cover image
LanceSoft, Inc.

Offensive Security Engineer

On site

Mountain view, United states

$ 100 /hour

Mid level

Freelance

21-01-2026

Share this job:

Skills

Python JavaScript Go Penetration Testing Cloud Security Research Motivation Architecture Programming Organization Azure AWS GCP

Job Specifications

Pay rate: $90.00/hr to $100.00/hr on W2

Location: Mountain View, CA

Contract Duration: 1 year

Job Description:

Senior Offensive Security Engineer - Web & AI Systems

About the Role

We are looking for a Senior Offensive Security Engineer to proactively identify, exploit, and help eliminate security weaknesses across our web platforms and AI/ML systems. In this role, you will think like an attacker, operate with engineering rigor, and work closely with product, platform, and AI teams to raise the security bar across the organization.

You will lead complex penetration tests, design novel attack techniques for web and modern AI-powered applications, and influence secure-by-design architecture at scale.

Responsibilities

· Conduct offensive security assessments on large-scale web applications, REST APIs, and cloud-backed services.

· Identify and validate vulnerabilities including injection flaws, access control

issues, authentication/authorization weaknesses, SSRF, deserialization, and logic

bugs.

· Evaluate LLM-based systems and AI agents for prompt injection, data exfiltration, model abuse and jailbreaks

· Design and execute red team–style engagements simulating real-world adversaries.

· Develop custom exploitation tools, PoCs, and fuzzers for web and AI attack surfaces.

· Identify systemic security weaknesses and collaborate with engineering teams to drive long-term mitigations.

· Review architectures and designs for new products with an attacker mindset.

· Produce clear, actionable security reports and present findings to technical and executive stakeholders.

Minimum Qualifications

· Master’s degree in Computer Science, Computer Engineering, Information Security, or a closely related technical field.

· Doctorate (PhD) in a relevant field is a plus but not required.

· 5+ years of experience in offensive security, penetration testing, or red teaming.

· Deep expertise in web application security.

· Strong understanding of API security.

· Hands-on experience testing AI/ML or LLM-based systems, or strong motivation with demonstrated research in this area.

· Proficiency in at least one scripting or programming language (Python, Go, JavaScript, or similar).

· Strong knowledge of common exploitation techniques and attacker tooling.

Preferred Qualifications

· Prior work on adversarial ML, red-teaming AI systems, or secure LLM pipeline

design.

· Experience with cloud security (AWS, GCP, Azure) and containerized environments.

· Background in security research, published CVEs, CTF experience, blog posts, or conference talks.

· OSCP, OSEP, OSWE, CRTO, or similar.

What We Look For

· An attacker-first mindset with strong engineering discipline.

· Ability to go beyond scanners and find novel, high-impact vulnerabilities.

· Clear communicator who can translate complex exploits into actionable fixes.

· Curiosity about emerging threats, especially in AI security.

· Ownership mentality and comfort operating in ambiguous problem spaces

About the Company

Established in 2000, LanceSoft is a pioneer in delivering top-notch Global Workforce Solutions and IT Services to a diverse clientele. As a Certified MBE and Woman-Owned organization, we pride ourselves on fostering global cross-cultural connections that advance both the careers of our employees and the success of our clients' businesses. At LanceSoft, our mission is clear: to leverage our global network to seamlessly connect businesses with the right talent and individuals with the right opportunities, all without bias. We... Know more