Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
GenAI
Generative AI @ 3
Go @ 5
LLM
Manual Testing
OWASP @ 6
Python @ 5
Security @ 5
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Coinbase is a remote-first, but not remote-only company. Employees are expected to get together quarterly for in-person working sessions called “surges.”
As an Offensive Security Engineer on the Application Security team within Security, you will pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red-team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security. You will own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response.
Responsibilities
- Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase’s product surface.
- Lead red-team efforts against internal AI systems, including jailbreak testing, prompt-injection analysis, and tool-abuse simulation.
- Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate bug-bounty and vulnerability-response pipelines.
- Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing.
- Mentor junior security engineers on integrating AI into offensive-security workflows to scale team capabilities.
Requirements
- At least 3 years of experience in application security, penetration testing, or offensive security, with demonstrated ability to build custom security tooling.
- Hands-on experience using LLMs or frontier models to automate security tasks, scale vulnerability research, or build security scanners.
- Demonstrated experience red-teaming AI-based systems, including prompt injection, jailbreak testing, and tool abuse.
- Deep understanding of common vulnerability classes, including the OWASP Top 10 and SANS Top 25, with a proven track record identifying and exploiting them in production environments.
- Proficiency in at least one programming language, such as Python or Go, with experience writing production-grade security tooling.
- Ability to use generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Compensation
The annual base salary range is $154,000–$154,000 CAD, excluding equity and bonus. Total compensation may also include equity, bonus eligibility, and benefits including medical, dental, and vision.
Additional Information
Candidates may submit a maximum of three applications within a six-month period. Coinbase is an equal opportunity employer. Reasonable accommodations are available for applicants with disabilities.