26 offensive security jobs at 19 companies in Baltimore, MD

1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
1w
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1mo
Save
Mark Applied
Hide
Sales Executive, Offensive Security Services Consulting (United Kingdom)
United Kingdom or Germany or Austria or Switzerland or Belgium or Netherlands or Luxembourg or United States or India or Europe or McLean
RemoteFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
5+ YOE5+ years quota-carrying cybersecurity or technical professional services sales; experience with offensive security preferred; enterprise sales in Europe and consultative selling; strong communication, negotiation, and forecasting/CRM discipline.
CRM
2mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2mo
Save
Mark Applied
Hide
Senior Systems Security Specialist
Baltimore, Maryland, United States
HybridFull Time
DMI
DMI: Provides end-to-end digital transformation and managed IT services.
8+ YOEEight+ years in cybersecurity; five+ years in penetration testing/red team; five+ years in network/web/app testing; security reporting; incident response support; strong scripting; cloud, zero trust, and compliance experience; offensive security certifications; government/regulatory experience.
Metasploit, Burp Suite, Nmap, Wireshark, Nessus, Python, C/C++, PowerShell, Bash
2w
Save
Mark Applied
Hide
Penetration Testers – Senior (Lead)
Washington, District of Columbia, United States
$140k-$170k/yr OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
8+ YOE4+ Mgmt8+ years offensive security experience with 4+ years leading penetration testing/red team operations, Bachelor's degree, public trust clearance eligibility, multiple offensive security certs, strong communication and cloud/app testing skills.
Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, Python, PowerShell, Bash, Ruby, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Principal Red Team Engineer
Ashburn or Irving or Cary or Basking Ridge
$121k-$231k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Global provider of wireless, internet, and communication services.
6+ YOEBachelor's or equivalent experience, 6+ years in offensive security or software development, expertise in exploit development, Linux internals, network protocols, and mentoring skills.
Python, C, C++, Rust, Go, Assembly, Ghidra, IDA Pro, Binary Ninja, Kubernetes, Docker, VMware ESXi, Proxmox, Large Language Models (LLMs)
3w
Save
Mark Applied
Hide
Penetration Tester, Mid (TS/SCI Clearance)
Arlington, Virginia, United States
$90k-$130k/yr OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
3+ YOEActive TS/SCI clearance, 3+ years offensive security/penetration testing experience, familiarity with OWASP Top 10, cloud and network security, scripting (Python, PowerShell, Bash), and possession of at least one listed security certification.
OWASP Top 10, Python, PowerShell, Bash
2mo
Save
Mark Applied
Hide
iOS Vulnerability Researcher
Arlington, Virginia, United States
RemoteFull Time
Interrupt Labs
Interrupt Labs: Provides specialized vulnerability research and offensive security services.
Experience in vulnerability research, offensive security, and reverse engineering on Apple platforms; proficient in Python and Rust; able to reverse engineer ARM64 and use IDA, Binary Ninja, Frida.
Python, Rust, C, Swift, C++, Objective-C, IDA, Binary Ninja, Frida
3w
Save
Mark Applied
Hide
Government and Public Sector - Cybersecurity - Penetration Tester - Senior Consultant
McLean, Virginia, United States
$105k-$192k/yr HybridFull Time
EY
EY: Global firm providing audit, tax, and professional consulting services.
3+ YOEBachelor's degree, 3+ years penetration testing/red team experience, ability to obtain Secret clearance, offensive security certification (e.g., OSCP/GPEN), strong technical and client-facing communication skills.
1mo
Save
Mark Applied
Hide
Senior Cyber Analyst
Crystal City or Arlington
OnsiteFull Time
Capstone Research Corporation
Capstone Research Corporation: Provides defense-focused systems engineering and R&D services.
10+ YOEBachelor's in a technical discipline, 10+ years supporting DoD/IC cyber or national security programs, experience with offensive/defensive cyber operations and non-kinetic effects, and active TS/SCI clearance required.
Modeling & Simulation (M&S), cyber ranges, Command and Control (C2) systems, tactical data links, electronic warfare systems
1w
Save
Mark Applied
Hide
Technical Targeting Analyst
McLean, Virginia, United States
$135k-$216k/yr OnsiteFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
8+ YOEActive TS/SCI with polygraph, 6–8+ years technical experience (analysis, network engineering/security, offensive ops, collection, reverse engineering, exploitation), experience with collection/dissemination systems, strong writing and communication.
2w
Save
Mark Applied
Hide
AOUSC - Threat Emulation & Readiness Lead / Red Team Lead
Washington, District of Columbia, United States
OnsiteFull Time
cFocus Software
cFocus Software: Provides cybersecurity compliance and enterprise IT services for government.
10+ YOE5+ Mgmt10+ years offensive security experience, 5+ years leading red team/adversary emulation; skilled in adversary tradecraft, post-exploitation, detection evasion, cloud and AD operations; strong executive briefing and teamwork abilities.
MITRE ATT&CK
1w
Save
Mark Applied
Hide
Technical Targeting Analyst
McLean, Virginia, United States
$135k-$216k/yr OnsiteFull Time
Peraton
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOEActive TS/SCI with polygraph; bachelor\u0002s in technical field (or equivalent); 6+ years technical experience across analysis, network/security, offensive ops, reverse engineering, or exploitation; 3+ years with collection/dissemination systems.
1mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix
1mo
Save
Mark Applied
Hide
Sr Cybersecurity Engineer
Reston, Virginia, United States
$160k-$239k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in incident response, intelligence, vulnerability assessment, security engineering or operations; experience with AI-based offensive tools; proficiency in Python/Java/Kotlin/Scala/JavaScript; threat hunting, detection development, and incident response skills.
Splunk, Spark, Python, Java, Kotlin, Scala, JavaScript
3w
Save
Mark Applied
Hide
Penetration Testing Team Lead
Work from home, Virginia, United States
$170k-$190k/yr RemoteFull Time
ECS
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
12+ YOEU.S. citizen with 12+ years offensive security experience, Public Trust 6c clearance (or ability to obtain), OSCP/OSCE/GXPN/CEH, network/web/AWS/API pentesting, MITRE ATT&CK and NIST SP 800-115 familiarity.
MITRE ATT&CK, NIST SP 800-115, DHS RVA, Burp Suite Professional, AWS GovCloud, Azure Government