131 offensive security engineer jobs at 95 companies in United States

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
2mo
Save
Mark Applied
Hide
Offensive Security Engineer
Seattle, Washington, United States
$150k-$200k/yr RemoteFull Time
Staris AI
Staris AI: AI-powered platform for continuous application security validation.
5+ YOE5+ years in application security, strong knowledge of offensive security, open-source attack tools, and cloud/modern environments.
SAST, DAST, Fuzzing, attack automation tools, AI model APIs
3mo
Save
Mark Applied
Hide
Offensive Security Engineer
San Francisco or London or New York City or Remote
$250k-$350k/yr HybridFull Time
Perplexity
Perplexity: AI-powered search engine providing conversational answers with citations.
5+ YOE5+ years in offensive security/red teaming; strong Python/Go; skilled with offensive tooling and AI/ML security.
Burp Suite, Cobalt Strike, Sliver, Mythic, Metasploit, BloodHound, Nuclei, Python, Go
2w
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for building customer engagement applications.
7+ YOE7+ years in offensive security/penetration testing or high-volume bug bounty; expert MITRE ATT&CK/OWASP knowledge; proficiency with offensive tooling; scripting in Python/Bash/C++; advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc, Python, Bash, C++, SIEM
2w
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for programmable messaging, voice, and email.
7+ YOE7+ years in offensive security/pentesting or bug bounty; expert MITRE/OWASP knowledge; proficiency with Burp Suite, Nmap, Metasploit, scripting (Python/Bash); advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (AppSec)
Austin, Texas, United States
OnsiteFull Time
webAI
webAI: Secure on-device AI infrastructure for distributed enterprise applications
7+ YOE7+ years in cybersecurity/appsec, offensive testing and secure SDLC experience; expertise securing distributed systems and Rust; strong cryptography and threat modeling skills; excellent communication.
Rust
2mo
Save
Mark Applied
Hide
Principal Offensive Security Engineer
Palo Alto, California, United States
$168k-$271k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Provides enterprise-grade network, cloud, and endpoint security software.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Kubernetes, Container Security, IaC, CI/CD, Cloud Security
1mo
Save
Mark Applied
Hide
Offensive Security Engineer
Poughkeepsie, New York, United States
$73k-$171k/yr OnsiteFull Time
Central Hudson Gas & Electric
Central Hudson Gas & Electric: Delivers electricity and natural gas to the Hudson Valley.
Bachelor's in cybersecurity/IT/CS (or equivalent experience), strong offensive security skills, experience with Metasploit/Cobalt Strike/Burp Suite/Nmap/BloodHound/CrackMapExec, scripting (Python, PowerShell, Bash, C#), SIEM/EDR familiarity, ability to work on-call and during incidents.
Metasploit, Cobalt Strike, Burp Suite, Nmap, BloodHound, CrackMapExec, Python, PowerShell, Bash, C#, SIEM, EDR, IDS/IPS, MITRE ATT&CK, NIST 800-61, SANS, CIS Critical Security Controls
1d
Save
Mark Applied
Hide
Senior Offensive Security Engineer
San Mateo, California, United States
$197k-$243k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years offensive security experience; proficiency in Python or Go; experience with purple team exercises, breach/attack simulation, cloud and API security; strong technical writing and analytical skills.
Python, Go, SOAR, MITRE ATT&CK, PTES, BAS, EDR, SIEM, XDR, AWS, Azure, GCP, CI/CD
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer
Austin, Texas, United States
$161k-$242k/yr OnsiteFull Time
Synopsys
SynopsysNasdaq: SNPS: Provides software and IP for semiconductor design and manufacturing.
8+ YOE8+ years penetration testing (app & infra), experience building AI/ML-driven autonomous security testing, familiarity with Burp Suite/Metasploit/Cobalt Strike/BloodHound, cloud (AWS/Azure/GCP), CVSS/OWASP/MITRE frameworks, and development in C/C++/Java/Python.
Burp Suite, Metasploit, Cobalt Strike, BloodHound, AWS, Azure, GCP, CVSS, OWASP Top 10, MITRE ATT&CK, C, C++, Java, Python
3w
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
1mo
Save
Mark Applied
Hide
Offensive Security Engineer - Red Team
Orlando, Florida, United States
HybridFull Time
Electronic Arts
Electronic ArtsNASDAQ: EA: Develops and publishes video games and interactive entertainment software.
3+ YOE3+ years offensive security/red teaming experience; proven ability to identify and document complex vulnerabilities in modern apps/APIs/cloud; experience testing AI/LLM integrations and agentic workflows; proficiency with Python, Go, or JavaScript; build custom exploit tooling.
Python, Go, JavaScript, LLM
1w
Save
Mark Applied
Hide
Offensive Security Engineer, Intermediate (Security Engineering, Senior Analyst)
Lexington Park, Maryland, United States
$115k-$170k/yr OnsiteFull Time
The MIL Corporation
The MIL Corporation: Delivering IT, engineering, and financial solutions to government agencies.
5+ YOE5+ years experience in offensive security, Python programming, reverse engineering (GHIDRA, IDA Pro), ability to obtain Top Secret/SCI, DCWF role qualifications within 60 days, strong communication and teamwork.
Python, GHIDRA, IDA Pro, Assembly Language
1mo
Save
Mark Applied
Hide
Offensive Security Engineer
Tempe, Arizona, United States
HybridFull Time
RunBuggy
RunBuggy: Digital marketplace connecting car shippers with vehicle transporters.
3+ YOEBachelor's in cybersecurity, 3+ years web application penetration testing, experience with AWS/Kubernetes/CI, proficiency with Burp Suite/Metasploit/OWASP ZAP/Nmap/SQLmap/Nikto, scripting (Python/Bash/JavaScript), and OSCP/GWAPT/eWPT or equivalent.
CI, Kubernetes, Docker, AWS, Burp Suite, Metasploit, C2 frameworks, OWASP ZAP, Nmap, SQLmap, Nikto, MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, OWASP Top 10 for LLMs, Python, Bash, JavaScript
2d
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1mo
Save
Mark Applied
Hide
WebApp Offensive Security Engineer
United States or Chicago
$196k-$242k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Extensive hands-on web application penetration testing experience, ability to reproduce and validate edge-case exploits, strong communication, proxy tool experience (Burp Suite), scripting (Python), and history of security research or bug bounty contributions.
NodeZero, Burp Suite, Python, Nuclei, sqlmap, LangChain, LangFlow, Postgres, Neo4j, Jira, Model Context Protocol (MCP)
1mo
Save
Mark Applied
Hide
Offensive Security Researcher, Kernel & Embedded Security
New York City, New York, United States
OnsiteFull Time
Apple
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Conduct offensive security research to find and fix vulnerabilities across Apple products to protect users; work as part of a security engineering and research team.
1w
Save
Mark Applied
Hide
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yr HybridFull Time
Freddie Mac
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
2mo
Save
Mark Applied
Hide
Senior Security Engineer, Offensive Security
New York, New York, United States
$195k-$240k/yr HybridFull Time
Datadog
DatadogNASDAQ: DDOG: Observability and security platform for cloud applications and infrastructure.
5+ YOE5+ years offensive security experience; production code (Python/Go); cloud, Linux/macOS security, Kubernetes or CI/CD; evasion techniques; strong communication; able to scope and deliver projects.
Python, Go, Cloud platforms (AWS, GCP, Azure), Kubernetes, CI/CD, Automation tooling
3w
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
5d
Save
Mark Applied
Hide
Associate Manager, Global Offensive Security Lead
Racine, Wisconsin, United States
HybridFull Time
SC Johnson
SC Johnson: Manufacturer of household cleaning products and consumer chemicals.
5+ YOEBachelor's in CS/MIS/Engineering or military experience,5+ years cybersecurity experience,2+ years in areas like vulnerability management,threat intel,BAS,threat hunting or offensive security,legal US work authorization.
breach attach simulation (BAS)