16 offensive security jobs at 8 companies in Philadelphia, PA

2w
Save
Mark Applied
Hide
Senior Manager, Offensive Security
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
10+ YOE3+ Mgmt10+ years in penetration testing, red teaming, or adversary simulation; 3+ years leading teams or programs; bachelor’s degree or equivalent; offensive security expertise and strong stakeholder communication.
MITRE ATT&CK, Large Language Models (LLMs), AI, ML, C2, OSFT
2w
Save
Mark Applied
Hide
Manager, Offensive Security Operations & Engineering
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
8+ YOERequires 8+ years of related experience, including 5+ years of project management, an undergraduate degree or equivalent, and relevant cloud or offensive security certifications.
AWS, Azure, GCP, Infrastructure-as-Code, CI/CD
1w
Save
Mark Applied
Hide
Sr. Associate, Offensive Security
New York City or Collegeville
$79k-$132k/yr HybridFull Time
Pfizer
PfizerNYSE: PFE: Develops and manufactures vaccines and medicines for global healthcare
2+ YOERequires cybersecurity experience, penetration testing or security assessment skills, attack technique knowledge, technical reporting, scripting, and collaboration. Degree and experience alternatives are specified.
MITRE ATT&CK, Python, PowerShell, Bash
2w
Save
Mark Applied
Hide
Manager, Offensive Security Operations & Engineering
Dallas or Charlotte or Malvern or Plano
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
8+ YOERequires 8+ years of related experience, including 5+ years of project management, an undergraduate degree or equivalent, and relevant cloud or offensive security certifications; graduate degree preferred.
AWS, Azure, GCP, Infrastructure-as-Code, CI/CD
2w
Save
Mark Applied
Hide
Senior Manager, Offensive Security
Dallas or Charlotte or Malvern
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
10+ YOE3+ MgmtRequires 10+ years in penetration testing, red teaming, or adversary simulation; 3+ years leading teams or programs; cybersecurity expertise, stakeholder communication, and a relevant bachelor's degree or equivalent experience.
MITRE ATT&CK, LLMs
1mo
Save
Mark Applied
Hide
Security Assurance Penetration Tester
Pennsylvania or Connecticut or Virginia or Massachusetts or Pittsburgh or Delaware or Michigan or New Jersey or Philadelphia or Colorado or New York
$72k-$119k/yr RemoteFull Time
Elsevier
ElsevierLondon Stock Exchange: REL: Provides scientific, technical, and medical research information and analytics.
Hands-on penetration testing experience, familiarity with web/cloud/OS security, scripting, and offensive security tooling; security certification preferred.
Burp Suite, Nmap, Metasploit, Nuclei, OWASP Top 10, CVSS, Python, Bash, PowerShell, AWS, Azure, GCP, SAST, DAST
2w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
1mo
Save
Mark Applied
Hide
Red Team Engineer
Quincy or Clifton or Princeton
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
2+ YOE2–4 years penetration testing/red-team experience preferred, bachelor’s or equivalent hands-on security experience, offensive security proficiency, threat‑informed testing, scripting ability, strong reporting and communication skills.
MITRE ATT&CK
2w
Save
Mark Applied
Hide
Threat Emulation and Exploit Engineer
Dallas or Charlotte or Malvern or Plano
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
5+ YOERequires 5+ years of related experience, including 3 years in threat analysis, a related undergraduate degree or equivalent, and offensive security experience in penetration testing, vulnerability analysis, web security, adversary emulation, and threat intelligence.
2d
Save
Mark Applied
Hide
Engineer III, Red Team
Carrollton or Conshohocken
OnsiteFull Time
Cencora
CencoraNYSE: COR: Distributes pharmaceuticals and provides global healthcare supply chain solutions.
6+ YOEBachelor's degree or equivalent experience; 6+ years in cybersecurity, including 4+ years in red team or offensive security; advanced penetration testing, scripting, reporting, and communication skills.
Cobalt Strike, Nighthawk C2, Metasploit, Evilginx, MITRE ATT&CK, Python, Go, PowerShell, Windows, Linux, MacOS
2w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Calgary or Toronto or Englewood or Chicago or Raleigh or New York or Dallas or Houston
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOE8+ years information security experience focused on penetration testing, application/cloud security, vulnerability management; offensive security certification required; scripting (Bash, Python, Go, PowerShell, JavaScript); experience with DAST/SAST/SCA and CI/CD integration; bachelor's degree or equivalent.
Burp Suite, Nessus, Metasploit, Nmap, OWASP Top 10, MITRE ATT&CK, DAST, SAST, SCA, Bash, Python, Go, PowerShell, JavaScript, AWS, Azure, GCP
2mo
Save
Mark Applied
Hide
Assessments & Exercises - Cybersecurity Solutions Engineer
Jersey City or New York or Wilmington or Columbus or Houston or Plano
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years of cybersecurity experience, formal training or certificate, experience with tactical/operational/strategic capabilities, offensive/defensive security knowledge, strong analytical, communication, and stakeholder collaboration skills.
Python, C, JavaScript, VBScript, firewalls, IDS/IPS, web proxies, DLP, SIEM, SOAR
1w
Save
Mark Applied
Hide
Senior IT Penetration Tester
United States or Oak Brook or Los Angeles or Washington or Troy or New York City or Houston or Chicago or Grand Rapids or Owings Mills or Columbia or Richmond or Memphis or Raleigh or Boston or San Jose or San Francisco or Austin or Kalamazoo or Spokane or Denver or Fort Worth or Atlanta or Orlando or Dallas or Wilmington or Phoenix or San Antonio or Milwaukee or Madison or McLean or Melville or Woodbridge or Stamford or Philadelphia or Charlotte or Greenville or West Palm Beach or Costa Mesa or St. Louis or Fort Lauderdale or Seattle or Pittsburgh or Tulsa or Cincinnati or Cleveland or Columbus or Akron or Cherry Hill or Tampa or Minneapolis or Anchorage or Salt Lake City or Norfolk or Jacksonville or Boulder or Nashville or Las Vegas or Indianapolis or San Diego or Potomac or Baton Rouge or Omaha
$120k-$160k/yr OnsiteFull Time
BDO USA
BDO USA: Provides accounting, tax, and business advisory services to organizations.
4+ YOEFour or more years of hands-on penetration testing experience, strong Windows, Linux, networking, Active Directory, scripting, reporting, client communication, and offensive security tooling skills; high school diploma required.
Kali Linux, Nessus, Tenable, Nmap, Burp Suite, Metasploit, BloodHound, Microsoft 365, OWASP Top 10 for LLM Applications, Python, PowerShell, Bash, Git, GitHub Actions, Azure DevOps, Docker, GitHub, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Splunk, Microsoft Sentinel, GitHub Copilot, Claude Code, Microsoft Azure, AWS, SAML, OAuth 2.0, OpenID Connect, Kerberos, NTLM, TCP/IP, DNS, Windows, Linux
2w
Save
Mark Applied
Hide
Threat Emulation and Exploit Engineer
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
5+ YOE5+ years related experience with 3+ years in threat analysis; undergraduate degree or equivalent; experience in offensive security, penetration testing, vulnerability analysis, adversary emulation; OSCP/OSWA preferred; strong collaboration skills.
2mo
Save
Mark Applied
Hide
Business Process Red Team Operator
Ohio or Columbus or Wilmington or New York or Plano or Jersey City
OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years in cybersecurity or resiliency; experience with offensive security, social engineering, penetration testing, business-process assessments; knowledge of networking, OSes, attack methodologies, assessment frameworks (OWASP/NIST); strong communication and report-writing.
OWASP Top Ten, NIST Cybersecurity Framework, Cobalt Strike, Metasploit, Nmap, Nessus, Burp Suite, Ruby, Python, Perl, C, C++, C#, Java, IDS/IPS, DLP, web proxies, firewalls
2mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix