29 offensive security engineer jobs at 22 companies in Laurel, MD
4w
Save
Mark Applied
Hide
4w
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yrRemoteFull Time
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yrRemoteFull Time
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yrHybridFull Time
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yrRemoteFull Time
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years information security; 3+ years threat hunting or detection engineering in cloud/hybrid; 2+ years analyzing EDR and bypass techniques; High School Diploma; relevant certifications listed.
Applied Intellect: Provides professional, technical, and human services to government agencies.
3+ YOE3+ years in web application or application security, proficiency with .NET/C#, modern web stacks, WAF/FIM, log analysis, DevSecOps automation, and current AppSec/offensive/foundational certifications; bachelor\u0002s degree required.
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
AnaVation: Providing technical engineering and cybersecurity solutions for federal agencies.
8+ YOEActive Top Secret clearance with SCI eligibility and ability to obtain a CI polygraph; US citizenship; typically 8+ years cyber/software experience (varies by degree); expertise in offensive/defensive cyber tools, exploit research, reverse engineering, secure development, and complex networking.
8+ YOEBachelor's degree or equivalent, minimum 8 years information security experience focused on penetration testing, expertise with offensive techniques, cloud/app security, scripting, and at least one offensive security certification.
Commit: End-to-end software, cloud, and cybersecurity consulting and development.
2+ YOE2+ years in vulnerability research/offensive security or low-level systems engineering; reverse engineering, binary analysis, fuzzing, exploit development experience; strong OS internals and debugging skills; ability to ship production tools.
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in incident response, intelligence, vulnerability assessment, security engineering or operations; experience with AI-based offensive tools; proficiency in Python/Java/Kotlin/Scala/JavaScript; threat hunting, detection development, and incident response skills.
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
7+ YOEBachelor's in related field and 7+ years experience; skills in offensive/defensive security, incident response, OS hardening, vulnerability assessment, Splunk; GPEN/GWAPT/OSCP/OSWA/CISSP/CCSP preferred.
VerizonNYSE: VZ: Global provider of wireless, internet, and communication services.
6+ YOEBachelor's or equivalent experience, 6+ years in offensive security or software development, expertise in exploit development, Linux internals, network protocols, and mentoring skills.
Python, C, C++, Rust, Go, Assembly, Ghidra, IDA Pro, Binary Ninja, Kubernetes, Docker, VMware ESXi, Proxmox, Large Language Models (LLMs)