113 offensive security developer jobs at 87 companies in United States

2d
Save
Mark Applied
Hide
Staff Offensive Security Engineer
New York City, New York, United States
$200k-$250k/yr HybridFull Time
Cloaked
Cloaked: Consumer privacy platform for managing digital identity and data.
Advanced offensive security expertise, exploit development, coding fluency, multi-cloud and SaaS architecture mastery, strong communication, and ability to prioritize and remediate business-critical risks.
2mo
Save
Mark Applied
Hide
Principal Offensive Security Engineer
Palo Alto, California, United States
$168k-$271k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Provides enterprise-grade network, cloud, and endpoint security software.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Kubernetes, Container Security, IaC, CI/CD, Cloud Security
1mo
Save
Mark Applied
Hide
Offensive Security Engineer
Poughkeepsie, New York, United States
$73k-$171k/yr OnsiteFull Time
Central Hudson Gas & Electric
Central Hudson Gas & Electric: Delivers electricity and natural gas to the Hudson Valley.
Bachelor's in cybersecurity/IT/CS (or equivalent experience), strong offensive security skills, experience with Metasploit/Cobalt Strike/Burp Suite/Nmap/BloodHound/CrackMapExec, scripting (Python, PowerShell, Bash, C#), SIEM/EDR familiarity, ability to work on-call and during incidents.
Metasploit, Cobalt Strike, Burp Suite, Nmap, BloodHound, CrackMapExec, Python, PowerShell, Bash, C#, SIEM, EDR, IDS/IPS, MITRE ATT&CK, NIST 800-61, SANS, CIS Critical Security Controls
3w
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for building customer engagement applications.
7+ YOE7+ years in offensive security/penetration testing or high-volume bug bounty; expert MITRE ATT&CK/OWASP knowledge; proficiency with offensive tooling; scripting in Python/Bash/C++; advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc, Python, Bash, C++, SIEM
3d
Save
Mark Applied
Hide
Lead Offensive Security Engineer
Naperville, Illinois, United States
$121k-$181k/yr OnsiteFull Time
Ecolab
EcolabNYSE: ECL: Provides water, hygiene, and infection prevention solutions and services.
8+ YOEBachelor's degree,8+ years in offensive/application/cloud/IoT security,hands-on penetration testing experience,team leadership,Azure/AWS/GCP familiarity and application security tooling proficiency.
Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST, SAST, SCA, Microsoft Azure, AWS, GCP, Kubernetes
1w
Save
Mark Applied
Hide
Senior Offensive Security Engineer
San Mateo, California, United States
$197k-$243k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years offensive security experience; proficiency in Python or Go; experience with purple team exercises, breach/attack simulation, cloud and API security; strong technical writing and analytical skills.
Python, Go, SOAR, MITRE ATT&CK, PTES, BAS, EDR, SIEM, XDR, AWS, Azure, GCP, CI/CD
3w
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for programmable messaging, voice, and email.
7+ YOE7+ years in offensive security/pentesting or bug bounty; expert MITRE/OWASP knowledge; proficiency with Burp Suite, Nmap, Metasploit, scripting (Python/Bash); advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc
3d
Save
Mark Applied
Hide
Senior Engineer, Offensive Security
United States
$118k-$162k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
4+ YOE4+ years offensive security experience, production Python engineering, built/operated agentic AI and LLM-driven tooling, hands-on AI/ML attack testing, and production cloud experience (AWS/GCP/Azure).
Python, LLM, Cobalt Strike, Sliver, Mythic, VECTR, Atomic Red Team, PyRIT, Garak, MITRE ATT&CK, MITRE ATLAS, Model Context Protocol (MCP), AWS, GCP, Azure
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (AppSec)
Austin, Texas, United States
OnsiteFull Time
webAI
webAI: Secure on-device AI infrastructure for distributed enterprise applications
7+ YOE7+ years in cybersecurity/appsec, offensive testing and secure SDLC experience; expertise securing distributed systems and Rust; strong cryptography and threat modeling skills; excellent communication.
Rust
1mo
Save
Mark Applied
Hide
Offensive Security Engineer - Red Team
Orlando, Florida, United States
HybridFull Time
Electronic Arts
Electronic ArtsNASDAQ: EA: Develops and publishes video games and interactive entertainment software.
3+ YOE3+ years offensive security/red teaming experience; proven ability to identify and document complex vulnerabilities in modern apps/APIs/cloud; experience testing AI/LLM integrations and agentic workflows; proficiency with Python, Go, or JavaScript; build custom exploit tooling.
Python, Go, JavaScript, LLM
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer
Austin, Texas, United States
$161k-$242k/yr OnsiteFull Time
Synopsys
SynopsysNasdaq: SNPS: Provides software and IP for semiconductor design and manufacturing.
8+ YOE8+ years penetration testing (app & infra), experience building AI/ML-driven autonomous security testing, familiarity with Burp Suite/Metasploit/Cobalt Strike/BloodHound, cloud (AWS/Azure/GCP), CVSS/OWASP/MITRE frameworks, and development in C/C++/Java/Python.
Burp Suite, Metasploit, Cobalt Strike, BloodHound, AWS, Azure, GCP, CVSS, OWASP Top 10, MITRE ATT&CK, C, C++, Java, Python
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
2w
Save
Mark Applied
Hide
Offensive Security Engineer, Intermediate (Security Engineering, Senior Analyst)
Lexington Park, Maryland, United States
$115k-$170k/yr OnsiteFull Time
The MIL Corporation
The MIL Corporation: Delivering IT, engineering, and financial solutions to government agencies.
5+ YOE5+ years experience in offensive security, Python programming, reverse engineering (GHIDRA, IDA Pro), ability to obtain Top Secret/SCI, DCWF role qualifications within 60 days, strong communication and teamwork.
Python, GHIDRA, IDA Pro, Assembly Language
1mo
Save
Mark Applied
Hide
WebApp Offensive Security Engineer
United States or Chicago
$196k-$242k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Extensive hands-on web application penetration testing experience, ability to reproduce and validate edge-case exploits, strong communication, proxy tool experience (Burp Suite), scripting (Python), and history of security research or bug bounty contributions.
NodeZero, Burp Suite, Python, Nuclei, sqlmap, LangChain, LangFlow, Postgres, Neo4j, Jira, Model Context Protocol (MCP)
1mo
Save
Mark Applied
Hide
Offensive Security Researcher, Kernel & Embedded Security
New York City, New York, United States
OnsiteFull Time
Apple
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Conduct offensive security research to find and fix vulnerabilities across Apple products to protect users; work as part of a security engineering and research team.
2d
Save
Mark Applied
Hide
Senior Principal Engineer, Offensive Security (2026-345)
San Jose, California, United States
$190k-$240k/yr OnsiteFull Time
Astera Labs
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
12+ YOEBachelor's in CS/CE/EE or related,12+ years offensive security experience,expertise in hardware/firmware/embedded/cloud or AD,proficiency in Python/C/C++/assembly,knowledge of MITRE ATT&CK,track record driving remediation.
Python, C, C++, Assembly, Azure, MITRE ATT&CK, PCIe, CXL, COSMOS
1w
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1mo
Save
Mark Applied
Hide
Security Engineer, Offensive Security
Tampa, Florida, United States
OnsiteFull Time
Thrive
Thrive: Provides managed IT, cybersecurity, and cloud services for organizations.
3+ YOE3+ years pentesting experience, strong network and OS internals knowledge, vulnerability discovery and analysis, incident response and risk assessment, client-facing communication, report writing, and familiarity with pentesting tools and scripting.
Burp Suite, Metasploit Framework, Caido, Python
2mo
Save
Mark Applied
Hide
Global Security Engineer Offensive Operations (Remote or Onsite)
Stamford, Connecticut, United States
HybridFull Time
Crane Company
Crane CompanyNYSE: CR: Manufactures engineered components for aerospace and industrial process markets.
5+ YOE5+ years in penetration testing and application security; Linux/Windows admin; offensive security tools; scripting; communication; degree or 5+ years experience.
Metasploit, Nmap, Burp Suite, Impacket, PowerShell, Python, Perl, Ruby, Go, Rust, Java, Linux, Windows