36 pentesting engineer jobs at 33 companies in United States
2d
Save
Mark Applied
Hide
2d
Reverse Engineer (Android)
United States
RemoteFull Time
Trellix: Provides an open cybersecurity platform for threat response.
3+ YOERequires 3–5+ years in Android development, reverse engineering, pentesting, application security, or CTF; experience with Android analysis, security tools, mobile languages, and malware research.
Arca: AI-native wealth management platform for personalized financial advice.
Ownership of security across AWS, applications, identity, IT, and compliance; experience with threat modeling, IAM/SSO/RBAC, secrets management, bug bounty/VDP, and working with pentesters.
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
10+ YOE10+ years engineering or offensive security experience, hands-on OCI offensive security experience, strong cloud attack path knowledge, Python coding, web and cloud pentesting experience, strong research and documentation skills.
Blaze Credit Union: Provides banking and lending services to credit union members.
4+ YOEDesign and maintain security infrastructure, perform vulnerability assessments and incident response; 4+ years information security experience; Security+/CySA+/PenTest+ preferred.
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOEActive Secret clearance, bachelor’s degree with 5 years relevant experience, professional penetration testing/threat-hunting experience, proficiency with common pentest tools and Linux, exploitation expertise.
Pensar: AI-powered continuous adversarial security testing for developers.
5+ YOE5+ years in offensive security or vulnerability research; strong programming in Python, Go, JavaScript, C/C++; experience running end-to-end pentests, customer-facing communication, and open source contributions; Bachelor's degree or equivalent.
Barracuda: Sells cybersecurity software for email, network, and data protection.
5+ YOE5+ years product-focused AppSec experience, proficient in multiple programming languages, hands-on pentesting and code review experience, threat modeling, CI/CD security tooling, and strong communication and presentation skills.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Noblis: Nonprofit science, technology, and strategy firm supporting government missions.
5+ YOEBachelor's in Cybersecurity/CS/Engineering or related field; 5+ years of experience; DoD cybersecurity RMF experience; ability to obtain Secret clearance; U.S. citizenship.
SentinelOneNYSE: S: Provides AI-powered cybersecurity software for threat detection and response.
7+ YOE7+ years in cybersecurity/endpoint defense; strong pre-sales and sales engineering skills; able to lead PoCs; travel up to 50%; excellent written and oral communication; experience selling to mid-to-large customers; knowledge of hacking/exploitation tools and malware defenses.
TikTok: Global short-form video hosting and social media platform.
Currently pursuing a BS/MS in CS/CE/IS or STEM; security engineering experience (threat modeling, tooling, pentesting); proficiency in at least one of JavaScript (Node JS), Go, Python, Java, C++, Rust; able to commit >=3 months.
BreachLock: AI-enabled penetration testing and attack surface management solutions.
3+ YOE3–6 years in offensive security or security consulting; sales engineer or solutions architect experience; pen testing across web apps, networks, cloud; CTEM concepts; OSCP/CEH/GPEN; US-based with travel.
Penetration Testing Tools, Web App Testing, Networks, Cloud Environments, APIs
Field AI: Develops autonomous software brains for robots in unstructured environments.
8+ YOE8+ years in product/security engineering with strong Linux and embedded security background; BS in CS/CE/Robotics/Cybersecurity; experience with threat modeling, pen-testing, and secure design.
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
8+ YOEBachelor's degree in a technical field, active Secret clearance, and 8+ years of cybersecurity experience including 3+ years supporting defense, military, or interagency programs. Expertise in enterprise architectures, Zero Trust, cloud, tactical edge, RMF, NIST, and DevSecOps.
Zero Trust, identity and access management, Risk Management Framework (RMF), NIST, DISA STIGs, SAFe, Scrum, Kanban, DevSecOps, CI/CD, penetration testing