23 offensive security engineer jobs at 17 companies in Westminster, MD
1mo
Save
Mark Applied
Hide
1mo
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yrRemoteFull Time
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yrRemoteFull Time
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yrHybridFull Time
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yrRemoteFull Time
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years information security; 3+ years threat hunting or detection engineering in cloud/hybrid; 2+ years analyzing EDR and bypass techniques; High School Diploma; relevant certifications listed.
8+ YOEBachelor's degree or equivalent, minimum 8 years information security experience focused on penetration testing, expertise with offensive techniques, cloud/app security, scripting, and at least one offensive security certification.
Commit: End-to-end software, cloud, and cybersecurity consulting and development.
2+ YOE2+ years in vulnerability research/offensive security or low-level systems engineering; reverse engineering, binary analysis, fuzzing, exploit development experience; strong OS internals and debugging skills; ability to ship production tools.
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in incident response, intelligence, vulnerability assessment, security engineering or operations; experience with AI-based offensive tools; proficiency in Python/Java/Kotlin/Scala/JavaScript; threat hunting, detection development, and incident response skills.
VerizonNYSE: VZ: Global provider of wireless, internet, and communication services.
6+ YOEBachelor's or equivalent experience, 6+ years in offensive security or software development, expertise in exploit development, Linux internals, network protocols, and mentoring skills.
Python, C, C++, Rust, Go, Assembly, Ghidra, IDA Pro, Binary Ninja, Kubernetes, Docker, VMware ESXi, Proxmox, Large Language Models (LLMs)
8+ YOEBachelor's or equivalent, 8+ years in information security with penetration testing focus; hands-on with Burp Suite, Nessus, Metasploit, Nmap; scripting (Bash, Python, Go, PowerShell, JavaScript); offensive cert (OSCP or similar).
Interrupt Labs: Provides specialized vulnerability research and offensive security services.
Experience in vulnerability research, offensive security, and reverse engineering on Apple platforms; proficient in Python and Rust; able to reverse engineer ARM64 and use IDA, Binary Ninja, Frida.
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOEActive TS/SCI with polygraph; bachelor\u0002s in technical field (or equivalent); 6+ years technical experience across analysis, network/security, offensive ops, reverse engineering, or exploitation; 3+ years with collection/dissemination systems.