← Back to jobs

Offensive Security Agent Engineer

Company
Pensar
Location
New York, NY
Work type
Full Time
Posted
2026-08-30

Job description

Description
We are seeking an Offensive Security Agent Engineer to build the systems that power autonomous offensive security across Apex and the Pensar platform. You'll work at the intersection of software engineering, offensive security, and AI agents, building the harnesses, tools, execution environments, and workflows that allow autonomous agents to discover and exploit vulnerabilities in real-world applications.

This is an engineering role focused heavily on web security and agentic systems. You'll work on everything surrounding the model itself: how agents interact with browsers, terminals, proxies, scanners, and custom security tools; how they maintain context and reason across long-running engagements; how they explore complex applications; and how we evaluate whether they are actually becoming better offensive security operators.

You'll work closely with our security researchers, AI engineers, and product engineers to turn offensive security techniques into reliable autonomous capabilities. When an agent fails to find a vulnerability, gets stuck in an application, uses a tool incorrectly, or takes an inefficient attack path, you'll dig into why and build the systems that make it better.

The ideal candidate is a strong software engineer who understands how modern web applications break, is deeply interested in agentic systems, and wants to build autonomous security infrastructure rather than simply use existing AI tooling.

Key Responsibilities
Agent Harness & Infrastructure
Design and build the agent harness powering autonomous offensive security workflows across Apex and the Pensar platform
Build systems that allow agents to reliably interact with browsers, terminals, HTTP proxies, scanners, APIs, filesystems, and other security tooling
Develop orchestration for long-running, multi-step offensive security tasks involving reconnaissance, exploitation, validation, and reporting
Build abstractions that allow agents to safely and effectively execute tools, inspect results, maintain state, and adapt their approach
Improve agent context management, memory, task decomposition, planning, and execution across complex engagements
Design reliable execution environments for autonomous security agents operating against customer applications and infrastructure
Debug agent trajectories to understand why an agent succeeded, failed, hallucinated, became stuck, or missed an attack path
Build observability and debugging infrastructure for understanding agent behavior at scale

Web & Application Security
Build autonomous capabilities for discovering and exploiting vulnerabilities in modern web applications and APIs
Develop tooling and workflows around authentication, authorization, session management, API discovery, application state, and complex multi-step attack paths
Enable agents to navigate and understand JavaScript-heavy applications, authenticated applications, APIs, and modern application architectures
Integrate offensive security tooling into autonomous workflows, including proxies, scanners, browsers, custom scripts, and exploitation frameworks
Implement techniques for identifying vulnerability classes such as access control issues, injection vulnerabilities, SSRF, authentication flaws, business logic vulnerabilities, and other application security weaknesses
Translate manual offensive security techniques into primitives and workflows that autonomous agents can execute reliably
Track emerging web exploitation techniques and determine how they can be incorporated into Apex

Agent Evaluation & Improvement
Build evaluation systems for measuring offensive security agent performance against realistic targets
Develop benchmarks, test environments, and regression suites that measure whether changes actually improve agent capabilities
Analyze agent trajectories and failure modes across real engagements
Identify systemic weaknesses in agent reasoning, tooling, navigation, and exploitation behavior
Design experiments around prompts, models, tools, context strategies, and orchestration approaches
Work with security researchers to turn newly discovered techniques into reproducible evaluations and agent capabilities
Help establish metrics for autonomous pentesting performance beyond simple vulnerability detection

Apex & Platform Engineering
Contribute directly to Apex, our open source autonomous offensive security tool
Build reusable offensive security primitives that can be shared across Apex and the Pensar platform
Design APIs and internal interfaces for agent execution, tools, environments, and security workflows
Work across the stack when necessary to ship new autonomous capabilities into production
Improve the reliability, performance, and scalability of systems running autonomous security engagements
Collaborate with platform engineers on infrastructure for securely executing large numbers of concurrent agent workloads
Help define the technical architecture of Pensar's autonomous offensive security systems as the platform scales

Offensive Security Research
Work closely with offensive security researchers to understand how experienced human operators approach difficult targets
Convert researcher techniques, workflows, and intuition into software and agent capabilities
Build experimental tooling to test new approaches to autonomous exploitation
Investigate difficult targets where existing agents fail and determine what capabilities are missing
Explore new approaches to browser automation, application understanding, vulnerability discovery, and autonomous exploitation
Contribute to technical research and open source releases around autonomous offensive security

Requirements
4+ years of professional software engineering, security engineering, offensive security engineering, or equivalent experience
Strong software engineering fundamentals and experience building production systems
Strong programming skills in Python, Go, JavaScript/TypeScript, Rust, C/C++, or similar languages
Deep understanding of modern web applications, HTTP, browsers, APIs, authentication, sessions, and application architecture
Working knowledge of common web vulnerability classes and offensive security techniques
Experience building or working with agentic systems, LLM applications, autonomous agents, or complex tool-using AI systems
Experience with browser automation technologies such as Playwright, Puppeteer, Chrome DevTools Protocol, or similar tooling
Ability to debug complex systems across application code, infrastructure, networking, and agent behavior
Comfortable working with Linux, containers, cloud infrastructure, and isolated execution environments
Ability to independently investigate ambiguous technical problems and turn findings into production systems
Strong product instincts and an interest in making autonomous systems reliable in messy real-world environments
Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience

Original source