... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
... engineering, and post-exploitation activities in a controlled and authorized manner ... The ideal candidate combines deep offensive security expertise with strong operational discipline ...
Application Security Engineer I
$90K - $110K/yr
This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer. What You Will Do: * Participate in ...
Application Security Engineer I
$90K - $110K/yr
This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer. What You Will Do: * Participate in ...
Application Security Engineer I
Arlington, VA · On-site
$90K - $110K/yr
This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer. What You Will Do: * Participate in ...
Application Security Engineer I
Arlington, VA · On-site
$90K - $110K/yr
This entry-level role is ideal for candidates beginning their Application Security career and looking to grow into a seasoned Application Security Engineer. What You Will Do: * Participate in ...
Software Developer- C/C#
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
In addition, desired skills/certifications are: o Offensive Security Experienced Pentester (OSEP ... Reverse Engineering Malware (GREM) Minimum Clearance Required to Start: Top Secret SCI This ...
Software Developer- C/C#
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
In addition, desired skills/certifications are: o Offensive Security Experienced Pentester (OSEP ... Reverse Engineering Malware (GREM) Minimum Clearance Required to Start: Top Secret SCI This ...
Software Developer- C/C#
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
In addition, desired skills/certifications are: o Offensive Security Experienced Pentester (OSEP ... Reverse Engineering Malware (GREM) Minimum Clearance Required to Start: Top Secret SCI This ...
Software Developer- C/C#
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
In addition, desired skills/certifications are: o Offensive Security Experienced Pentester (OSEP ... Reverse Engineering Malware (GREM) Minimum Clearance Required to Start: Top Secret SCI This ...
Penetration Tester
Reston, VA · On-site
Experience carrying out social-engineering assessments * Development/modification of exploits ... Offensive Security Certified Professional (OSCP) * Certified Red Team Professional (CRTP) * GIAC ...
Penetration Tester
Reston, VA · On-site
Experience carrying out social-engineering assessments * Development/modification of exploits ... Offensive Security Certified Professional (OSCP) * Certified Red Team Professional (CRTP) * GIAC ...
Red Cyber Operator (new)
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
Antivirus evasion, EDR evasion, offensive infrastructure, phishing and social engineering ... Security, Rogue Ops- Red Team 1 (ROPS), Certified Professional (OSCP), Global Information Assurance ...
Red Cyber Operator (new)
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
Antivirus evasion, EDR evasion, offensive infrastructure, phishing and social engineering ... Security, Rogue Ops- Red Team 1 (ROPS), Certified Professional (OSCP), Global Information Assurance ...
Red Cyber Operator (new)
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
Antivirus evasion, EDR evasion, offensive infrastructure, phishing and social engineering ... Security, Rogue Ops- Red Team 1 (ROPS), Certified Professional (OSCP), Global Information Assurance ...
Red Cyber Operator (new)
Fort Belvoir, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
Antivirus evasion, EDR evasion, offensive infrastructure, phishing and social engineering ... Security, Rogue Ops- Red Team 1 (ROPS), Certified Professional (OSCP), Global Information Assurance ...
Description We are seeking an DevSecOps Engineer to support a federal client by helping integrate ... Familiarity with NIST 800-53, FedRAMP, or other federal security standards * Entry-level ...
New
Description We are seeking an DevSecOps Engineer to support a federal client by helping integrate ... Familiarity with NIST 800-53, FedRAMP, or other federal security standards * Entry-level ...
New
iOS Vulnerability Researcher
Arlington, VA · Remote
$59.50 - $82/hr
Medical
Dental
Vision
Retirement
PTO
We are looking for experienced and passionate people who have a background in vulnerability research, offensive security and reverse engineering on Apple platforms. The role: * You'll join our team ...
Quick apply
iOS Vulnerability Researcher
Arlington, VA · Remote
$59.50 - $82/hr
Medical
Dental
Vision
Retirement
PTO
We are looking for experienced and passionate people who have a background in vulnerability research, offensive security and reverse engineering on Apple platforms. The role: * You'll join our team ...
iOS Vulnerability Researcher
Arlington, VA · On-site +1
$59.50 - $82/hr
Medical
Dental
Vision
Retirement
PTO
We are looking for experienced and passionate people who have a background in vulnerability research, offensive security and reverse engineering on Apple platforms. The role: * You'll join our team ...
iOS Vulnerability Researcher
Arlington, VA · On-site +1
$59.50 - $82/hr
Medical
Dental
Vision
Retirement
PTO
We are looking for experienced and passionate people who have a background in vulnerability research, offensive security and reverse engineering on Apple platforms. The role: * You'll join our team ...
Tier 1 - Vulnerability Assessment Analyst
Ashburn, VA · On-site
$69K - $125K/yr
Bachelors' degree in Computer Science, Engineering, Information Technology, Cyber Security, or ... CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP ...
New
Tier 1 - Vulnerability Assessment Analyst
Ashburn, VA · On-site
$69K - $125K/yr
Bachelors' degree in Computer Science, Engineering, Information Technology, Cyber Security, or ... CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP ...
New
Tier 1 - Vulnerability Assessment Analyst
Ashburn, VA · On-site
$69K - $125K/yr
Bachelors' degree in Computer Science, Engineering, Information Technology, Cyber Security, or ... CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP ...
Tier 1 - Vulnerability Assessment Analyst
Ashburn, VA · On-site
$69K - $125K/yr
Bachelors' degree in Computer Science, Engineering, Information Technology, Cyber Security, or ... CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP ...
Android security Developer with Security Clearance
Herndon, VA · On-site
$150K - $250K/yr
... offensive and defensive cyber problems for our clients. Description Job Title: Android Cyber Tool ... As an Android Cyber Tool Developer, you will play a crucial role in researching and developing ...
Android security Developer with Security Clearance
Herndon, VA · On-site
$150K - $250K/yr
... offensive and defensive cyber problems for our clients. Description Job Title: Android Cyber Tool ... As an Android Cyber Tool Developer, you will play a crucial role in researching and developing ...
CNO Developer with Security Clearance
Herndon, VA · On-site
$129K - $177K/yr
CNO Developer--designs, develops, and tests offensive cyber tools, techniques, and integrated effects for computer network operations (CNO), a critical aspect of national security. These roles ...
CNO Developer with Security Clearance
Herndon, VA · On-site
$129K - $177K/yr
CNO Developer--designs, develops, and tests offensive cyber tools, techniques, and integrated effects for computer network operations (CNO), a critical aspect of national security. These roles ...
Software Engineer (Entry-Level / Developmental) with Security Clearance
Chantilly, VA · On-site
Medical
Dental
Vision
Retirement
PTO
Software Engineer (Entry-Level / Developmental) Location: Chantilly, Virginia Security Clearance: Active TS/SCI with polygraph Job Type: Full-Time Position Overview The selected candidate will ...
Software Engineer (Entry-Level / Developmental) with Security Clearance
Chantilly, VA · On-site
Medical
Dental
Vision
Retirement
PTO
Software Engineer (Entry-Level / Developmental) Location: Chantilly, Virginia Security Clearance: Active TS/SCI with polygraph Job Type: Full-Time Position Overview The selected candidate will ...
Software Engineer (Entry-Level / Developmental)
Chantilly, VA · On-site +1
Medical
Dental
Vision
Retirement
PTO
Software Engineer (Entry-Level / Developmental) Location ... Chantilly, Virginia Security Clearance: Active TS/SCI with polygraph Job Type: Full-Time Position ...
Quick apply
Software Engineer (Entry-Level / Developmental)
Chantilly, VA · On-site +1
Medical
Dental
Vision
Retirement
PTO
Software Engineer (Entry-Level / Developmental) Location ... Chantilly, Virginia Security Clearance: Active TS/SCI with polygraph Job Type: Full-Time Position ...
Entry Level Offensive Security Engineer information
What is the difference between Entry Level Offensive Security Engineer vs Penetration Tester?
| Aspect | Entry Level Offensive Security Engineer | Penetration Tester |
|---|---|---|
| Certifications | CompTIA Security+, CEH (Certified Ethical Hacker) | CEH, OSCP (Offensive Security Certified Professional) |
| Work Environment | Security teams, cybersecurity firms, internal security departments | Consulting firms, security companies, freelance engagements |
| Job Focus | Identify vulnerabilities, develop attack simulations, improve security posture | Perform targeted security assessments, exploit vulnerabilities, report findings |
Both roles involve assessing security weaknesses, often requiring similar certifications like CEH. An Entry Level Offensive Security Engineer typically works within organizations to strengthen defenses, while a Penetration Tester often conducts external assessments for clients. The main difference lies in their scope: engineers focus on proactive security development, whereas testers focus on identifying vulnerabilities through simulated attacks.
What are the key skills and qualifications needed to thrive as an entry level offensive security engineer, and why are they important?
What types of projects or tasks can an entry level offensive security engineer expect to work on during their first year?
What is an entry level offensive security engineer?
What are the most commonly searched types of Offensive Security Engineer jobs in Virginia?
The most popular types of Offensive Security Engineer jobs in Virginia are:
What are popular job titles related to Entry Level Offensive Security Engineer jobs in Virginia?
For Entry Level Offensive Security Engineer jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Entry Level Offensive Security Engineer jobs in Virginia look for?
The top searched job categories for Entry Level Offensive Security Engineer jobs in Virginia are:

Full-time
Re-posted 25 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
We are seeking a skilled Red Team Operator to simulate real-world adversary tactics, techniques, and procedures to assess and improve the organization's detection, response, and resilience capabilities. This role is responsible for planning and executing adversary emulation, penetration testing, social engineering, and post-exploitation activities in a controlled and authorized manner. The ideal candidate combines deep offensive security expertise with strong operational discipline and clear reporting skills.
Work you'll do
As a Red Team Operator on the Cyber Defense & Resilience team, you will be responsible for...
- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Conduct reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration simulations.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Perform phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Deliver clear after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
Qualifications
Required:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week.
- 2+ years of experience within the following:
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports that connect technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Experience with C2 Frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $110,700- $218,300.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
We are seeking a skilled Red Team Operator to simulate real-world adversary tactics, techniques, and procedures to assess and improve the organization's detection, response, and resilience capabilities. This role is responsible for planning and executing adversary emulation, penetration testing, social engineering, and post-exploitation activities in a controlled and authorized manner. The ideal candidate combines deep offensive security expertise with strong operational discipline and clear reporting skills.
Work you'll do
As a Red Team Operator on the Cyber Defense & Resilience team, you will be responsible for...
- Plan and execute red team operations against enterprise environments, web applications, cloud platforms, and endpoints.
- Emulate advanced threat actors using realistic attack paths, tools, and techniques.
- Conduct reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration simulations.
- Assess the effectiveness of security controls, monitoring, and incident response processes.
- Perform phishing, social engineering, and credential attack exercises where authorized.
- Develop custom payloads, scripts, and attack workflows to support engagements.
- Document findings, attack chains, gaps in defenses, and recommendations for remediation.
- Deliver clear after-action reports and debriefs to technical and leadership stakeholders.
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities.
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
Qualifications
Required:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week.
- 2+ years of experience within the following:
- Knowledge of network architecture, protocols, and techniques (e.g., tunneling)
- Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
- Strong knowledge of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
- Experience with command and control frameworks, privilege escalation, lateral movement, and evasion techniques.
- Proficiency with tools such as Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
- Experience with MITRE ATT&CK mapping and threat emulation.
- Ability to write high-quality reports that connect technical findings to business risk.
- Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
- Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Experience with C2 Frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP.
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
- Experience developing custom tooling or modifying public offensive tools.
- Knowledge of malware analysis, reverse engineering, or exploit development.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $110,700- $218,300.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.