36 pentesting engineer jobs at 33 companies in United States

2d
Save
Mark Applied
Hide
Reverse Engineer (Android)
United States
RemoteFull Time
Trellix
Trellix: Provides an open cybersecurity platform for threat response.
3+ YOERequires 3–5+ years in Android development, reverse engineering, pentesting, application security, or CTF; experience with Android analysis, security tools, mobile languages, and malware research.
Jadx, Ghidra, Frida, IDA Pro, Burp, Java, Kotlin, JavaScript, Flutter, ELF, SQL, Yara, AOSP, VirusTotal, ExploitDB, MITRE
3w
Save
Mark Applied
Hide
Member of Technical Staff, Security Engineer
New York City, New York, United States
$150k-$250k/yr OnsiteFull Time
Arca
Arca: AI-native wealth management platform for personalized financial advice.
Ownership of security across AWS, applications, identity, IT, and compliance; experience with threat modeling, IAM/SSO/RBAC, secrets management, bug bounty/VDP, and working with pentesters.
AWS, VPC, VPN, IAM, SSO, RBAC, bug bounty, VDP
1mo
Save
Mark Applied
Hide
Staff Engineer - Offensive Security
United States
$156k-$229k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for programmable messaging, voice, and email.
7+ YOE7+ years in offensive security/pentesting or bug bounty; expert MITRE/OWASP knowledge; proficiency with Burp Suite, Nmap, Metasploit, scripting (Python/Bash); advanced OffSec certifications preferred.
Burp Suite, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, PyRIT, Promptfoo, Garak, Cobalt Strike, Sliver, Havoc
3w
Save
Mark Applied
Hide
Senior Product Security Engineer
Austin, Texas, United States
HybridFull Time
Cloudflare
CloudflareNYSE: NET: Provides security and performance services for internet properties.
Senior product/application security experience in large-scale cloud/SaaS, threat modeling, vulnerability lifecycle ownership, bug bounty and pentest triage, AI/LLM-driven automation, strong communication and cross-functional influence.
LLM, AI, HackerOne, Bugcrowd, JIRA, SAST, fuzzing
2mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
1mo
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
2mo
Save
Mark Applied
Hide
Staff Attack Engineer, OCI
Chicago or United States
$247k-$275k/yr RemoteFull Time
Horizon3.ai
Horizon3.ai: Autonomous penetration testing platform for continuous security assessment.
10+ YOE10+ years engineering or offensive security experience, hands-on OCI offensive security experience, strong cloud attack path knowledge, Python coding, web and cloud pentesting experience, strong research and documentation skills.
Python, NodeZero, Oracle Cloud Infrastructure (OCI), Oracle Kubernetes Engine (OKE), Kubernetes, AWS, Azure, GCP
2w
Save
Mark Applied
Hide
Sr IS Systems Engineer
Saint Paul, Minnesota, United States
$78k-$118k/yr OnsiteFull Time
Blaze Credit Union
Blaze Credit Union: Provides banking and lending services to credit union members.
4+ YOEDesign and maintain security infrastructure, perform vulnerability assessments and incident response; 4+ years information security experience; Security+/CySA+/PenTest+ preferred.
firewalls, Intrusion detection systems, VPNs, endpoint protection, IDS/IPS, SEIM, vulnerability scanning, PKI, SSL/TLS
3w
Save
Mark Applied
Hide
Penetration Tester - Cyber Engineer
Aberdeen Proving Ground, Maryland, United States
$90k-$190k/yr OnsiteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOEActive Secret clearance, bachelor’s degree with 5 years relevant experience, professional penetration testing/threat-hunting experience, proficiency with common pentest tools and Linux, exploitation expertise.
nmap, Wireshark, Burp Suite, Nessus, Linux, Bash, Python, Perl, Ruby, Android
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
London or New York or Pune or Toronto
$125k-$165k/yr OnsiteFull Time
TripleLift
TripleLift: Programmatic advertising platform for high-quality digital ad experiences.
5+ YOE5+ years application security experience; hands-on SAST/DAST/SCA, CI/CD integration, pentesting, threat modeling, secure coding guidance, and AWS security controls.
GitHub Advanced Security (GHAS), CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, Python, Java, TypeScript, Go, IAM, VPC, KMS, GuardDuty, CloudTrail, Claude
2mo
Save
Mark Applied
Hide
Security Research Engineer
New York, New York, United States
$120k-$175k/yr OnsiteFull Time
Pensar
Pensar: AI-powered continuous adversarial security testing for developers.
5+ YOE5+ years in offensive security or vulnerability research; strong programming in Python, Go, JavaScript, C/C++; experience running end-to-end pentests, customer-facing communication, and open source contributions; Bachelor's degree or equivalent.
Apex, Python, Go, JavaScript, C/C++, AWS, GCP, Azure, AI/LLM
2mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Ann Arbor or Alpharetta or United States
RemoteFull Time
Barracuda
Barracuda: Sells cybersecurity software for email, network, and data protection.
5+ YOE5+ years product-focused AppSec experience, proficient in multiple programming languages, hands-on pentesting and code review experience, threat modeling, CI/CD security tooling, and strong communication and presentation skills.
TypeScript, JavaScript, Python, Ruby, Java, Go, CI/CD, SAST, SCA, Secrets Scanning, AI security controls, LLM, XDR
2mo
Save
Mark Applied
Hide
Principal Offensive Security Engineer
Palo Alto, California, United States
$168k-$271k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Provides enterprise-grade network, cloud, and endpoint security software.
8+ YOE8+ years in Offensive Security/Red Teaming, cloud expertise (GCP/AWS/Azure), Kubernetes security, IaC/CI–CD security, and led pentests/red team ops.
Kubernetes, Container Security, IaC, CI/CD, Cloud Security
3mo
Save
Mark Applied
Hide
Cyber Security Engineer
Washington, Washington, DC, United States
$87k-$136k/yr OnsiteFull Time
Noblis
Noblis: Nonprofit science, technology, and strategy firm supporting government missions.
5+ YOEBachelor's in Cybersecurity/CS/Engineering or related field; 5+ years of experience; DoD cybersecurity RMF experience; ability to obtain Secret clearance; U.S. citizenship.
RMF, A&A, Navy security policies, POA&M, Vulnerability scanning, Security testing, Network diagrams
2mo
Save
Mark Applied
Hide
Software Engineer - Senior (contingent 045)
Aberdeen Proving Ground, Maryland, United States
OnsiteFull Time
Systems Products and Solutions: Provides logistics and technical services to defense agencies.
7+ YOESenior software engineer with DoD biometric systems experience; security clearance required; Agile/DevSecOps; Android apps; cybersecurity.
Android, DevOps, DevSecOps, CI/CD, Security testing, Encryption
2mo
Save
Mark Applied
Hide
Staff Solutions Engineer
Boston, Massachusetts, United States
$224k-$308k/yr HybridFull Time
SentinelOne
SentinelOneNYSE: S: Provides AI-powered cybersecurity software for threat detection and response.
7+ YOE7+ years in cybersecurity/endpoint defense; strong pre-sales and sales engineering skills; able to lead PoCs; travel up to 50%; excellent written and oral communication; experience selling to mid-to-large customers; knowledge of hacking/exploitation tools and malware defenses.
Endpoint security, EDR, Threat hunting, Hacking tools, Penetration testing
1mo
Save
Mark Applied
Hide
Security Software Engineer Project Intern (Product Security) - 2026 Start (BS/MS)
San Jose, California, United States
OnsiteInternship
TikTok
TikTok: Global short-form video hosting and social media platform.
Currently pursuing a BS/MS in CS/CE/IS or STEM; security engineering experience (threat modeling, tooling, pentesting); proficiency in at least one of JavaScript (Node JS), Go, Python, Java, C++, Rust; able to commit >=3 months.
JavaScript (Node JS), Go, Python, Java, C++, Rust
3mo
Save
Mark Applied
Hide
Sales Engineer - Offensive Security (US Remote)
United States
RemoteFull Time
BreachLock
BreachLock: AI-enabled penetration testing and attack surface management solutions.
3+ YOE3–6 years in offensive security or security consulting; sales engineer or solutions architect experience; pen testing across web apps, networks, cloud; CTEM concepts; OSCP/CEH/GPEN; US-based with travel.
Penetration Testing Tools, Web App Testing, Networks, Cloud Environments, APIs
2mo
Save
Mark Applied
Hide
Robotics Product Security Engineer
Irvine, California, United States
OnsiteFull Time
Field AI
Field AI: Develops autonomous software brains for robots in unstructured environments.
8+ YOE8+ years in product/security engineering with strong Linux and embedded security background; BS in CS/CE/Robotics/Cybersecurity; experience with threat modeling, pen-testing, and secure design.
Linux, Embedded systems, Threat modeling, Penetration testing, Secure communications
4d
Save
Mark Applied
Hide
Cybersecurity Engineer
Aberdeen Proving Ground, Maryland, United States
OnsiteFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
8+ YOEBachelor's degree in a technical field, active Secret clearance, and 8+ years of cybersecurity experience including 3+ years supporting defense, military, or interagency programs. Expertise in enterprise architectures, Zero Trust, cloud, tactical edge, RMF, NIST, and DevSecOps.
Zero Trust, identity and access management, Risk Management Framework (RMF), NIST, DISA STIGs, SAFe, Scrum, Kanban, DevSecOps, CI/CD, penetration testing