Back to Jobs
Array
Development 2h ago

Offensive Security Engineer

Array
CanadaCanada
United StatesUnited States
Full-time
$170,000+
Senior-Level

Job Description

Key Skills Required

Master these to land this role

BackendBestseller 🔥
Learn in 18 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
PythonBestseller 🔥
Learn in 56 Hours
AI EngineerCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

Array is a financial innovation platform that helps digital brands, financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and identity monitoring tools, privacy protection, and a financial ads marketplace via embeddable widgets or a clean, modern API. Our private label offerings help drive revenue and increase engagement for our customers while empowering millions of consumers to achieve their financial goals.

As a remote-first company, we’re focused on providing opportunities for high performing individuals to have deep impact in the fast growing fintech space. A clear mission, a commitment to continuous improvement and a willingness to experiment empower us individually and together deliver the best products for our clients and users.

We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You’re a paid hacker; you'll operate with full access to our applications, source code, and infrastructure to identify vulnerabilities that create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze large codebases, accelerate hypothesis generation, and increase testing coverage while relying on your own judgment to validate results.

You Have:

  • 5+ years of offensive security, application security, penetration testing, or red team experience with a track record of finding real application vulnerabilities.
  • Deep expertise in modern web applications, APIs, authentication, authorization, distributed systems, and the OWASP Top 10.
  • Experience developing proof-of-concept exploits that demonstrate real business impact, not just theoretical risk.
  • Proficiency using AI to accelerate vulnerability discovery, exploit development, code analysis, and security research while validating AI-generated output.
  • Strong communication skills with the ability to explain complex vulnerabilities, attack paths, and remediation guidance to engineering teams.
  • A belief that AI is reshaping work, you instinctively use it to accelerate everything you do.

You Will:

  • Identify, validate, and demonstrate realistic attack paths against Array's products, infrastructure, and internal systems with a focus on business impact.
  • Analyze large, multi-language codebases using AI and manual techniques to uncover vulnerabilities, generate exploit hypotheses, and perform variant analysis.
  • Build safe proof-of-concept exploits that demonstrate unauthorized access, privilege escalation, data exposure, business logic flaws, or other meaningful security risks.
  • Partner with engineering to validate remediations, confirm exploit paths are fully eliminated, and identify similar patterns elsewhere in the environment.
  • Document findings with clear evidence, technical root cause, business impact, and practical remediation guidance while continuously improving Array's offensive security capabilities.
  • Maintain a habit of using AI tools to think, build, and ship faster—it’s your default, not an afterthought.

Success Looks Like:

  • Demonstrated exploit paths to sensitive data, unauthorized access, or privilege escalation.
  • Security gaps identified that were not detected by existing tools or processes.
  • High-confidence validation that engineering fixes eliminate vulnerabilities and related attack paths.
  • Meaningful system coverage supported by documented testing methodology, whether vulnerabilities are found or not.

How would you rate this job post?

See what other professionals think about this role.

banner

Array is a financial technology company that provides an embeddable platform for consumer credit, identity, and privacy protection tools. Founded in 2020, the company enables banks, credit unions, fintech startups, and digital brands to seamlessly integrate financial health features—such as credit score monitoring, identity theft protection, and personalized financial offers—directly into their own web or mobile applications. Through its suite of APIs, embeddable components, and white-label solutions (including products like My Credit Manager, Offers Engine, and Privacy Protect), Array helps organizations accelerate their time-to-market, increase user engagement, and drive new revenue streams while empowering consumers to take control of their financial wellness.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Offensive Security Engineer at Array