43 offensive security jobs at 32 companies in Washington, DC

4w
Save
Mark Applied
Hide
Lead, Offensive Security
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Washington or Chicago or Boston or Atlanta or Nashville
$142k-$196k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Provides health insurance plans and clinical healthcare services.
6+ YOE6+ Mgmt6+ years in red team/penetration testing with leadership experience; production Python engineering; built or operated agentic AI/LLM applications; experience attacking AI/ML systems; production cloud experience (AWS, GCP, or Azure).
Python, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, AWS, GCP, Azure, Hack The Box Pro Labs
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer (Red Team)
California or Maryland or Virginia or Herndon
$149k-$224k/yr RemoteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
Deep hands-on offensive security/red team experience executing complex engagements, manual exploitation and attack chaining, identity and cloud abuse, custom scripting/tooling, and strong communication with engineering and response teams.
1w
Save
Mark Applied
Hide
Offensive Security Engineer, Technical Lead (In Office or Remote)
McLean or United States
$150k-$224k/yr HybridFull Time
Freddie Mac
Freddie MacOTCQB: FMCC: Purchases and securitizes home mortgages for the secondary market.
8+ YOE8+ years offensive security experience, red team assessments, automation and tooling development, vulnerability exploitation and remediation, expertise in web/cloud/AI domains.
6d
Save
Mark Applied
Hide
Offensive Security Agent Engineer
New York City or Seattle or Washington or San Francisco or United States
$347k-$490k/yr RemoteFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
Staff/principal-level offensive security expertise, domain knowledge in cloud/Kubernetes/web/Linux/macOS, experience building production software and agent systems, strong judgment and communication.
Kubernetes, Linux, macOS
3mo
Save
Mark Applied
Hide
Manager, Offensive Security: Purple Team
McLean or Plano or Richmond
HybridFull Time
Capital One
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years information security; 3+ years threat hunting or detection engineering in cloud/hybrid; 2+ years analyzing EDR and bypass techniques; High School Diploma; relevant certifications listed.
Databricks, Spark, EDR, Log Analysis, Threat Hunting, Incident Response, Forensics, Scripting, Python, PowerShell
1mo
Save
Mark Applied
Hide
Sr. Staff Security Engineer – AI, VMR, Offensive Security
Bethesda or Palo Alto or Dallas or Seattle
$120k-$260k/yr OnsiteFull Time
GEICO
GEICO: Provides vehicle and property insurance services to consumers.
10+ YOE10+ years in security engineering with deep vulnerability management and offensive security experience; hands-on cloud (AWS/Azure/GCP), programming (Python, Go, Java), NIST CSF, compliance (PCI, SOX, NYDFS), and strong leadership and communication skills.
AWS, Azure, GCP, Python, Go, Java, NIST CSF, SIEM, SOAR, CI/CD, CMDB, AI
1mo
Save
Mark Applied
Hide
Sales Executive, Offensive Security Services Consulting (United Kingdom)
United Kingdom or Germany or Austria or Switzerland or Belgium or Netherlands or Luxembourg or United States or India or Europe or McLean
RemoteFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
5+ YOE5+ years quota-carrying cybersecurity or technical professional services sales; experience with offensive security preferred; enterprise sales in Europe and consultative selling; strong communication, negotiation, and forecasting/CRM discipline.
CRM
2mo
Save
Mark Applied
Hide
Senior Security Engineer
McLean, Virginia, United States
OnsiteFull Time
Range
Range: AI-powered platform for wealth management and financial planning.
6+ YOE6+ years security engineering; offensive security; cloud AWS; tooling for security testing (Python/Go); web app vulnerability analysis; threat modeling; translate findings to engineering.
Python, Go, AWS, ECS, EC2, RDS, S3, IAM
1mo
Save
Mark Applied
Hide
Staff Application Security Engineer
Washington, District of Columbia, United States
$150k-$173k/yr OnsiteFull Time
The Nuclear Company
The Nuclear Company: Deploys standardized nuclear reactors for utility-scale energy generation.
4+ YOE4+ years in application/product/software security; experience with secure SDLC tooling (GitHub Advanced Security, CodeQL, Dependabot, SAST/SCA/DAST), familiarity with AWS security, ability to read code (Python, TypeScript, Go, Java, C#, C++), strong communication and offensive-security mindset.
GitHub, GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, DAST, Palantir Foundry, AWS, IAM, CI/CD, Python, TypeScript, Go, Java, C#, C++, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, NERC CIP
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2mo
Save
Mark Applied
Hide
Senior Systems Security Specialist
Baltimore, Maryland, United States
HybridFull Time
DMI
DMI: Provides end-to-end digital transformation and managed IT services.
8+ YOEEight+ years in cybersecurity; five+ years in penetration testing/red team; five+ years in network/web/app testing; security reporting; incident response support; strong scripting; cloud, zero trust, and compliance experience; offensive security certifications; government/regulatory experience.
Metasploit, Burp Suite, Nmap, Wireshark, Nessus, Python, C/C++, PowerShell, Bash
1d
Save
Mark Applied
Hide
Web Developer Security Engineer
Chantilly or United States
$120k-$135k/yr OnsiteFull Time
Applied Intellect
Applied Intellect: Provides professional, technical, and human services to government agencies.
3+ YOE3+ years in web application or application security, proficiency with .NET/C#, modern web stacks, WAF/FIM, log analysis, DevSecOps automation, and current AppSec/offensive/foundational certifications; bachelor\u0002s degree required.
.NET, C#, MVC, WCF, HTML5, CSS3, JavaScript, REST APIs, SQL, GitHub Copilot, OpenAI API/Codex, Python, Node.js, Java, React.js, TypeScript, OWASP Top 10, WAF, FIM, Wireshark, SIEM, IDS/IPS, NDR, EDR, Docker, Kubernetes, AWS
2mo
Save
Mark Applied
Hide
Cyber Security Engineer V
Woodbridge, Virginia, United States
OnsiteFull Time
Redhorse
Redhorse: Delivering data insights and technology solutions to government agencies.
7+ YOEActive Top Secret/SCI with CI Poly; 7+ years in offensive cyber engineering or related fields; strong networking; Linux administration; experience integrating cyber tools into workflows; bachelor’s in a technical field or equivalent experience with certifications.
Linux, Networking, CNO tools
1w
Save
Mark Applied
Hide
Senior Director – AI & Proactive Security
Centreville or Florida or California or Texas or Massachusetts or Pennsylvania or North Carolina or Minnesota or Rhode Island or Colorado or Michigan or New York
OnsiteFull Time
Mobility Global
Mobility GlobalNYSE: MBGL: Provider of critical automotive intelligence and lifecycle data solutions.
15+ YOE15+ years cybersecurity experience with offensive security/red teaming, AI/ML understanding, ability to operationalize AI security and lead cross-functional transformation.
AI Security Posture Management (AISPM), AWS Bedrock, GCP Vertex AI, MLOps
3w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Boston or Chicago or Dallas or Houston or Englewood or Raleigh or Princeton or New York or Southfield or Washington or Toronto or Calgary or Boulder
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOEBachelor's degree or equivalent, minimum 8 years information security experience focused on penetration testing, expertise with offensive techniques, cloud/app security, scripting, and at least one offensive security certification.
Burp Suite, Nessus, Metasploit, Nmap, DAST, SAST, SCA, CI/CD, Bash, Python, Go, PowerShell, JavaScript, MITRE ATT&CK, OWASP Top 10, CVE, CVSS, CWE
1w
Save
Mark Applied
Hide
Penetration Testers – Senior (Lead)
Washington, District of Columbia, United States
$140k-$170k/yr OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
8+ YOE4+ Mgmt8+ years offensive security experience with 4+ years leading penetration testing/red team operations, Bachelor's degree, public trust clearance eligibility, multiple offensive security certs, strong communication and cloud/app testing skills.
Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, Python, PowerShell, Bash, Ruby, AWS, Azure, GCP
3mo
Save
Mark Applied
Hide
Android CNO Software Developer
Annapolis Junction, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years Android offensive software development; Java on Android; Android NDK C; offensive security concepts; reverse engineering tools; build systems; Docker, Python; HS diploma.
Java, Android, Android NDK, C, IDA Pro, Ghidra, Frida, Jadx, ndk-build, Make, CMake, Gradle, GitHub Enterprise CI/CD, Docker, Python
3mo
Save
Mark Applied
Hide
Android CNO Software Developer
Annapolis Junction, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years Android offensive software development; Java on Android; NDK C on Android; offensive security concepts; reverse engineering tools; build systems; Docker; Python; HS diploma or GED.
Java, Android NDK, JNI, ID A Pro, Ghidra, Frida, Jadx, ndk-build, Make, CMake, Gradle, GitHub Enterprise CI/CD, Docker, Python
5d
Save
Mark Applied
Hide
Principal Red Team Engineer
Ashburn or Irving or Cary or Basking Ridge
$121k-$231k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Global provider of wireless, internet, and communication services.
6+ YOEBachelor's or equivalent experience, 6+ years in offensive security or software development, expertise in exploit development, Linux internals, network protocols, and mentoring skills.
Python, C, C++, Rust, Go, Assembly, Ghidra, IDA Pro, Binary Ninja, Kubernetes, Docker, VMware ESXi, Proxmox, Large Language Models (LLMs)
2w
Save
Mark Applied
Hide
Penetration Tester, Mid (TS/SCI Clearance)
Arlington, Virginia, United States
$90k-$130k/yr OnsiteFull Time
Praescient Analytics
Praescient Analytics: Provides data analytics and intelligence for national security missions.
3+ YOEActive TS/SCI clearance, 3+ years offensive security/penetration testing experience, familiarity with OWASP Top 10, cloud and network security, scripting (Python, PowerShell, Bash), and possession of at least one listed security certification.
OWASP Top 10, Python, PowerShell, Bash