Detection Engineer - (Fulltime)100% Remote

ICONMAJersey City, NJ, United States
Remote
Full-time

Over 8 years of Information Security or Intelligence experienceDeep experience as a Cyber Security Detection Engineer focusing on Microsoft Azure.To include experience with Defender for Cloud, Entr... Show more

 • Promoted

Security Agent - LGA

ACTS-Aviation Security IncNew York City, NY, United States
Full-time

Join a Global Leader in Aviation Security!Work in a World Class Catering Facility!Starting pay $22.Hour Free Health, Dental and Vision Insurance for Employee Only!401K with company matching! Paid v... Show more

 • Promoted

Security

TradeJobsWorkforce10705 Yonkers, NY, US
$14.00 hourly
Full-time

Hiring patrol officers for assignments.Must be able to work any shift/days.Uniforms and equipment provided.All applicants must pass a pre-employment drug screen, background check and polygraph Ess... Show more

 • Promoted

Airport Security Agent PT (44747)

Inter-Con SecurityNew York City, NY, United States
Full-time +1

Company Overview:Founded in 1973, Inter-Con Security Systems, Inc.US-owned security company, providing integrated security solutions to government and commercial customers on four continents.Inter-... Show more

 • Promoted

Principal Cyber Security Engineer

Hatch Global SearchTinton Falls, New Jersey, United States
Full-time

Principal Cyber Security Engineer.Principal Cyber Security Engineer.Monmouth County, NJ based client.This senior-level position requires deep technical knowledge and advanced problem-solving skills... Show more

Cyber Security Engineer

Hatch Global SearchTinton Falls, New Jersey, United States
Full-time

Principal Cyber Security Engineer.Principal Cyber Security Engineer.Monmouth County, NJ based client.This senior-level position requires deep technical knowledge and advanced problem-solving skills... Show more

Overnight Surveillance Security Agent

GardaWorldEatontown, NJ, United States
Part-time

Job DescriptionGardaWorld Security Services is Now Hiring a Surveillance Security Officer!Ready to suit up as a Surveillance Security Guard?What matters most about a role like this is your sharp ey... Show more

 • Promoted

Specialist Solutions Engineer - Security

AHEAD USANew York City, NY, United States
Full-time

AHEAD builds platforms for digital business.By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digi... Show more

 • Promoted

Senior Security Engineer Remote, Equity & Benefits

GoFundMeNew York City, NY, United States
Remote
Full-time

A leading charitable organization in New York is seeking a Senior Security Engineer to ensure a secure giving platform.The role involves conducting application security assessments, collaborating w... Show more

 • Promoted

Senior Threat Detection Content Engineer - Remote

BlueVoyantNew York City, NY, United States
Remote
Full-time

A cybersecurity firm is seeking a Security Consultant for a fully remote position focused on developing automated security analysis solutions.The role requires expertise in detection logic and coll... Show more

 • Promoted

Senior Security Architect

TradeJobsWorkForce10701 Yonkers, NY, US
Full-time

Senior Security Architect Job Duties: Enhances security team accomplishments and competence by planning deliv... Show more

 • Promoted

Director of Engineering

DoubleTree by Hilton Miami Airport Convention CenterLong Branch, NJ, United States
Full-time

Ocean Place Resort & Spa is seeking an experienced and driven Chief Engineer to oversee all aspects of our engineering and facilities operations.This leadership role is responsible for protecting a... Show more

 • Promoted

Security Specialist

Gaton And Gaton Security ConsultantBronx, NY, United States
Full-time

Benefits:Enjoy free uniforms as part of our team!Join our dedicated workforce as a Security Specialist, where your mission is to uphold the safety and security of our premises, creating a secure an... Show more

 • Promoted

Remote Enterprise Security Engineer Zero-Trust & Cloud

OpenAINew York City, NY, United States
Remote
Full-time

OpenAI is seeking an Enterprise Security Engineer responsible for securing internal information systems and implementing security policies.This role involves close collaboration with IT teams to en... Show more

 • Promoted

Quality Assurance & EHS Manager

HR Journals LLCLong Branch, NJ, United States
Full-time

Quality Assurance & EHS Manager.We are seeking an experienced Quality Manager to lead site-level quality and EHS initiatives at its Long Branch, NJ facility.This role is responsible for administeri... Show more

 • Promoted

Director, Cyber Security

Veracity SolutionsMontvale, NJ, United States
Full-time

Montvale, NJ, Ogden, UT - Multiple locations (Must be onsite at least 3 days/week Non-negotiable) Full Time Work Model: Hybrid (Flexible WFH days).The Director of Cyber Security will lead our info... Show more

 • Promoted

GLOBAL OPS - Armed Security Agent - Brooklyn

GLOBAL OPSBrooklyn, NY, United States
Full-time

Armed Security AgentLocation:BrooklynSchedule:Full-time, In-PersonCompensation:$28.Benefits:401(k) matchHealth insurancePaid time offReferral programTraining AcademyAbout GLOBAL OPSGLOBAL OPS disti... Show more

 • Promoted

Physical Security Enablement V

EquinixSecaucus, NJ, United States
Full-time

Who are we?Equinix is the world's digital infrastructure company , shortening the path to connectivity to enable the innovations that enrich our work, life and planet.A place where bold ideas are w... Show more

 • Promoted

Remote Senior Technical Marketing Engineer, IoT Security

Palo Alto NetworksNew York City, NY, United States
Remote
Full-time

A leading cybersecurity company is seeking a Senior Technical Marketing Engineer specializing in IoT security.This remote role involves collaborating with Sales, Marketing, and Product teams to dev... Show more

 • Promoted

Senior Cloud Security Engineer Remote (Kubernetes & IaC)

Promote ProjectNew York City, NY, United States
Remote
Full-time

An established industry player is seeking a Cloud Security Engineer to enhance the security posture of its cloud environments.In this role, youll be a key contributor to the security team, responsi... Show more