2

Entry Level Offensive Security Engineer Jobs (NOW HIRING)

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

Cloud Security Engineer

Mesa, AZ · Remote

$40 - $75/hr

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

Cloud Security Engineer

Corona, CA · Remote

$40 - $75/hr

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

Cloud Security Engineer

Albany, NY · Remote

$40 - $75/hr

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

Cloud Security Engineer

Tacoma, WA · Remote

$40 - $75/hr

... and offensive security techniques -- for real-world accuracy and validity. * Design and solve ... engineering, DFIR, malware analysis, threat intelligence, or adjacent fields, including government ...

next page

Showing results 1-20

Entry Level Offensive Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do entry level offensive security engineer jobs pay per year?

As of Jun 11, 2026, the average yearly pay for entry level offensive security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What is the difference between Entry Level Offensive Security Engineer vs Penetration Tester?

AspectEntry Level Offensive Security EngineerPenetration Tester
CertificationsCompTIA Security+, CEH (Certified Ethical Hacker)CEH, OSCP (Offensive Security Certified Professional)
Work EnvironmentSecurity teams, cybersecurity firms, internal security departmentsConsulting firms, security companies, freelance engagements
Job FocusIdentify vulnerabilities, develop attack simulations, improve security posturePerform targeted security assessments, exploit vulnerabilities, report findings

Both roles involve assessing security weaknesses, often requiring similar certifications like CEH. An Entry Level Offensive Security Engineer typically works within organizations to strengthen defenses, while a Penetration Tester often conducts external assessments for clients. The main difference lies in their scope: engineers focus on proactive security development, whereas testers focus on identifying vulnerabilities through simulated attacks.

What are the key skills and qualifications needed to thrive as an Entry Level Offensive Security Engineer, and why are they important?

To thrive as an Entry Level Offensive Security Engineer, you need a solid understanding of network protocols, cybersecurity fundamentals, and common vulnerabilities, often supported by a bachelor's degree in computer science or a related field. Familiarity with penetration testing tools like Metasploit, Burp Suite, and knowledge of operating systems such as Linux is essential, and entry-level certifications like CompTIA Security+ or CEH are commonly valued. Strong analytical thinking, attention to detail, and effective communication skills help you identify security issues and clearly report findings. These competencies are crucial for assessing organizational security, executing ethical hacking tasks, and helping teams proactively defend against cyber threats.

What types of projects or tasks can an Entry Level Offensive Security Engineer expect to work on during their first year?

As an Entry Level Offensive Security Engineer, you will typically assist with vulnerability assessments, penetration testing, and security audits under the guidance of more experienced team members. Your daily tasks might include running automated scans, analyzing results, writing reports, and helping to develop and validate security tools. Collaboration with IT, development, and incident response teams is also common, as you work together to identify and remediate vulnerabilities. These experiences provide a strong foundation for professional growth and may lead to more advanced responsibilities over time.

What is an Entry Level Offensive Security Engineer?

An Entry Level Offensive Security Engineer is a cybersecurity professional who specializes in testing and assessing the security of computer systems, networks, and applications by simulating real-world attacks. Their primary responsibility is to identify vulnerabilities and weaknesses that malicious hackers could exploit. They use tools and techniques such as penetration testing, vulnerability scanning, and social engineering to find and report security issues. These engineers typically work under the guidance of more experienced team members and help organizations strengthen their security posture.
More about Entry Level Offensive Security Engineer jobs
What cities are hiring for Entry Level Offensive Security Engineer jobs? Cities with the most Entry Level Offensive Security Engineer job openings:
What are the most commonly searched types of Offensive Security Engineer jobs? The most popular types of Offensive Security Engineer jobs are:
What states have the most Entry Level Offensive Security Engineer jobs? States with the most job openings for Entry Level Offensive Security Engineer jobs include:
Infographic showing various Entry Level Offensive Security Engineer job openings in the United States as of June 2026, with employment types broken down into 95% Full Time, 4% Part Time, and 1% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.
Offensive Cybersecurity Operator

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Job Summary:
The Cybersecurity and Infrastructure Security Agency is responsible for protecting the nation's critical infrastructure from cyber threats. They are seeking an Offensive Cybersecurity Operator to plan and execute offensive security engagements, emulating real adversary tactics against federal and critical infrastructure partners, and to brief leadership on remediation priorities.
Responsibilities:
• Lead full-lifecycle red team and penetration-test engagements against federal enterprise networks, cloud tenants (AWS / Azure / GCP), containerized and serverless workloads, web applications, and CI/CD pipelines - owning scoping, rules of engagement, operator tasking, deconfliction, and final reporting.
• Emulate real-world threat actors - design and run ATT&CK-aligned operations that chain initial access, identity/IAM abuse, privilege escalation, and lateral movement to reach crown-jewel systems, then prove impact without causing harm.
• Build and operate offensive infrastructure as code - stand up and tear down C2, redirectors, phishing, and lab/range environments repeatably with Terraform, Ansible, or comparable tooling, with disciplined OPSEC.
• Develop and extend offensive tooling - custom payloads, C2 profiles, exploit adaptations, and AI/LLM-augmented recon, code-review, and triage workflows - and feed that tradecraft back into team capability.
• Run continuous external attack-surface testing - automate discovery and assessment of internet-facing assets, set severity rubrics, and track exposure reduction across the agencies you support.
• Assess emerging attack surface - infrastructure-as-code and pipeline supply chains, SaaS/identity-provider federation, and AI/ML-integrated applications (prompt injection, model abuse, data-exfil paths).
• Partner with threat intelligence and detection engineering - turn current adversary reporting into testable TTPs, and work purple-team to validate and harden defensive coverage after every operation.
• Brief the people who can act - deliver attack narratives and prioritized, concrete remediation to system owners and senior executives in mission-impact terms; mentor operators and set tradecraft, automation, and OPSEC standards for the team.
Qualifications:
Required:
• You must be a U.S. citizen.
• Selective Service - Males born after 12/31/59 must be registered or exempt from Selective Service.
• All Federal employees are required to participate in Direct Deposit/Electronic Funds Transfer for salary payments.
• DHS uses E-Verify, an Internet-based system, to confirm the eligibility of all newly hired employees to work in the United States.
• You must be able to obtain and maintain a security clearance suitable for Federal employment as determined by a background investigation.
• One-year probationary period may be required.
• This position may be designated as essential personnel.
• This position has been identified as a drug testing designated position (TDP) for purposes of the CISA's Drug-Free Workplace Program.
• Experience must be Information Technology (IT)-related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate.
• You must have IT-related experience demonstrating each of the 9 competencies listed below: Attention to Detail, Customer Service, Decision Making, Information Management, Interpersonal Skills, Oral Communication, Problem Solving, Teamwork, Technical Competence.
• In addition to meeting the qualification requirement listed above, you must have at least one year of specialized experience at the next lower GS-grade level (or equivalent).
• You qualify at the GS-13 grade level if you have at least one (1) year of specialized experience at the GS-12 grade level (or equivalent) performing at least three of the specified duties.
• You qualify at the GS-14 grade level if you have at least one (1) year of specialized experience at the GS-13 grade level (or equivalent) performing at least three of the specified duties.
Company:
Cybersecurity and Infrastructure Security Agency protects the resilience of the nation's physical and cyberinfrastructure. Founded in 2007, the company is headquartered in Washington, USA, with a team of 1001-5000 employees. The company is currently Late Stage.