For Employers

ProCircular

Senior Offensive Security Engineer

Posted 7 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

You will conduct internal and external network penetration tests while leading the development of a new AI red team practice. This role involves managing client engagements from scoping to remediation and building custom internal tools to improve testing efficiency.

Company Overview
ProCircular is a cybersecurity firm that helps organizations see where they’re vulnerable, understand how those gaps get exploited, and build a security program grounded in the real world. We invest in advanced cybersecurity and AI research, then translate complex findings into practical guidance and solutions our clients can actually use. Across assessments, monitoring, incident response, advisory, AI risk, and compliance, ProCircular brings deep technical expertise, practical judgment, and a team that stays involved from initial findings through response and longer-term program development.


Trusted by organizations across healthcare, finance, manufacturing, education, transportation and logistics, and government, where downtime and risk carry real operational weight, ProCircular helps teams move from reactive security work to confident decisions, stronger readiness, and better follow-through.


Position Summary
You will run network penetration tests for organizations across the Midwest, and you will help us build our artificial intelligence (AI) red team practice from the ground up. 


Most of your first year is traditional offensive work: internal and external network testing, owned end to end. The AI side is real and growing, and the person in this seat gets to define how we do it. We are not looking for someone to execute a playbook that already exists.  We are looking for someone to write it.

 

Essential Job Functions (including but are not limited to the following)

  • Plan and execute internal and external network penetration tests, from scoping through remediation guidance.
  • Run engagements independently. You own the scope, the testing, the report, and the client readout.
  • Write findings a system administrator can act on and an executive can understand.
  • Present results to technical teams and to leadership, including IT directors, executive sponsors, and boards.
  • Retest remediated findings and help clients actually close gaps rather than just cataloging them.
  • Contribute to purple team exercises and adversary simulation work as engagements call for it. 


Building the AI red team practice:
This part is greenfield. You will be building the offering, not inheriting it. 

  • Design our testing methodology for AI systems: chatbots, autonomous agents, retrieval augmented generation (RAG) pipelines, and Model Context Protocol (MCP) servers.
  • Test for prompt injection (both direct and indirect), tool abuse and excessive agency, guardrail bypass, sensitive data exposure through agent tool chains, and unsafe handling of model output.
  • Assess MCP servers and agent integrations for authorization gaps, over-permissioned tools, tool poisoning, and insecure defaults.
  • Map our work to recognized references including the OWASP Top 10 for Large Language Model Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Turn what you learn into a repeatable service: scoping questions, test plans, report templates, and input on how we price the work. 


Tooling and automation:
We expect our senior engineers to build, not just run other people's tools. 

  • Write and ship internal tooling that makes testing faster and more consistent across the team.
  • Automate the repetitive parts of reconnaissance, validation, and reporting.
  • Bring an offensive perspective to our internal security products and help make them better.
  • Python is the common language on our offensive team. 


Position Requirements  
The requirements listed below are representative of the knowledge skills and abilities required. Employees who do not have the requirements for a job at the time of hire will not be considered for the position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
 
Required Skills and Experience: 

  • Five or more years of hands-on offensive security experience.
  • OSCP or an equivalent hands-on, practical certification. We care about the exam you had to actually pass, not the number of acronyms.
  • Real depth in internal and external network penetration testing, including Active Directory attack paths, credential attacks, privilege escalation, and lateral movement.
  • The ability to carry a client engagement solo from kickoff through readout.
  • Strong written English. Reporting is a large part of this job, and we do not hand it off to someone else.
  • Comfort working remotely on a distributed team.
  • Ability to pass the background checks our education and public sector clients require. 


Desired Skills and Experience:

  • Web application and application programming interface (API) testing. 
  • Cloud testing in Amazon Web Services (AWS), Microsoft Azure, or Microsoft 365.
  • Any hands on experience attacking or defending AI systems, agents, or MCP servers, whether professional, research, capture the flag, or bug bounty.
  • Experience with agent harnesses such as Claude Code, Codex, Hermes, or OpenClaw is strongly preferred.
  • Development experience in Python, TypeScript, or Go.
  • Additional certifications such as OSWE, OSEP, CRTO, GPEN, or GXPN.
  • Social engineering or physical security testing experience. 


What we do not require 
You do not need prior professional AI red teaming experience. Almost nobody has it yet, and we are not going to pretend otherwise. 


If you are a strong network tester who has been taking language models and agent frameworks apart on your own time, you are exactly the person we want to talk to. We would rather teach a great operator the AI material than teach an AI enthusiast how to run a penetration test. 


Language Requirements
The primary language of ProCircular is English. Excellent communication skills are required, defined as the ability to:

  • Actively listen for total comprehension.
  • Ask questions that enhance the understanding of a certain topic.
  • Relay information and/or instruction in a descriptive and understandable fashion in both written and verbal format.


Reasoning Ability Requirements
High-functioning reasoning abilities are necessary to meet deadlines, prioritize company and customer needs, and work in a collaborative team environment. 


Physical Requirements
Occasional lifting up to 40 lbs. may be necessary from time to time. Must be able to sit for long periods of time, view a computer monitor, and type frequently/constantly (up to 8 hours a day). 


Travel Requirements
A valid driver's license is required for occasional travel (under 10%).


Schedule Expectations
Our normal hours of operation are from Monday through Friday, from 8:00 am to 5:00 pm. Central Time.
Full-Time: Full-Time employees are defined legally as working at least 30 hours per week. However, full-time positions at ProCircular require at least 40 hours. This position requires 40 hours worked within a regular workweek. Occasionally, time over 40 hours may be necessary to meet the requirements of the position. If performance expectations are met, employees may flex his or her schedule, subject to preapproval of one's direct supervisor. 


Supervision Requirements
This position does not have supervisory responsibilities.


Performance Expectations
All teammates are evaluated at least annually on their performance based on the essential job functions in this job description, along with ProCircular's Core Values: 


It's about people
People define every part of our business. Growth potential is based on the abilities and personalities of the people involved. Technology solutions are a part of the equation, but it's the people in an organization that define its true security. We work hardest when we're supporting one another. We take care of each other; we take care of our families, and in doing so we take better care of our customers.


Fear is the mind killer
We don't let fear define the need for our services and we don't present a problem without discussing realistic response or mitigation options. There's more than enough to worry about in life and plenty of people telling us to be afraid. We're solutions people, not fear mongers.


Strong opinions lightly held
Opinions are important - they coalesce facts, reason, experience, and judgment into actionable points of view. We present our opinions with logic and reason rather than emotions, offering several alternatives to each challenge and the supporting data. The rejection of an idea is not a rejection of the individual or their merit. Everyone has a voice and a chance to speak, regardless of title, station or seniority.


Quality over speed, speed over cost
Every organization must consciously balance quality, speed, and cost. We will always put the quality of our work first. We make great efforts to move quickly, but never at the expense of quality. While we strive to keep our services affordable, we never choose an inexpensive alternative that will adversely impact quality or speed.


Cool heads, warm hearts
We keep a cool head and help others do the same, especially in a crisis. We approach adversity with patience, logic, and understanding. Mistakes happen; we don't hide, ignore, condemn, or fear them. Mistakes are opportunities to exemplify honesty, accountability, professionalism, tolerance, and grace. Instead of pointing a finger, we use humor, empathy, and fun when it matters most.


R-E-S-P-E-C-T
We treat each other how we hope to be treated. We don't yell; we aren't condescending, and we always try to understand the other person's perspective, before reacting to it. We keep it light and we listen. We extend this principle to our customers, and we understand that talking down to them is the easiest way to send them to a competitor.


Tomorrow just happened
Life is what happens when we're busy making other plans. We work hard on today but we're always thinking about the future. We take extra time to make sure we're learning and looking ahead. No matter what your discipline or area of expertise, you're adding your capabilities to the long-term plan for the organization and its clients.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Sr Manager, Salesforce Platform Engineering

Full Time United States $172K - $440K per year Software Development

Senior Klaviyo Consultant / Solutions Architect

Freelance United States $25 - $35 per hour Software Development

JavaScript Developer (Remote)

Full Time United States $89759 - $117K per year Software Development

Director, Enterprise Strategic Programs (ERP, PMO, AI)

Full Time United States $200K - $230K per year Software Development

Pre-Sales Solution Consultant, Big Tech/AI

Full Time United States $160K - $185K per year Software Development

Grant Operations Administrator

Full Time United States Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Security Engineer

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified