29 offensive security engineer jobs at 22 companies in Washington, DC

4w
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
5d
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1w
Save
Mark Applied
Hide
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yr HybridFull Time
Freddie Mac
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
3w
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
3mo
Save
Mark Applied
Hide
Manager, Offensive Security: Purple Team
McLean or Plano or Richmond
HybridFull Time
Capital One
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years information security; 3+ years threat hunting or detection engineering in cloud/hybrid; 2+ years analyzing EDR and bypass techniques; High School Diploma; relevant certifications listed.
Databricks, Spark, EDR, Log Analysis, Threat Hunting, Incident Response, Forensics, Scripting, Python, PowerShell
2mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
17h
Save
Mark Applied
Hide
Web Developer Security Engineer
Chantilly or United States
$120k-$135k/yr OnsiteFull Time
Applied Intellect
Applied Intellect: Provides professional, technical, and human services to government agencies.
3+ YOE3+ years in web application or application security, proficiency with .NET/C#, modern web stacks, WAF/FIM, log analysis, DevSecOps automation, and current AppSec/offensive/foundational certifications; bachelor\u0002s degree required.
.NET, C#, MVC, WCF, HTML5, CSS3, JavaScript, REST APIs, SQL, GitHub Copilot, OpenAI API/Codex, Python, Node.js, Java, React.js, TypeScript, OWASP Top 10, WAF, FIM, Wireshark, SIEM, IDS/IPS, NDR, EDR, Docker, Kubernetes, AWS
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
2mo
Save
Mark Applied
Hide
Cyber Security Engineer V
Woodbridge, Virginia, United States
OnsiteFull Time
Redhorse
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
Linux, Networking, CNO tools
1mo
Save
Mark Applied
Hide
Cyber Capability Developer
Chantilly, Virginia, United States
OnsiteFull Time
AnaVation
AnaVation: Providing technical engineering and cybersecurity solutions for federal agencies.
8+ YOEActive Top Secret clearance with SCI eligibility and ability to obtain a CI polygraph; US citizenship; typically 8+ years cyber/software experience (varies by degree); expertise in offensive/defensive cyber tools, exploit research, reverse engineering, secure development, and complex networking.
CI/CD, git, VPN, firewall, proxy, network diode, COTS, GOTS
3w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Boston or Chicago or Dallas or Houston or Englewood or Raleigh or Princeton or New York or Southfield or Washington or Toronto or Calgary or Boulder
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOEBachelor's degree or equivalent, minimum 8 years information security experience focused on penetration testing, expertise with offensive techniques, cloud/app security, scripting, and at least one offensive security certification.
Burp Suite, Nessus, Metasploit, Nmap, DAST, SAST, SCA, CI/CD, Bash, Python, Go, PowerShell, JavaScript, MITRE ATT&CK, OWASP Top 10, CVE, CVSS, CWE
3mo
Save
Mark Applied
Hide
Android CNO Software Developer
Annapolis Junction, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years Android offensive software development; Java on Android; Android NDK C; offensive security concepts; reverse engineering tools; build systems; Docker, Python; HS diploma.
Java, Android, Android NDK, C, IDA Pro, Ghidra, Frida, Jadx, ndk-build, Make, CMake, Gradle, GitHub Enterprise CI/CD, Docker, Python
3mo
Save
Mark Applied
Hide
Android CNO Software Developer
Annapolis Junction, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years Android offensive software development; Java on Android; NDK C on Android; offensive security concepts; reverse engineering tools; build systems; Docker; Python; HS diploma or GED.
Java, Android NDK, JNI, ID A Pro, Ghidra, Frida, Jadx, ndk-build, Make, CMake, Gradle, GitHub Enterprise CI/CD, Docker, Python
1mo
Save
Mark Applied
Hide
Vulnerability Research Engineer
Kyiv or Washington or Tel Aviv or London
RemoteFull Time
Commit
Commit: End-to-end software, cloud, and cybersecurity consulting and development.
2+ YOE2+ years in vulnerability research/offensive security or low-level systems engineering; reverse engineering, binary analysis, fuzzing, exploit development experience; strong OS internals and debugging skills; ability to ship production tools.
1mo
Save
Mark Applied
Hide
Sr Cybersecurity Engineer
Reston, Virginia, United States
$160k-$239k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in incident response, intelligence, vulnerability assessment, security engineering or operations; experience with AI-based offensive tools; proficiency in Python/Java/Kotlin/Scala/JavaScript; threat hunting, detection development, and incident response skills.
Splunk, Spark, Python, Java, Kotlin, Scala, JavaScript
5d
Save
Mark Applied
Hide
Cybersecurity Engineer
Oklahoma City or Chantilly
$90k-$190k/yr HybridFull Time
CACI International
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
7+ YOEBachelor's in related field and 7+ years experience; skills in offensive/defensive security, incident response, OS hardening, vulnerability assessment, Splunk; GPEN/GWAPT/OSCP/OSWA/CISSP/CCSP preferred.
Splunk, Python, JavaScript, Go, .NET
4d
Save
Mark Applied
Hide
Principal Red Team Engineer
Ashburn or Irving or Cary or Basking Ridge
$121k-$231k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Global provider of wireless, internet, and communication services.
6+ YOEBachelor's or equivalent experience, 6+ years in offensive security or software development, expertise in exploit development, Linux internals, network protocols, and mentoring skills.
Python, C, C++, Rust, Go, Assembly, Ghidra, IDA Pro, Binary Ninja, Kubernetes, Docker, VMware ESXi, Proxmox, Large Language Models (LLMs)
2w
Save
Mark Applied
Hide
Penetration Testing Engineer, Senior — Army (TS/SCI)
Arlington, Virginia, United States
OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
5+ YOEActive TS/SCI clearance, GPEN or OSCP, 5+ years penetration testing/offensive security experience, exploit development, reverse engineering, Python/Bash/PowerShell skills, strong reporting and communication, U.S. citizenship required.
Metasploit, Burp Suite, Nmap, Wireshark, Empire, Cobalt Strike, Kali, Parrot, Python, Bash, PowerShell, C, C++, assembly, AWS, Azure