The Cybersecurity and Infrastructure Security Agency is responsible for protecting the nation ... engineering - turn current adversary reporting into testable TTPs, and work purple-team to validate ...
The Cybersecurity and Infrastructure Security Agency is responsible for protecting the nation ... engineering - turn current adversary reporting into testable TTPs, and work purple-team to validate ...
Cloud Security Engineer
Pasadena, TX · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Pasadena, TX · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Beaumont, TX · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Beaumont, TX · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Temecula, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Temecula, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Burbank, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Burbank, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
North Charleston, SC · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
North Charleston, SC · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Alexandria, VA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Alexandria, VA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Mesa, AZ · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Mesa, AZ · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
High Point, NC · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
High Point, NC · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Corona, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Corona, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Scottsdale, AZ · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Scottsdale, AZ · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Stamford, CT · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Stamford, CT · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
New Bedford, MA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
New Bedford, MA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Albany, NY · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Albany, NY · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
San Jose, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
San Jose, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Pompano Beach, FL · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Pompano Beach, FL · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Las Cruces, NM · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Las Cruces, NM · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Santa Clara, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Santa Clara, CA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Palm Coast, FL · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Palm Coast, FL · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Cloud Security Engineer
Tacoma, WA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Quick apply
Cloud Security Engineer
Tacoma, WA · Remote
$40 - $75/hr
... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...
Entry Level Offensive Security Engineer information
See salary details
$61.5K - $74.6K
0% of jobs
$74.6K - $87.7K
2% of jobs
$87.7K - $100.8K
3% of jobs
$100.8K - $113.9K
6% of jobs
$113.9K - $127K
5% of jobs
$127K - $140K
4% of jobs
$141.4K is the 25th percentile. Wages below this are outliers.
$140K - $153.1K
39% of jobs
$161.2K is the 75th percentile. Wages above this are outliers.
$153.1K - $166.2K
24% of jobs
$166.2K - $179.3K
2% of jobs
$179.3K - $192.4K
0% of jobs
$192.4K - $205.5K
14% of jobs
$61.5K
$152.8K
$205.5K
How much do entry level offensive security engineer jobs pay per year?
What is the difference between Entry Level Offensive Security Engineer vs Penetration Tester?
| Aspect | Entry Level Offensive Security Engineer | Penetration Tester |
|---|---|---|
| Certifications | CompTIA Security+, CEH (Certified Ethical Hacker) | CEH, OSCP (Offensive Security Certified Professional) |
| Work Environment | Security teams, cybersecurity firms, internal security departments | Consulting firms, security companies, freelance engagements |
| Job Focus | Identify vulnerabilities, develop attack simulations, improve security posture | Perform targeted security assessments, exploit vulnerabilities, report findings |
Both roles involve assessing security weaknesses, often requiring similar certifications like CEH. An Entry Level Offensive Security Engineer typically works within organizations to strengthen defenses, while a Penetration Tester often conducts external assessments for clients. The main difference lies in their scope: engineers focus on proactive security development, whereas testers focus on identifying vulnerabilities through simulated attacks.
What are the key skills and qualifications needed to thrive as an Entry Level Offensive Security Engineer, and why are they important?
What types of projects or tasks can an Entry Level Offensive Security Engineer expect to work on during their first year?
What is an Entry Level Offensive Security Engineer?

Offensive Cybersecurity Operator
Cybersecurity and Infrastructure Security AgencyPensacola, FL • On-site
Full-time
This job post has expired today. Applications are no longer accepted.
Job description
The Cybersecurity and Infrastructure Security Agency is responsible for protecting the nation's critical infrastructure from cyber threats. They are seeking an Offensive Cybersecurity Operator to plan and execute offensive security engagements, emulating real adversary tactics against federal and critical infrastructure partners, and to brief leadership on remediation priorities.
Responsibilities:
• Lead full-lifecycle red team and penetration-test engagements against federal enterprise networks, cloud tenants (AWS / Azure / GCP), containerized and serverless workloads, web applications, and CI/CD pipelines - owning scoping, rules of engagement, operator tasking, deconfliction, and final reporting.
• Emulate real-world threat actors - design and run ATT&CK-aligned operations that chain initial access, identity/IAM abuse, privilege escalation, and lateral movement to reach crown-jewel systems, then prove impact without causing harm.
• Build and operate offensive infrastructure as code - stand up and tear down C2, redirectors, phishing, and lab/range environments repeatably with Terraform, Ansible, or comparable tooling, with disciplined OPSEC.
• Develop and extend offensive tooling - custom payloads, C2 profiles, exploit adaptations, and AI/LLM-augmented recon, code-review, and triage workflows - and feed that tradecraft back into team capability.
• Run continuous external attack-surface testing - automate discovery and assessment of internet-facing assets, set severity rubrics, and track exposure reduction across the agencies you support.
• Assess emerging attack surface - infrastructure-as-code and pipeline supply chains, SaaS/identity-provider federation, and AI/ML-integrated applications (prompt injection, model abuse, data-exfil paths).
• Partner with threat intelligence and detection engineering - turn current adversary reporting into testable TTPs, and work purple-team to validate and harden defensive coverage after every operation.
• Brief the people who can act - deliver attack narratives and prioritized, concrete remediation to system owners and senior executives in mission-impact terms; mentor operators and set tradecraft, automation, and OPSEC standards for the team.
Qualifications:
Required:
• You must be a U.S. citizen.
• Selective Service - Males born after 12/31/59 must be registered or exempt from Selective Service.
• All Federal employees are required to participate in Direct Deposit/Electronic Funds Transfer for salary payments.
• DHS uses E-Verify, an Internet-based system, to confirm the eligibility of all newly hired employees to work in the United States.
• You must be able to obtain and maintain a security clearance suitable for Federal employment as determined by a background investigation.
• One-year probationary period may be required.
• This position may be designated as essential personnel.
• This position has been identified as a drug testing designated position (TDP) for purposes of the CISA's Drug-Free Workplace Program.
• Experience must be Information Technology (IT)-related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate.
• You must have IT-related experience demonstrating each of the 9 competencies listed below: Attention to Detail, Customer Service, Decision Making, Information Management, Interpersonal Skills, Oral Communication, Problem Solving, Teamwork, Technical Competence.
• In addition to meeting the qualification requirement listed above, you must have at least one year of specialized experience at the next lower GS-grade level (or equivalent).
• You qualify at the GS-13 grade level if you have at least one (1) year of specialized experience at the GS-12 grade level (or equivalent) performing at least three of the specified duties.
• You qualify at the GS-14 grade level if you have at least one (1) year of specialized experience at the GS-13 grade level (or equivalent) performing at least three of the specified duties.
Company:
Cybersecurity and Infrastructure Security Agency protects the resilience of the nation's physical and cyberinfrastructure. Founded in 2007, the company is headquartered in Washington, USA, with a team of 1001-5000 employees. The company is currently Late Stage.
About Cybersecurity and Infrastructure Security Agency
Sourced by ZipRecruiter
Industry
Public administration
Company size
1,001 - 5,000 Employees
Headquarters location
Washington, DC, US
Year founded
2018