39 offensive security jobs at 29 companies in Manassas, VA

4w
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
1mo
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
3w
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1mo
Save
Mark Applied
Hide
Sales Executive, Offensive Security Services Consulting (United Kingdom)
United Kingdom or Germany or Austria or Switzerland or Belgium or Netherlands or Luxembourg or United States or India or Europe or McLean
RemoteFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
5+ YOE5+ years quota-carrying cybersecurity or technical professional services sales; experience with offensive security preferred; enterprise sales in Europe and consultative selling; strong communication, negotiation, and forecasting/CRM discipline.
CRM
3mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1w
Save
Mark Applied
Hide
AI Security Engineer, AI Security Unit
Washington, District of Columbia, United States
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
Offensive security experience (red teaming/pen testing), deep LLM vulnerability knowledge, threat modeling, automation/tooling development, client-facing delivery and strong technical writing.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, Model Context Protocol (MCP)
2d
Save
Mark Applied
Hide
Network Security Penetration Tester, AppSTAR Network Security
United States or Virtual or North America
$159k-$202k/yr RemoteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires 3+ years in network penetration testing or offensive security, 3+ years of scripting or programming, security code review, vulnerability remediation, networking protocols, and threat modeling.
AWS, Python, Java, C++, HTTP(S), DNS, TCP/IP, VLAN
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2mo
Save
Mark Applied
Hide
Cyber Security Engineer V
Woodbridge, Virginia, United States
OnsiteFull Time
Redhorse
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
Linux, Networking, CNO tools
3w
Save
Mark Applied
Hide
Senior Director – AI & Proactive Security
Centreville or Florida or California or Texas or Massachusetts or Pennsylvania or North Carolina or Minnesota or Rhode Island or Colorado or Michigan or New York
OnsiteFull Time
Mobility Global
Mobility GlobalNYSE: MBGL: Provider of critical automotive intelligence and lifecycle data solutions.
15+ YOE15+ years cybersecurity experience with offensive security/red teaming, AI/ML understanding, ability to operationalize AI security and lead cross-functional transformation.
AI Security Posture Management (AISPM), AWS Bedrock, GCP Vertex AI, MLOps
4w
Save
Mark Applied
Hide
Penetration Testers – Senior (Lead)
Washington, District of Columbia, United States
$140k-$170k/yr OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
8+ YOE4+ Mgmt8+ years offensive security experience with 4+ years leading penetration testing/red team operations, Bachelor's degree, public trust clearance eligibility, multiple offensive security certs, strong communication and cloud/app testing skills.
Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, Python, PowerShell, Bash, Ruby, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
6d
Save
Mark Applied
Hide
Penetration Tester, Senior (TS/SCI Clearance)
Arlington, Virginia, United States
$110k-$160k/yr OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
8+ YOEActive TS/SCI clearance, U.S. citizenship, 8+ years of offensive security experience, and proficiency in web, cloud, network, and scripting security. At least one listed cybersecurity certification required.
OWASP Top 10, Python, PowerShell, Bash
1w
Save
Mark Applied
Hide
Pentest Operator
Beltsville, Maryland, United States
$113k-$188k/yr OnsiteFull Time
Guidehouse
Guidehouse: Provides management and technology consulting services to diverse organizations.
5+ YOEActive Secret clearance, 5+ years offensive security experience, penetration testing and red team skills, ability to communicate technical findings to stakeholders.
Kali Linux, Burp Suite, Metasploit, Nmap, Nessus, Wireshark, BloodHound, Impacket, Responder, Hashcat, John the Ripper, CrackMapExec, Cobalt Strike, Sliver, SIEM, EDR
1w
Save
Mark Applied
Hide
Senior Red Team Operator
Washington, District of Columbia, United States
OnsiteFull Time
Covington & Burling
Covington & Burling: Global law firm providing legal and regulatory counseling services.
Deep offensive security expertise, penetration testing, adversary emulation, vulnerability research, automation scripting, threat intelligence, and cross-functional technical communication experience.
2mo
Save
Mark Applied
Hide
iOS Vulnerability Researcher
Arlington, Virginia, United States
RemoteFull Time
Interrupt Labs
Interrupt Labs: Provides specialized vulnerability research and offensive security services.
Experience in vulnerability research, offensive security, and reverse engineering on Apple platforms; proficient in Python and Rust; able to reverse engineer ARM64 and use IDA, Binary Ninja, Frida.
Python, Rust, C, Swift, C++, Objective-C, IDA, Binary Ninja, Frida
1w
Save
Mark Applied
Hide
Principal Group Software Engineering Manager
Redmond or Mountain View or Reston or New York City or Austin or Boston
$166k-$296k/yr HybridFull Time
Microsoft
MicrosoftNASDAQ: MSFT: Develops software, services, devices, and cloud computing solutions.
8+ YOE6+ MgmtBachelor's in CS or related and 8+ years technical engineering experience (or equivalent); experience leading engineering organizations; offensive/defensive security and AI/ML experience preferred; coding in C/C++/C#/Java/JavaScript/Python; B2B security screening.
C, C++, C#, Java, JavaScript, Python