Senior Offensive Security Engineer

ProCircular•North Liberty, IA
•Remote

About The Position

ProCircular is a cybersecurity firm that helps organizations see where they’re vulnerable, understand how those gaps get exploited, and build a security program grounded in the real world. We invest in advanced cybersecurity and AI research, then translate complex findings into practical guidance and solutions our clients can actually use. Across assessments, monitoring, incident response, advisory, AI risk, and compliance, ProCircular brings deep technical expertise, practical judgment, and a team that stays involved from initial findings through response and longer-term program development. Trusted by organizations across healthcare, finance, manufacturing, education, transportation and logistics, and government, where downtime and risk carry real operational weight, ProCircular helps teams move from reactive security work to confident decisions, stronger readiness, and better follow-through. You will run network penetration tests for organizations across the Midwest, and you will help us build our artificial intelligence (AI) red team practice from the ground up. Most of your first year is traditional offensive work: internal and external network testing, owned end to end. The AI side is real and growing, and the person in this seat gets to define how we do it. We are not looking for someone to execute a playbook that already exists. We are looking for someone to write it.

Requirements

  • Five or more years of hands-on offensive security experience.
  • OSCP or an equivalent hands-on, practical certification.
  • Real depth in internal and external network penetration testing, including Active Directory attack paths, credential attacks, privilege escalation, and lateral movement.
  • The ability to carry a client engagement solo from kickoff through readout.
  • Strong written English. Reporting is a large part of this job, and we do not hand it off to someone else.
  • Comfort working remotely on a distributed team.
  • Ability to pass the background checks our education and public sector clients require.
  • Python is the common language on our offensive team.
  • Excellent communication skills are required, defined as the ability to: Actively listen for total comprehension. Ask questions that enhance the understanding of a certain topic. Relay information and/or instruction in a descriptive and understandable fashion in both written and verbal format.
  • High-functioning reasoning abilities are necessary to meet deadlines, prioritize company and customer needs, and work in a collaborative team environment.

Nice To Haves

  • Web application and application programming interface (API) testing.
  • Cloud testing in Amazon Web Services (AWS), Microsoft Azure, or Microsoft 365.
  • Any hands on experience attacking or defending AI systems, agents, or MCP servers, whether professional, research, capture the flag, or bug bounty.
  • Experience with agent harnesses such as Claude Code, Codex, Hermes, or OpenClaw is strongly preferred.
  • Development experience in Python, TypeScript, or Go.
  • Additional certifications such as OSWE, OSEP, CRTO, GPEN, or GXPN.
  • Social engineering or physical security testing experience.

Responsibilities

  • Plan and execute internal and external network penetration tests, from scoping through remediation guidance.
  • Run engagements independently. You own the scope, the testing, the report, and the client readout.
  • Write findings a system administrator can act on and an executive can understand.
  • Present results to technical teams and to leadership, including IT directors, executive sponsors, and boards.
  • Retest remediated findings and help clients actually close gaps rather than just cataloging them.
  • Contribute to purple team exercises and adversary simulation work as engagements call for it.
  • Building the AI red team practice: This part is greenfield. You will be building the offering, not inheriting it.
  • Design our testing methodology for AI systems: chatbots, autonomous agents, retrieval augmented generation (RAG) pipelines, and Model Context Protocol (MCP) servers.
  • Test for prompt injection (both direct and indirect), tool abuse and excessive agency, guardrail bypass, sensitive data exposure through agent tool chains, and unsafe handling of model output.
  • Assess MCP servers and agent integrations for authorization gaps, over-permissioned tools, tool poisoning, and insecure defaults.
  • Map our work to recognized references including the OWASP Top 10 for Large Language Model Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Turn what you learn into a repeatable service: scoping questions, test plans, report templates, and input on how we price the work.
  • Write and ship internal tooling that makes testing faster and more consistent across the team.
  • Automate the repetitive parts of reconnaissance, validation, and reporting.
  • Bring an offensive perspective to our internal security products and help make them better.

Benefits

  • Occasional lifting up to 40 lbs. may be necessary from time to time.
  • Must be able to sit for long periods of time, view a computer monitor, and type frequently/constantly (up to 8 hours a day).
  • A valid driver's license is required for occasional travel (under 10%).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service