高级进攻性安全工程师
Senior Offensive Security Engineer
Array 是一个金融创新平台,帮助数字品牌、金融机构和金融科技公司更快地推出有吸引力的消费者产品。我们通过可嵌入的小部件或简洁现代的 API,提供一套信用和身份监控工具、隐私保护以及金融广告市场。我们的自有品牌产品帮助客户增加收入并提高参与度,同时赋能数百万消费者实现财务目标。
作为一家以远程办公为主导的公司,我们专注于为高绩效人才提供在快速发展的金融科技领域产生深远影响的机会。明确的使命、对持续改进的承诺以及勇于实验的精神,使我们个人和团队都能为客户提供最佳产品和用户体验。
我们正在寻找一名进攻性安全工程师,能够像攻击者一样思考,并通过真实世界的利用验证 Array 产品的安全性。你是一名付费黑客;你将拥有对我们应用程序、源代码和基础设施的完全访问权限,以识别造成实际业务风险的漏洞——而不是理论上的发现。AI 应该是你的主要工具之一,它能帮助你分析大型代码库、加速假设生成并扩大测试范围,同时依靠你自己的判断来验证结果。
**你具备:**
- 5 年以上进攻性安全、应用安全、渗透测试或红队经验,有发现真实应用漏洞的记录。
- 对现代 Web 应用、API、认证授权、分布式系统和 OWASP Top 10 有深入理解。
- 有开发证明真实业务影响的 PoC 漏洞的经验,而不仅仅是理论风险。
- 熟练使用 AI 加速漏洞发现、利用开发、代码分析和安全研究,同时验证 AI 生成的输出。
- 具备良好的沟通能力,能够向工程团队解释复杂的漏洞、攻击路径和修复建议。
- 相信 AI 正在重塑工作方式,你本能地用它来加速你所做的每一件事。
**你将:**
- 针对 Array 的产品、基础设施和内部系统,识别、验证并演示现实中的攻击路径,重点关注业务影响。
- 使用 AI 和手动技术分析大型多语言代码库,发现漏洞,生成利用假设并执行测试
查看英文原文
Array is a financial innovation platform that helps digital brands, financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and identity monitoring tools, privacy protection, and a financial ads marketplace via embeddable widgets or a clean, modern API. Our private label offerings help drive revenue and increase engagement for our customers while empowering millions of consumers to achieve their financial goals.
As a remote-first company, we’re focused on providing opportunities for high performing individuals to have deep impact in the fast growing fintech space. A clear mission, a commitment to continuous improvement and a willingness to experiment empower us individually and together deliver the best products for our clients and users.
We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You’re a paid hacker; you'll operate with full access to our applications, source code, and infrastructure to identify vulnerabilities that create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze large codebases, accelerate hypothesis generation, and increase testing coverage while relying on your own judgment to validate results.
**You Have:**
- 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
- Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
- Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
- Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
- Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
- A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.
**You Will:**
- Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
- Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
- Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
- Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
- Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
- Maintain a habit of using AI tools to think, build, and ship faster—it’s your default, not an afterthought.
**Success Looks Like:**
- Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
- Security gaps identified that were not detected by existing tools or processes.
- High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
- Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.
**Pay transparency:** $170,000 + for base salary, depending on experience. Full time employee compensation includes an Incentive Stock Option (ISO) grant, subject to Board approval.
**Expected interview process:** Recruiter Conversation - Hiring Manager Interview - Loop round: How We Work, Engineering leadership.
**Array Offers All Full Time Employees the following Benefits and Perks:**
- Full medical, dental, and vision, premiums covered at 100% for full-time employees and 70% for dependents
- Unlimited PTO and sick leave + 14 company holidays to encourage a healthy work-life blend
- 100% 401k match up to 4% with immediate vesting
- Generous and competitive parental leave for all parents
- $1,000 desk setup subsidy to set-up your unique remote office
- $100/month to subsidize wifi/cell phone expenses
- Summer Fridays (half-day Fridays) typically from late May to the end of August
- Commuter benefits for those who choose to go into our New York City or San Francisco office spaces
_Not sure if you meet the Qualifications? We know that folks tend to only apply if they check every box. If you think you have the appropriate qualifications, but don’t meet every single one, we encourage you to still apply. We’d love to hear from you._
_We are proud to be an equal opportunity workplace; we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Array will provide reasonable accommodations to qualified applicants—if you need an accommodation to participate in the application or interview process, please email talent@array.com to make your request._
_Array uses CLEAR to conduct identity verification as part of the application process. We encourage you to review CLEAR’s_ [_Privacy Notice_](https://www.clearme.com/privacy-policy) _and_ [_Terms of Use_](https://www.clearme.com/terms-of-use) _to understand how your personal data will be processed._