8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Central Hudson Gas & Electric: Delivers electricity and natural gas to the Hudson Valley.
Bachelor's in cybersecurity/IT/CS (or equivalent experience), strong offensive security skills, experience with Metasploit/Cobalt Strike/Burp Suite/Nmap/BloodHound/CrackMapExec, scripting (Python, PowerShell, Bash, C#), SIEM/EDR familiarity, ability to work on-call and during incidents.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years offensive security experience; proficiency in Python or Go; experience with purple team exercises, breach/attack simulation, cloud and API security; strong technical writing and analytical skills.
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
4+ YOE4+ years offensive security experience, production Python engineering, built/operated agentic AI and LLM-driven tooling, hands-on AI/ML attack testing, and production cloud experience (AWS/GCP/Azure).
webAI: Secure on-device AI infrastructure for distributed enterprise applications
7+ YOE7+ years in cybersecurity/appsec, offensive testing and secure SDLC experience; expertise securing distributed systems and Rust; strong cryptography and threat modeling skills; excellent communication.
Electronic ArtsNASDAQ: EA: Develops and publishes video games and interactive entertainment software.
3+ YOE3+ years offensive security/red teaming experience; proven ability to identify and document complex vulnerabilities in modern apps/APIs/cloud; experience testing AI/LLM integrations and agentic workflows; proficiency with Python, Go, or JavaScript; build custom exploit tooling.
SynopsysNasdaq: SNPS: Provides software and IP for semiconductor design and manufacturing.
8+ YOE8+ years penetration testing (app & infra), experience building AI/ML-driven autonomous security testing, familiarity with Burp Suite/Metasploit/Cobalt Strike/BloodHound, cloud (AWS/Azure/GCP), CVSS/OWASP/MITRE frameworks, and development in C/C++/Java/Python.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
The MIL Corporation: Delivering IT, engineering, and financial solutions to government agencies.
5+ YOE5+ years experience in offensive security, Python programming, reverse engineering (GHIDRA, IDA Pro), ability to obtain Top Secret/SCI, DCWF role qualifications within 60 days, strong communication and teamwork.
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Extensive hands-on web application penetration testing experience, ability to reproduce and validate edge-case exploits, strong communication, proxy tool experience (Burp Suite), scripting (Python), and history of security research or bug bounty contributions.
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Conduct offensive security research to find and fix vulnerabilities across Apple products to protect users; work as part of a security engineering and research team.
Senior Principal Engineer, Offensive Security (2026-345)
San Jose, California, United States
$190k-$240k/yrOnsiteFull Time
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
12+ YOEBachelor's in CS/CE/EE or related,12+ years offensive security experience,expertise in hardware/firmware/embedded/cloud or AD,proficiency in Python/C/C++/assembly,knowledge of MITRE ATT&CK,track record driving remediation.
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yrRemoteFull Time
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
Thrive: Provides managed IT, cybersecurity, and cloud services for organizations.
3+ YOE3+ years pentesting experience, strong network and OS internals knowledge, vulnerability discovery and analysis, incident response and risk assessment, client-facing communication, report writing, and familiarity with pentesting tools and scripting.
Global Security Engineer Offensive Operations (Remote or Onsite)
Stamford, Connecticut, United States
HybridFull Time
Crane CompanyNYSE: CR: Manufactures engineered components for aerospace and industrial process markets.
5+ YOE5+ years in penetration testing and application security; Linux/Windows admin; offensive security tools; scripting; communication; degree or 5+ years experience.