57 pentest jobs at 47 companies in United States

PromotedHiringCafe
Founding Backend / Infra Engineer
Cupertino, CA, US
$160k-$300k/yr On-SiteFull Time
HiringCafe
HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Node.js, Python, Elasticsearch, Redis
2mo
Save
Mark Applied
Hide
Director, Pentest Platform
United States
$280k-$315k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
Lead and scale multiple engineering teams; strong distributed systems and platform architecture; drive product and technical strategy; Bachelor's or Master's in CS/Engineering; experience in security or cybersecurity platforms.
Kubernetes, Docker, Python, Go, C++, C#, Airflow, Temporal, PostgreSQL, MongoDB, Neo4j, CI/CD, AWS, Azure, GCP
3w
Save
Mark Applied
Hide
Senior Backend Engineer - Agentic Pentest
Toronto or Tel Aviv-Yafo or Canada or United States
RemoteFull Time
OX Security
OX Security: Secures software development lifecycles from code to runtime.
5+ YOEBachelor's degree in CS or related field, 5+ years backend experience, proficiency with Node.js, SQL/NoSQL, cloud platforms and microservices, active use of AI tools (Copilot, LLMs), strong problem-solving and mentoring skills.
Copilot, LLMs, Node.js, SQL, NoSQL, AWS, GCP, Docker, Kubernetes
2w
Save
Mark Applied
Hide
Security Engineering Manager (Pentest), Amazon Stores Security
Austin, Texas, United States
RemoteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOE5+ MgmtLead a penetration testing team with 5+ years security management and 5+ years Information Security experience; plan compliance-driven penetration tests, drive automation, influence stakeholders, and communicate with technical and non-technical audiences.
AWS
1mo
Save
Mark Applied
Hide
Application Security Pentester, Specialist
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
5+ YOE5+ years related experience (including 3 years in IT security or application development), undergraduate degree or equivalent, hands-on web/API/network pentesting, SAST/DAST tooling preferred, Python or Java proficiency, preferred pentesting certifications.
DAST, SAST, MITRE ATT&CK, OWASP Top 10, OWASP Top 10 API, SANS Top 25, Python, Java
1mo
Save
Mark Applied
Hide
Security Engineer, Offensive Security
Tampa, Florida, United States
OnsiteFull Time
Thrive
Thrive: Provides managed IT, cybersecurity, and cloud services for organizations.
3+ YOE3+ years pentesting experience, strong network and OS internals knowledge, vulnerability discovery and analysis, incident response and risk assessment, client-facing communication, report writing, and familiarity with pentesting tools and scripting.
Burp Suite, Metasploit Framework, Caido, Python
2mo
Save
Mark Applied
Hide
Cybersecurity Pentester
Norcross, Georgia, United States
HybridFull Time
ACI Worldwide
ACI WorldwideNASDAQ: ACIW: Powering the world's real-time electronic payments ecosystem.
1+ YOE1-3 years in information security; bachelor's degree in computer science or related field; OSCP/CRTO/CRTP/OSEP/GXPN or similar certifications a plus; strong OWASP knowledge; proficient with manual and automated pentesting tools; ability to report findings and recommendations.
Burp, OWASP ZAP, NMAP, OpenVAS, OpenSSL, Cobalt Strike, SQLmap, Pupy, Mimikatz, Metasploit, Python, C++, Perl, Ruby
1mo
Save
Mark Applied
Hide
Sr Advanced Cyber Security Architect/Engineer
Atlanta or Mason
HybridFull Time
Honeywell
HoneywellNASDAQ: HON: Manufactures aerospace products, building technologies, and industrial control systems.
7+ YOEBachelors in CS/SE/EE or equivalent; 7+ years penetration testing (or 5+ pentesting plus 2+ years app development); experience with web/mobile/API/cloud/containers/hardware/ICS pentesting; scripting, fuzzing, reverse engineering, CI/CD integration; strong communication.
CI/CD
17h
Save
Mark Applied
Hide
Cybersecurity Instructor (Ethical Hacking, SOC, Web Pentesting, AI Security)
United States
RemoteContract
Educate 360
Educate 360: Provides professional training and certification programs for corporate teams.
3+ YOE3+ years cybersecurity experience, expertise in ethical hacking/SOC/web pentesting/AI security, teaching or mentoring experience, hands-on lab skills, strong communication; industry certs (OSCP, PNPT, PJPT, PSAA, GIAC) are a plus.
OSINT, SIEM, exploitation frameworks
3mo
Save
Mark Applied
Hide
Member of Technical Staff - Security
San Francisco or United States
$180k-$350k/yr RemoteFull Time
Prime Intellect
Prime Intellect: Decentralized infrastructure for training and deploying agentic AI models.
5+ YOE5+ years security engineering; cloud security (GCP), Kubernetes; Python and Rust; external pentests; incident response; SOC 2/ISO awareness.
Python, Rust, Kubernetes, GCP, mTLS, container-runtime-hardening, eBPF
3mo
Save
Mark Applied
Hide
Contract IT Careers Instructor - Part Time
Saint Paul, Minnesota, United States
$35-$45/hr HybridPart Time, Contract
Hmong American Partnership
Hmong American Partnership: Non-profit providing social, economic, and educational services to immigrants.
3+ YOEThree years IT experience; current CompTIA certifications (A+, N+, S+, CySA+, PenTest+); proven teaching experience, online preferred; strong communication and classroom management.
CompTIA A+, CompTIA Network+, CompTIA Security+, CompTIA CySA+, CompTIA PenTest+
1d
Save
Mark Applied
Hide
Member of Technical Staff, Security Engineer
New York City, New York, United States
$150k-$250k/yr OnsiteFull Time
Arca
Arca: AI-native wealth management platform for personalized financial advice.
Ownership of security across AWS, applications, identity, IT, and compliance; experience with threat modeling, IAM/SSO/RBAC, secrets management, bug bounty/VDP, and working with pentesters.
AWS, VPC, VPN, IAM, SSO, RBAC, bug bounty, VDP
1mo
Save
Mark Applied
Hide
Reverse Engineer- Android
United States
RemoteFull Time
Trellix
Trellix: Provides an open cybersecurity platform for threat response.
3+ YOE3+ years in Android development/reverse engineering/pentesting, experience analyzing Android apps/SDKs, static and dynamic analysis, familiarity with reverse engineering tools and mobile languages.
Jadx, Ghidra, Frida, IDA Pro, Burp, Java, Kotlin, JavaScript, Flutter, ELF, SQL, Yara, VirusTotal, ExploitDB, MITRE, AOSP
2mo
Save
Mark Applied
Hide
Principal Offensive Security Engineer
Palo Alto, California, United States
$168k-$271k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Provides enterprise-grade network, cloud, and endpoint security software.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Kubernetes, Container Security, IaC, CI/CD, Cloud Security
3d
Save
Mark Applied
Hide
Penetration Tester - Cyber Engineer
Aberdeen Proving Ground, Maryland, United States
$90k-$190k/yr OnsiteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOEActive Secret clearance, bachelor’s degree with 5 years relevant experience, professional penetration testing/threat-hunting experience, proficiency with common pentest tools and Linux, exploitation expertise.
nmap, Wireshark, Burp Suite, Nessus, Linux, Bash, Python, Perl, Ruby, Android
3w
Save
Mark Applied
Hide
Technical Delivery Manager 2 (Technical Engagement Manager 2)
United States
$85k-$106k/yr RemoteFull Time
Bugcrowd
Bugcrowd: Provides a crowdsourced platform for security vulnerability testing.
4+ YOE4+ years in customer-facing technical roles; deep knowledge of pentest, bug-bounty and red-team methodologies; strong problem solving, communication, and cross-functional collaboration skills.
2mo
Save
Mark Applied
Hide
Senior Penetration Tester
Arlington, Virginia, United States
HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
6+ YOE6+ years in a technical role; 3+ years in penetration testing; Bachelor's in CS/Cybersecurity or related; web/API pentesting experience; security reporting; scripting in Python/PowerShell; security certifications.
Burp Suite, OWASP ZAP, Nmap, Bloodhound, Metasploit, Cobalt Strike
4d
Save
Mark Applied
Hide
Senior Red Team Operator - Social Engineering Focus
United States
RemoteFull Time
Hexens
Hexens: Provides cybersecurity audits and products for blockchain projects.
Proven red team/adversary simulation and social engineering experience, strong web and network pentesting skills, C2 and post-exploitation ability, solo engagement execution, and strong client communication.
C2, Bugcrowd, HackerOne
1w
Save
Mark Applied
Hide
Team Lead, AppSec
Boston or United States or Dominican Republic or Canada
$175k-$200k/yr RemoteFull Time
Forward Financing
Forward Financing: Provides fast, flexible capital to underserved small businesses.
7+ YOE7+ years in application/product/offensive security with leadership experience; hands-on pentesting, code review, AWS and secure SDLC experience; proficiency with Ruby, Python, or Go; strong communication skills.
AWS, Ruby, Python, Go, LLM
2w
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for programmable messaging, voice, and email.
7+ YOE7+ years in offensive security/pentesting or bug bounty; expert MITRE/OWASP knowledge; proficiency with Burp Suite, Nmap, Metasploit, scripting (Python/Bash); advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc
3mo
Save
Mark Applied
Hide
Cybersecurity Engineer
Fort Meade, Maryland, United States
$193k-$213k/yr OnsiteFull Time
GovCIO
GovCIO: Provides technology and mission support services to federal agencies.
10+ YOEHigh school with 10+ years experience; TS/SCI CI Poly; 10 yrs DoD cybersecurity RMF; cloud and data security; pentesting; DoD 8570.01-M IAT Level II.
RMF, Penetration testing, Vulnerability assessment, Cloud security, Data protection