What We're Looking For 4+ years of experience in offensive security, penetration testing, red teaming, application security, or vulnerability research Strong hands-on experience identifying and exploiting vulnerabilities in modern applications and infrastructure Deep understanding of web application security, APIs, authentication, authorization, and common attack techniques Strong knowledge of OWASP Top 10 and modern exploitation techniques Experience with vulnerability chaining and identifying complex attack paths Strong programming and scripting skills, with the ability to build offensive security tools and proof-of-concepts Ability to understand code and modern software architectures from an attacker's perspective Strong understanding of how modern applications and cloud environments can be attacked Ability to independently investigate complex systems and find creative ways to break them Strong communication skills and the ability to explain technical findings clearly A hands-on, curious, and highly technical mindset The DNA We're Looking For Attacker mindset: You naturally think about how a system can be abused, bypassed, or broken Builder-breaker: You enjoy both finding vulnerabilities and building the tools to exploit and automate them Creative attacker: You look beyond known vulnerabilities and find unconventional attack paths Scale-oriented: You’re excited by the idea of turning a manual offensive technique into an automated, agentic capability Systems thinker: You understand how seemingly small weaknesses can combine into a real attack Fearless investigator: You enjoy complex, ambiguous problems where there is no obvious answer Ownership-driven: You take initiative, experiment quickly, and push ideas from research to production