44 offensive security jobs at 33 companies in Alexandria, VA

1d
Save
Mark Applied
Hide
Offensive Security Engineer
Washington, District of Columbia, United States
$145k-$200k/yr HybridFull Time
Palantir
PalantirNasdaq: PLTR: Developing software platforms for data integration and analytics.
4+ YOERequires 4+ years in offensive security or penetration testing, scripting or programming proficiency, cloud and container security experience, strong communication, and eligibility to obtain a U.S. security clearance preferred.
Burp Suite, BloodHound, SharpHound, Certipy, Impacket, Responder, Pacu, ScoutSuite, Nuclei, Python, Go, AWS, Azure, GCP, Docker, Kubernetes, Microsoft Active Directory, CI/CD, Infrastructure-as-Code, Kerberos, ADCS, SCCM, IMDS, IAM, SSRF
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
1mo
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
3w
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
2mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1d
Save
Mark Applied
Hide
Offensive Cyber Analyst / Programmer 2
Hanover, Maryland, United States
$110k-$205k/yr OnsiteFull Time
Lockheed Martin
Lockheed MartinNYSE: LMT: Designs and manufactures advanced aerospace, defense, and security systems.
8+ YOERequires active US security clearance with polygraph, 8+ years of experience, a relevant bachelor's degree or equivalent experience, programming in Assembly, C, C++, or Python, and offensive cyber tools experience.
Assembly, C, C++, Python, Windows, Linux, MacOS, Android, iOS, IoT, ICS/SCADA, network sockets, IP, TCP
1d
Save
Mark Applied
Hide
Offensive Security Control Assessor Security Control Assessor Representative
Arlington, Virginia, United States
$135k-$160k/yr HybridFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
5+ YOETop Secret clearance, IAM II/III certification, 5–7+ years of DoD or federal security control assessment experience, AWS and GitLab CI/CD expertise, NIST/RMF knowledge, and RMF artifact and GRC repository experience.
AWS, EC2, S3, IAM, VPC, Security Groups, Security Hub, GitLab CI/CD, eMASS, XACTA, NIST SP 800-53, NIST SP 800-37, FedRAMP, AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, OpenSearch Vector Engine, Pinecone, Milvus, PostgreSQL, pgvector, PyTorch, LangChain, LlamaIndex, Promptfoo, Garak, Giskard, NeMo Guardrails, Terraform, CloudFormation, AWS EKS, AWS ECS, Docker, LangGraph
2mo
Save
Mark Applied
Hide
Sales Executive, Offensive Security Services Consulting (United Kingdom)
United Kingdom or Germany or Austria or Switzerland or Belgium or Netherlands or Luxembourg or United States or India or Europe or McLean
RemoteFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
5+ YOE5+ years quota-carrying cybersecurity or technical professional services sales; experience with offensive security preferred; enterprise sales in Europe and consultative selling; strong communication, negotiation, and forecasting/CRM discipline.
CRM
3mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1w
Save
Mark Applied
Hide
AI Security Engineer, AI Security Unit
Washington, District of Columbia, United States
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
Offensive security experience (red teaming/pen testing), deep LLM vulnerability knowledge, threat modeling, automation/tooling development, client-facing delivery and strong technical writing.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, Model Context Protocol (MCP)
5d
Save
Mark Applied
Hide
Network Security Penetration Tester, AppSTAR Network Security
United States or Virtual or North America
$159k-$202k/yr RemoteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires 3+ years in network penetration testing or offensive security, 3+ years of scripting or programming, security code review, vulnerability remediation, networking protocols, and threat modeling.
AWS, Python, Java, C++, HTTP(S), DNS, TCP/IP, VLAN
2mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
3mo
Save
Mark Applied
Hide
Senior Systems Security Specialist
Baltimore, Maryland, United States
HybridFull Time
DMI
DMI: Provides end-to-end digital transformation and managed IT services.
8+ YOEEight+ years in cybersecurity; five+ years in penetration testing/red team; five+ years in network/web/app testing; security reporting; incident response support; strong scripting; cloud, zero trust, and compliance experience; offensive security certifications; government/regulatory experience.
Metasploit, Burp Suite, Nmap, Wireshark, Nessus, Python, C/C++, PowerShell, Bash
2mo
Save
Mark Applied
Hide
Cyber Security Engineer V
Woodbridge, Virginia, United States
OnsiteFull Time
Redhorse
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
Linux, Networking, CNO tools
3w
Save
Mark Applied
Hide
Senior Director – AI & Proactive Security
Centreville or Florida or California or Texas or Massachusetts or Pennsylvania or North Carolina or Minnesota or Rhode Island or Colorado or Michigan or New York
OnsiteFull Time
Mobility Global
Mobility GlobalNYSE: MBGL: Provider of critical automotive intelligence and lifecycle data solutions.
15+ YOE15+ years cybersecurity experience with offensive security/red teaming, AI/ML understanding, ability to operationalize AI security and lead cross-functional transformation.
AI Security Posture Management (AISPM), AWS Bedrock, GCP Vertex AI, MLOps
1mo
Save
Mark Applied
Hide
Penetration Testers – Senior (Lead)
Washington, District of Columbia, United States
$140k-$170k/yr OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
8+ YOE4+ Mgmt8+ years offensive security experience with 4+ years leading penetration testing/red team operations, Bachelor's degree, public trust clearance eligibility, multiple offensive security certs, strong communication and cloud/app testing skills.
Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, Python, PowerShell, Bash, Ruby, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Penetration Tester, Senior (TS/SCI Clearance)
Arlington, Virginia, United States
$110k-$160k/yr OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
8+ YOEActive TS/SCI clearance, U.S. citizenship, 8+ years of offensive security experience, and proficiency in web, cloud, network, and scripting security. At least one listed cybersecurity certification required.
OWASP Top 10, Python, PowerShell, Bash