131 offensive security engineer jobs at 95 companies in United States
🚀PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yrOn-SiteFull Time
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
webAI: Secure on-device AI infrastructure for distributed enterprise applications
7+ YOE7+ years in cybersecurity/appsec, offensive testing and secure SDLC experience; expertise securing distributed systems and Rust; strong cryptography and threat modeling skills; excellent communication.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Central Hudson Gas & Electric: Delivers electricity and natural gas to the Hudson Valley.
Bachelor's in cybersecurity/IT/CS (or equivalent experience), strong offensive security skills, experience with Metasploit/Cobalt Strike/Burp Suite/Nmap/BloodHound/CrackMapExec, scripting (Python, PowerShell, Bash, C#), SIEM/EDR familiarity, ability to work on-call and during incidents.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years offensive security experience; proficiency in Python or Go; experience with purple team exercises, breach/attack simulation, cloud and API security; strong technical writing and analytical skills.
SynopsysNasdaq: SNPS: Provides software and IP for semiconductor design and manufacturing.
8+ YOE8+ years penetration testing (app & infra), experience building AI/ML-driven autonomous security testing, familiarity with Burp Suite/Metasploit/Cobalt Strike/BloodHound, cloud (AWS/Azure/GCP), CVSS/OWASP/MITRE frameworks, and development in C/C++/Java/Python.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
Electronic ArtsNASDAQ: EA: Develops and publishes video games and interactive entertainment software.
3+ YOE3+ years offensive security/red teaming experience; proven ability to identify and document complex vulnerabilities in modern apps/APIs/cloud; experience testing AI/LLM integrations and agentic workflows; proficiency with Python, Go, or JavaScript; build custom exploit tooling.
The MIL Corporation: Delivering IT, engineering, and financial solutions to government agencies.
5+ YOE5+ years experience in offensive security, Python programming, reverse engineering (GHIDRA, IDA Pro), ability to obtain Top Secret/SCI, DCWF role qualifications within 60 days, strong communication and teamwork.
RunBuggy: Digital marketplace connecting car shippers with vehicle transporters.
3+ YOEBachelor's in cybersecurity, 3+ years web application penetration testing, experience with AWS/Kubernetes/CI, proficiency with Burp Suite/Metasploit/OWASP ZAP/Nmap/SQLmap/Nikto, scripting (Python/Bash/JavaScript), and OSCP/GWAPT/eWPT or equivalent.
CI, Kubernetes, Docker, AWS, Burp Suite, Metasploit, C2 frameworks, OWASP ZAP, Nmap, SQLmap, Nikto, MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, OWASP Top 10 for LLMs, Python, Bash, JavaScript
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yrRemoteFull Time
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Extensive hands-on web application penetration testing experience, ability to reproduce and validate edge-case exploits, strong communication, proxy tool experience (Burp Suite), scripting (Python), and history of security research or bug bounty contributions.
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Conduct offensive security research to find and fix vulnerabilities across Apple products to protect users; work as part of a security engineering and research team.
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yrHybridFull Time
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
DatadogNASDAQ: DDOG: Observability and security platform for cloud applications and infrastructure.
5+ YOE5+ years offensive security experience; production code (Python/Go); cloud, Linux/macOS security, Kubernetes or CI/CD; evasion techniques; strong communication; able to scope and deliver projects.
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yrRemoteFull Time
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
SC Johnson: Manufacturer of household cleaning products and consumer chemicals.
5+ YOEBachelor's in CS/MIS/Engineering or military experience,5+ years cybersecurity experience,2+ years in areas like vulnerability management,threat intel,BAS,threat hunting or offensive security,legal US work authorization.