22 offensive security developer jobs at 17 companies in Manassas Park, VA

3w
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
2w
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2d
Save
Mark Applied
Hide
AI Security Engineer, AI Security Unit
Washington, District of Columbia, United States
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
Offensive security experience (red teaming/pen testing), deep LLM vulnerability knowledge, threat modeling, automation/tooling development, client-facing delivery and strong technical writing.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, Model Context Protocol (MCP)
2mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
2mo
Save
Mark Applied
Hide
Cyber Security Engineer V
Woodbridge, Virginia, United States
OnsiteFull Time
Redhorse
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
Linux, Networking, CNO tools
1mo
Save
Mark Applied
Hide
Sr Cybersecurity Engineer
Reston, Virginia, United States
$160k-$239k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in incident response, intelligence, vulnerability assessment, security engineering or operations; experience with AI-based offensive tools; proficiency in Python/Java/Kotlin/Scala/JavaScript; threat hunting, detection development, and incident response skills.
Splunk, Spark, Python, Java, Kotlin, Scala, JavaScript
1mo
Save
Mark Applied
Hide
Cyber Capability Developer
Chantilly, Virginia, United States
OnsiteFull Time
AnaVation
AnaVation: Providing technical engineering and cybersecurity solutions for federal agencies.
8+ YOEActive Top Secret clearance with SCI eligibility and ability to obtain a CI polygraph; US citizenship; typically 8+ years cyber/software experience (varies by degree); expertise in offensive/defensive cyber tools, exploit research, reverse engineering, secure development, and complex networking.
CI/CD, git, VPN, firewall, proxy, network diode, COTS, GOTS
2d
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
2w
Save
Mark Applied
Hide
Cybersecurity Engineer
Oklahoma City or Chantilly
$90k-$190k/yr HybridFull Time
CACI International
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
7+ YOEBachelor's in related field and 7+ years experience; skills in offensive/defensive security, incident response, OS hardening, vulnerability assessment, Splunk; GPEN/GWAPT/OSCP/OSWA/CISSP/CCSP preferred.
Splunk, Python, JavaScript, Go, .NET
4w
Save
Mark Applied
Hide
Penetration Testing Engineer, Senior — Army (TS/SCI)
Arlington, Virginia, United States
OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
5+ YOEActive TS/SCI clearance, GPEN or OSCP, 5+ years penetration testing/offensive security experience, exploit development, reverse engineering, Python/Bash/PowerShell skills, strong reporting and communication, U.S. citizenship required.
Metasploit, Burp Suite, Nmap, Wireshark, Empire, Cobalt Strike, Kali, Parrot, Python, Bash, PowerShell, C, C++, assembly, AWS, Azure
1d
Save
Mark Applied
Hide
Principal Group Software Engineering Manager
Redmond or Mountain View or Reston or New York City or Austin or Boston
$166k-$296k/yr HybridFull Time
Microsoft
MicrosoftNASDAQ: MSFT: Develops software, services, devices, and cloud computing solutions.
8+ YOE6+ MgmtBachelor's in CS or related and 8+ years technical engineering experience (or equivalent); experience leading engineering organizations; offensive/defensive security and AI/ML experience preferred; coding in C/C++/C#/Java/JavaScript/Python; B2B security screening.
C, C++, C#, Java, JavaScript, Python
2w
Save
Mark Applied
Hide
Technical Targeting Analyst
McLean, Virginia, United States
$135k-$216k/yr OnsiteFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
8+ YOEActive TS/SCI with polygraph, 6–8+ years technical experience (analysis, network engineering/security, offensive ops, collection, reverse engineering, exploitation), experience with collection/dissemination systems, strong writing and communication.
2w
Save
Mark Applied
Hide
Technical Targeting Analyst
McLean, Virginia, United States
$135k-$216k/yr OnsiteFull Time
Peraton
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOEActive TS/SCI with polygraph; bachelor\u0002s in technical field (or equivalent); 6+ years technical experience across analysis, network/security, offensive ops, reverse engineering, or exploitation; 3+ years with collection/dissemination systems.
2mo
Save
Mark Applied
Hide
Red Team Operator
Culpeper or Manassas
$101k-$188k/yr RemoteFull Time
SWIFT
SWIFT: Provides secure messaging services for global financial transactions.
5+ YOE5+ years Red Team experience; OSCP or similar; Bachelor's in computer science; strong offensive security across networks, cloud, AD; ability to develop tooling and perform adversary simulations.
C2 frameworks, phishing platforms, OPSEC tooling, penetration testing tools, SIEM/EDR/XDR evasion tooling, Active Directory exploitation, cloud penetration testing