17 offensive security jobs at 12 companies in Berwyn, IL

1w
Save
Mark Applied
Hide
Lead Offensive Security Engineer
Naperville, Illinois, United States
$121k-$181k/yr OnsiteFull Time
Ecolab
EcolabNYSE: ECL: Provides water, hygiene, and infection prevention solutions and services.
8+ YOEBachelor's degree,8+ years in offensive/application/cloud/IoT security,hands-on penetration testing experience,team leadership,Azure/AWS/GCP familiarity and application security tooling proficiency.
Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST, SAST, SCA, Microsoft Azure, AWS, GCP, Kubernetes
1w
Save
Mark Applied
Hide
Senior Offensive Security Engineer
Naperville, Illinois, United States
$101k-$152k/yr OnsiteFull Time
Ecolab
EcolabNYSE: ECL: Provides water, hygiene, and infection prevention solutions and services.
5+ YOEBachelor's degree,5+ years hands-on offensive/application/cloud/IoT security testing,experience with Azure/AWS/GCP,tooling familiarity,mentoring and reporting skills.
Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST, SAST, SCA, Microsoft Azure, AWS, GCP, Kubernetes
4w
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
1mo
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
2mo
Save
Mark Applied
Hide
WebApp Offensive Security Engineer
United States or Chicago
$196k-$242k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Extensive hands-on web application penetration testing experience, ability to reproduce and validate edge-case exploits, strong communication, proxy tool experience (Burp Suite), scripting (Python), and history of security research or bug bounty contributions.
NodeZero, Burp Suite, Python, Nuclei, sqlmap, LangChain, LangFlow, Postgres, Neo4j, Jira, Model Context Protocol (MCP)
1mo
Save
Mark Applied
Hide
Senior Engineer, Offensive Security
Louisville or Charlotte or Tampa or Dallas or Washington or Chicago or Atlanta or New York City or Nashville or Miami or Boston
$118k-$162k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
4+ YOE4+ years red-team/pen-test experience, production Python engineering, agentic AI/LLM tooling experience, AI adversarial testing, and production cloud experience (AWS/GCP/Azure).
Python, Cobalt Strike, Sliver, Mythic, EDR, XDR, NDR, DLP, MITRE ATT&CK, VECTR, Atomic Red Team, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, Model Context Protocol (MCP), Hack The Box, AWS, GCP, Azure
3mo
Save
Mark Applied
Hide
Security Engineer
Chicago, Illinois, United States
$145k-$195k/yr OnsiteFull Time
Coinflow
Coinflow: Enables instant global payments using stablecoins and blockchain technology.
4+ YOE4+ years in security engineering or DevSecOps; hands-on offensive and defensive security; SIEM; code experience in TS/Node; vulnerability management; AI-native tooling.
Datadog, Splunk, Elastic, Panther, TypeScript, Node.js, Rust, Go, Python, Claude Security, Claude Code, SAST, DAST, CI/CD
1w
Save
Mark Applied
Hide
AI Security Engineer, AI Security Unit
Chicago, Illinois, United States
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
Offensive security and red teaming experience, knowledge of LLM and agentic vulnerabilities, proficiency building automation tooling, client-facing assessment delivery, strong technical writing and communication.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, Model Context Protocol (MCP)
1mo
Save
Mark Applied
Hide
Artificial Intelligence Senior Security Engineer
Chicago or Washington or Denver or Jersey City or Boston
$145k-$193k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
7+ YOE7+ years cybersecurity experience with hands-on AI/ML, agentic AI and LLM development, offensive/defensive security expertise, large-scale data and model deployment, and executive communication.
Azure AI Foundry, AWS Bedrock, GCP Vertex, PyTorch, TensorFlow, LangChain
1mo
Save
Mark Applied
Hide
Senior Penetration Testing Engineer
Chicago, Illinois, United States
$93k-$144k/yr HybridFull Time
Alliant Credit Union
Alliant Credit Union: Provides digital banking, consumer loans, and mortgage lending services.
3+ YOEBachelor's in CS/related or 6 years' equivalent; minimum 3 years penetration testing/offensive security; preferred offensive security certifications; strong communication and reporting skills.
1mo
Save
Mark Applied
Hide
Senior Red Team Operator
Minneapolis or Atlanta or Cincinnati or Cupertino or Portland or New York or Chicago or Englewood or Charlotte or Irving
$133k-$157k/yr HybridFull Time
U.S. Bank
U.S. BankNYSE: USB: Provider of personal, business, and institutional financial services.
8+ YOEBachelor's degree or equivalent, 8+ years in information security with offensive security/Red Team experience; expertise in exploit development, offensive tooling, and scripting; strong communication and leadership.
Cobalt Strike, Metasploit, Mythic, Sliver, Python, PowerShell, C/C++, C#, Go, Shell, EDR, XDR, Infrastructure as Code (IaC)
2mo
Save
Mark Applied
Hide
Staff Attack Engineer, OCI
Chicago or United States
$247k-$275k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
10+ YOE10+ years engineering or offensive security experience, hands-on OCI offensive security experience, strong cloud attack path knowledge, Python coding, web and cloud pentesting experience, strong research and documentation skills.
Python, NodeZero, Oracle Cloud Infrastructure (OCI), Oracle Kubernetes Engine (OKE), Kubernetes, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Calgary or Toronto or Englewood or Chicago or Raleigh or New York or Dallas or Houston
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOE8+ years information security experience focused on penetration testing, application/cloud security, vulnerability management; offensive security certification required; scripting (Bash, Python, Go, PowerShell, JavaScript); experience with DAST/SAST/SCA and CI/CD integration; bachelor's degree or equivalent.
Burp Suite, Nessus, Metasploit, Nmap, OWASP Top 10, MITRE ATT&CK, DAST, SAST, SCA, Bash, Python, Go, PowerShell, JavaScript, AWS, Azure, GCP
5d
Save
Mark Applied
Hide
Senior IT Penetration Tester
United States or Oak Brook or Los Angeles or Washington or Troy or New York City or Houston or Chicago or Grand Rapids or Owings Mills or Columbia or Richmond or Memphis or Raleigh or Boston or San Jose or San Francisco or Austin or Kalamazoo or Spokane or Denver or Fort Worth or Atlanta or Orlando or Dallas or Wilmington or Phoenix or San Antonio or Milwaukee or Madison or McLean or Melville or Woodbridge or Stamford or Philadelphia or Charlotte or Greenville or West Palm Beach or Costa Mesa or St. Louis or Fort Lauderdale or Seattle or Pittsburgh or Tulsa or Cincinnati or Cleveland or Columbus or Akron or Cherry Hill or Tampa or Minneapolis or Anchorage or Salt Lake City or Norfolk or Jacksonville or Boulder or Nashville or Las Vegas or Indianapolis or San Diego or Potomac or Baton Rouge or Omaha
$120k-$160k/yr OnsiteFull Time
BDO USA
BDO USA: Provides accounting, tax, and business advisory services to organizations.
4+ YOEFour or more years of hands-on penetration testing experience, strong Windows, Linux, networking, Active Directory, scripting, reporting, client communication, and offensive security tooling skills; high school diploma required.
Kali Linux, Nessus, Tenable, Nmap, Burp Suite, Metasploit, BloodHound, Microsoft 365, OWASP Top 10 for LLM Applications, Python, PowerShell, Bash, Git, GitHub Actions, Azure DevOps, Docker, GitHub, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Splunk, Microsoft Sentinel, GitHub Copilot, Claude Code, Microsoft Azure, AWS, SAML, OAuth 2.0, OpenID Connect, Kerberos, NTLM, TCP/IP, DNS, Windows, Linux
1mo
Save
Mark Applied
Hide
Forward deployed engineer Chicago
Chicago, Illinois, United States
FieldFull Time
Aikido Security
Aikido Security: Developer-first security platform for code, cloud, and runtime.
Strong infrastructure and networking fundamentals (Docker, DNS, TLS), Linux debugging, ability to read Go/TypeScript/Python, familiarity with enterprise networks, basic offensive security knowledge, strong communication; must live in Chicago.
Docker, Postgres, Go, TypeScript, Python, Linux, AWS, Azure, GCP, SSO, IdP, PKI, DNS, TLS
2mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix