Offensive Security Engineer

at Casco — Autonomous security testing for web apps, APIs, cloud, and AI systems

US / Remote (US)Full-time3+ years$200KYC-S25

What the role involves

About the Role

We're seeking an exceptional Offensive Security Engineer to join our fast-growing startup and help shape the future of security testing. This role uniquely combines traditional penetration testing excellence with cutting-edge AI/LLM security expertise. You'll conduct sophisticated manual penetration tests while also working alongside our automated agentic red teaming systems, bridging the gap between human expertise and AI-driven security assessment.

What You’ll Do

Core Responsibilities

Execute comprehensive, white-glove manual penetration tests across web applications, APIs, cloud infrastructure, and network environments

Review, validate, and enhance findings generated by our agentic red teaming platform

Develop custom exploits, tools, and methodologies to identify complex security vulnerabilities

Contribute to the development of security-focused software and tooling within our engineering team

Collaborate with our engineering team to improve and refine our automated security testing capabilities

Produce detailed, actionable security assessment reports with clear remediation guidance

Partner with customer engineering teams to ensure security findings are properly understood and addressed

Research emerging attack vectors, particularly those involving AI/LLM systems and applications

Technical Leadership

Drive innovation in offensive security methodologies, especially at the intersection of traditional pentesting and AI-assisted security assessment

Mentor team members on advanced penetration testing techniques

Contribute to the company's security strategy and roadmap

Participate in the continuous improvement of our security testing frameworks and processes

What We’re Looking For

Required Qualifications

3+ years of professional penetration testing or offensive security experience with a proven track record of identifying critical vulnerabilities

Hands-on experience with AI/LLM security, including prompt injection, model manipulation, data poisoning, or other AI-specific attack vectors

Strong software engineering skills with proficiency in at least two programming languages, including TypeScript.

Deep understanding of OWASP Top 10, MITRE ATT&CK framework, and modern attack methodologies

Experience with common penetration testing tools (Burp Suite, Metasploit, Cobalt Strike, custom tooling)

Expertise in at least two of the following domains

  • Web application security
  • Cloud security (AWS, Azure, GCP)
  • Network penetration testing
  • API security testing

Preferred Qualifications

  • Experience building or contributing to security tools and frameworks
  • Knowledge of machine learning security, adversarial ML, or AI red teaming
  • Relevant certifications (OSCP, OSWE, OSEP, GPEN, or equivalent)
  • Experience with container security and Kubernetes environments
  • Background in vulnerability research or exploit development
  • Contributions to open-source security projects
  • Experience working in fast-paced startup environments

Skills & Attributes

  • Hacker mindset: Creative, persistent, and always thinking outside the box
  • Technical depth: Ability to dive deep into complex systems and understand their security implications
  • Communication excellence: Can translate technical findings into business risk for various stakeholders
  • Self-directed: Thrives in a startup environment with minimal supervision
  • Continuous learner: Passionate about staying current with evolving threats and technologies
  • Collaborative spirit: Works effectively with cross-functional teams including engineers, product managers, and leadership

What We Offer

Remote-first culture: Work from anywhere within the United States

Competitive compensation

  • Base salary: $200,000
  • Equity package with high growth potential
  • Cutting-edge work: Be at the forefront of AI-assisted security testing
  • Growth opportunities: Shape the security posture of a rapidly scaling startup
  • Learning budget: Annual allocation for training, certifications, and conferences
  • Modern tech stack: Access to the latest

About Casco

Casco performs autonomous security testing for your web apps, APIs, infrastructure, and AI systems. Human supervision optionally available. Use Casco for year-round security and get a penetration test report for your SOC2 and ISO27001 compliance certifications. Trusted by 100+ companies from enterprises to fast-moving startups, such as Gusto, CrewAI, Novig, and Accrual. Hack yourself at: https://casco.com --- We already secure software deployed in 60% of Fortune 500 companies and are default alive. [1] [1] http://www.paulgraham.com/aord.html

Full Casco profile

Other roles at Casco

Similar Engineering, Full stack elsewhere

jobo is a browser extension. Open this on a computer to install it.