Elite Web & API Security Hacker
Axos BankAbout the role
Target Range:
$115,000.00 /Yr. - $200,000.00 /Yr.Actual starting pay will vary based on factors including, but not limited to, geographic location, experience, skills, specialty, and education.
Eligible for an Annual Discretionary Cash Bonus Target:Eligible for an Annual Discretionary Restricted Stock Units Bonus Target:These discretionary target bonuses may be awarded semi-annually based upon your achievement of performance goals and targets.
About This Job
Are you a relentless hacker who sees a login page as a challenge and an API endpoint as an invitation?We’re not looking for someone who knows how to run SAST, DAST, or point-and-click scanners.
We’re hiring an elite technical offensive security expert — a hacker who lives in Burp Suite, thinks in curl, and sees an API schema as a playground. In this role, you’ll simulate real-world adversaries, uncover security flaws across our web applications and APIs, and work closely with engineering to harden the systems that power our platform.
If your favorite tools have names like ffuf, jwt_tool, custom Python scripts, and your brain, we’re ready to talk.
Whether you specialize in bypassing authentication, exploiting misconfigured CORS policies, or finding logic flaws that scanners can’t, we want your mindset, your creativity, and your technical firepower.
This position is on-site at any of our office locations (San Diego CA, Irvine CA, Los Angeles CA, Las Vegas NV, Centennial CO, Omaha NE, Overland Park KS, Edison NJ) or 100% Remote, depending upon your location.
This is a hands-on, offensive role. You should be able to find, exploit, and explain vulnerabilities in modern, production-grade applications without needing your hand held or a scanner to tell you where to look.
What You'll Be Doing
- Break real applications: Perform targeted, manual security testing of production-grade web apps and APIs — REST, GraphQL, gRPC, internal and public-facing
- Simulate adversaries: Go beyond OWASP Top 10 — find logic flaws, auth bypasses, data leakage, and chained exploits
- Red team mindset: Think like an attacker. Design and execute your own kill chains. Document it so even a backend dev gets it
- Code-aware exploitation: You don't need the source, but if you had it, you’d read it like a map to the treasure
- Outthink security controls: WAF? Rate limits? Auth tokens? Good. We want someone who thrives when blocked
- Go deep on abuse cases: Find the obscure. The unintended. The "shouldn’t happen but does" kind of bugs
🛠 You Should Already Know
- Web protocols cold: HTTP, cookies, sessions, auth flows, JWTs, CORS
- AuthN/AuthZ exploits: OAuth abuse, IDOR, BOLA, SSO bypass
- API attack patterns: Broken schema enforcement, insecure object references, parameter pollution, replay attacks
- Tools you own (or write): Burp Suite Pro, Postman, ffuf, sqlmap, jwt_tool, mitmproxy, Python, bash — or your own
- Manual testing workflow: You don’t wait for a scanner to find something. You hunt, fuzz, and test edge cases manually
- Threat modeling mindset: You think in abuse scenarios, not just CVEs
What This Role Is Not
- A checkbox compliance role
- A scanner operator (we already have those)
- A security generalist
- A hands-off SME
Why You’ll Love It Here
- Autonomy: You own your targets. You choose your tools. You run your ops
- Impact: We ship fast. You’ll test real apps that matter
- Access: No red tape. You’ll work directly with developers and security leadership
- Culture: Security is valued here. Your work will not be sidelined, deprioritized, or
Work Culture: Intensity, Accountability, and Purpose
We operate in a high-intensity, high-accountability environment where both effort and results matter. We don’t glorify burnout — but we do expect people to push hard, go deep, and take real ownership of their work. Security is critical to our business, and we treat it like it is.
This isn’t a slow, checklist-driven environment. This is a place where your ideas, execution, and attention to detail will have direct, visible impact — and where coasting is not an option.
We value:
- Strong work ethic and consistency — not just short bursts of brilliance
- Extreme ownership — you finish what you start and raise your own bar
- Effort + outcome — we care how hard you work and what you deliver
- Grit, curiosity, and urgency — you act like the atta
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s