waypointjobs

PensarAI

Offensive Security Agent Engineer

new york, NY

Check who can apply and the requirements below before continuing.

Availability awaiting confirmation

We are waiting for a fresh update from the source. This page preserves the last received job details; current availability is not confirmed.

Job description

We are seeking an Offensive Security Agent Engineer to build the systems that power autonomous offensive security across Apex and the Pensar platform. You'll work at the intersection of software engineering, offensive security, and AI agents, building the harnesses, tools, execution environments, and workflows that allow autonomous agents to discover and exploit vulnerabilities in real-world applications.

This is an engineering role focused heavily on web security and agentic systems. You'll work on everything surrounding the model itself: how agents interact with browsers, terminals, proxies, scanners, and custom security tools; how they maintain context and reason across long-running engagements; how they explore complex applications; and how we evaluate whether they are actually becoming better offensive security operators.

You'll work closely with our security researchers, AI engineers, and product engineers to turn offensive security techniques into reliable autonomous capabilities. When an agent fails to find a vulnerability, gets stuck in an application, uses a tool incorrectly, or takes an inefficient attack path, you'll dig into why and build the systems that make it better.

The ideal candidate is a strong software engineer who understands how modern web applications break, is deeply interested in agentic systems, and wants to build autonomous security infrastructure rather than simply use existing AI tooling.

Key Responsibilities

Agent Harness & Infrastructure

Design and build the agent harness powering autonomous offensive security workflows across Apex and the Pensar platform

Build systems that allow agents to reliably interact with browsers, terminals, HTTP proxies, scanners, APIs, filesystems, and other security tooling

Develop orchestration for long-running, multi-step offensive security tasks involving reconnaissance, exploitation, validation, and reporting

Build abstractions that allow agents to safely and effectively execute tools, inspect results, maintain state, and adapt their approach

Improve agent context management, memory, task decomposition, planning, and execution across complex engagements

Design reliable execution environments for autonomous security agents operating against customer applications and infrastructure

Debug agent trajectories to understand why an agent succeeded, failed, hallucinated, became stuck, or missed an attack path

Build observability and debugging infrastructure for understanding agent behavior at scale

Web & Application Security

Build autonomous capabilities for discovering and exploiting vulnerabilities in modern web applications and APIs

Develop tooling and workflows around authentication, authorization, session management, API discovery, application state, and complex multi-step attack paths

Enable agents to navigate and understand JavaScript-heavy applications, authenticated applications, APIs, and modern application architectures

Integrate offensive security tooling into autonomous workflows, including proxies, scanners, browsers, custom scripts, and exploitation frameworks

Implement techniques for identifying vulnerability classes such as access control issues, injection vulnerabilities, SSRF, authentication flaws, business logic vulnerabilities, and other application security weaknesses

Translate manual offensive security techniques into primitives and workflows that autonomous agents can execute reliably

Track emerging web exploitation techniques and determine how they can be incorporated into Apex

Agent Evaluation & Improvement

Build evaluation systems for measuring offensive security agent performance against realistic targets

Develop benchmarks, test environments, and regression suites that measure whether changes actually improve agent capabilities

Analyze agent trajectories and failure modes across real engagementsIdentify systemic weaknesses in agent reasoning, tooling, navigation, and exploitation behavior

Design experiments around prompts, models, tools, context strategies, and orchestration approaches

Work with security researchers to turn newly discovered techniques into reproducible evaluations and agent capabilities

Help establish metrics for autonomous pentesting performance beyond simple vulnerability detection

Apex & Platform Engineering

Contribute directly to Apex, our open source autonomous offensive security tool

Build reusable offensive security primitives that can be shared across Apex and the Pensar platform

Design APIs and internal interfaces for agent execution, tools, environments, and security workflows

Work across the stack when necessary to ship new autonomous capabilities into production

Improve the reliability, performance, and scalability of systems running autonomous security engagements

Collaborate with platform engineers on infrastructure for securely executing large numbers of concurrent agent workloads

Help define the technical architecture of Pensar's autonomous offensive security systems as the platform scales

Offensive Security Research

Work closely with offensive security researchers to understand how experienced human operators approach difficult targets

Convert researcher techniques, workflows, and intuition into software and agent capabilities

Build experimental tooling to test new approaches to autonomous exploitation

Investigate difficult targets where existing agents fail and determine what capabilities are missing

Explore new approaches to browser automation, application understanding, vulnerability discovery, and autonomous exploitation

Contribute to technical research and open source releases around autonomous offensive security

Reports To

CTO

We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.

4+ years of professional software engineering, security engineering, offensive security engineering, or equivalent experience

Strong software engineering fundamentals and experience building production systems

Strong programming skills in Python, Go, JavaScript/TypeScript, Rust, C/C++, or similar languages

Deep understanding of modern web applications, HTTP, browsers, APIs, authentication, sessions, and application architecture

Working knowledge of common web vulnerability classes and offensive security techniques

Experience building or working with agentic systems, LLM applications, autonomous agents, or complex tool-using AI systems

Experience with browser automation technologies such as Playwright, Puppeteer, Chrome DevTools Protocol, or similar tooling

Ability to debug complex systems across application code, infrastructure, networking, and agent behavior

Comfortable working with Linux, containers, cloud infrastructure, and isolated execution environments

Ability to independently investigate ambiguous technical problems and turn findings into production systems

Strong product instincts and an interest in making autonomous systems reliable in messy real-world environments

Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience

Comprehensive health, dental, and vision insurance

Direct ownership of core autonomous offensive security infrastructure

Opportunity to build agentic security systems operating against real-world applications

Work directly with offensive security researchers and engineers pushing the capabilities of autonomous pentesting

Professional development budget for conferences, training, and certifications

Support for publishing research, open source work, and presenting at industry conferences

Direct, visible impact on Apex and the Pensar platform

#J-18808-Ljbffr

Worksite address

new york, NY, 10261, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Explore related searches

Current related jobs

GE Vernova

WhatJobs

Lead Application Engineer

boston, MA

See pay details in description

Job Description Summary The Lead Application Engineer is an established leader in their respective engineering team. They will drive business …

Listing review due 2026-10-08View job

Kohler

WhatJobs

Engineer, New Product Integration

kohler, WI

Salary not specified

Engineer, New Product Integration Work Mode: Onsite Location: Onsite, four days per week - Kohler, WI Opportunity This is mo…

Listing review due 2026-10-08View job

GE Vernova

WhatJobs

Principal Engineer - AI Engineering

niskayuna, NY

See pay details in description

Job Description Summary GE Vernova is embracing cutting-edge technologies to streamline operations, improve customer experiences, and drive gr…

Listing review due 2026-10-08View job

GE Vernova

WhatJobs

Lead Product Safety and Compliance Engineer

rochester, NY

See pay details in description

Job Description Summary The Product Safety & Compliance Engineer works directly within the engineering development team to ensure our products…

Listing review due 2026-10-08View job

Hobbs Brook Real Estate

WhatJobs

Commercial Facilities Engineer

waltham, MA

$30.88 to $38.61 per hour

Job Description: Hobbs Brook Real Estate LLC is an innovative commercial real estate leader with a portfolio of forward-thinking, sustainable pr…

Listing review due 2026-10-08View job

Avantor

WhatJobs

Process Engineer

carpinteria, CA

See pay details in description

The Opportunity: NuSil (apart of Avantor) is seeking a Process Engineer to be responsible for all phases of silicone products manufacturing …

Listing review due 2026-10-08View job