1

Internship Offensive Security Engineer Jobs in Washington

Senior Security Engineer

Mclean, VA · On-site

$116K - $159K/yr

Required : • 6+ years of professional security engineering experience • Deep hands-on experience with offensive security: red teaming, penetration testing, or vulnerability research • ...

Senior Security Engineer

Mclean, VA · On-site

$116K - $159K/yr

Required : • 6+ years of professional security engineering experience • Deep hands-on experience with offensive security: red teaming, penetration testing, or vulnerability research • ...

We're looking for a highly technical Offensive Security Engineer who thrives at the intersection of software engineering and cybersecurity. Rather than operating as a centralized security reviewer ...

... on offensive security, penetration testing, or vulnerability research * Prior experience performing security testing and assessment in IoT, embedded, or firmware based environments * Working ...

New

Showing results 41-60

Internship Offensive Security Engineer information

What is an internship offensive security engineer?

Internship Offensive Security Engineers are students or early-career professionals who assist organizations in identifying and addressing security vulnerabilities from an attacker's perspective. Their main responsibilities often include performing penetration tests, vulnerability assessments, and security research under the supervision of experienced security engineers. Through this hands-on experience, interns gain practical knowledge of cybersecurity tools, techniques, and industry best practices while contributing to the organization's overall security posture. This role is ideal for those seeking to start a career in cybersecurity, especially in ethical hacking and penetration testing.

What does an internship offensive security engineer do?

As an Internship Offensive Security Engineer, you can expect to work on a variety of hands-on tasks such as assisting with penetration testing, vulnerability assessments, and security research. Interns often help in simulating real-world cyberattacks under supervision, writing reports on findings, and collaborating with security teams to recommend remediation strategies. You may also participate in red team exercises and learn to use industry-standard tools, gaining exposure to the workflow and methodologies of experienced offensive security professionals. This role offers an excellent opportunity to develop technical skills and gain practical experience in a dynamic, team-oriented environment.

What are the key skills and qualifications needed to thrive as an internship offensive security engineer?

To thrive as an Internship Offensive Security Engineer, you need a solid understanding of cybersecurity fundamentals, network protocols, and penetration testing methodologies, typically supported by relevant coursework or certifications like CompTIA Security+ or OSCP. Familiarity with tools such as Kali Linux, Metasploit, Wireshark, and vulnerability scanners is often essential. Strong analytical thinking, problem-solving skills, and effective communication set top candidates apart. These skills and qualities are crucial for identifying vulnerabilities, collaborating with teams, and ensuring organizational security.

What is the difference between Internship Offensive Security Engineer vs Security Analyst?

AspectInternship Offensive Security EngineerSecurity Analyst
Required CredentialsBasic cybersecurity certifications (e.g., CompTIA Security+), relevant courseworkSecurity+ or equivalent, sometimes additional certifications like CEH
Work EnvironmentHands-on penetration testing, vulnerability assessments, simulated attacksMonitoring security systems, analyzing threats, incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations with active security testing teamsAll industries, focusing on security monitoring and risk management

Internship Offensive Security Engineers focus on practical penetration testing and offensive security tasks, often in a hands-on environment, while Security Analysts primarily monitor and analyze security threats. Both roles require foundational cybersecurity knowledge, but the internship provides more direct offensive security experience.

What are the most commonly searched types of Offensive Security Engineer jobs in Washington?

The most popular types of Offensive Security Engineer jobs in Washington are:

What job categories do people searching Internship Offensive Security Engineer jobs in Washington look for?

The top searched job categories for Internship Offensive Security Engineer jobs in Washington are:

What cities in Washington are hiring for Internship Offensive Security Engineer jobs?

Cities in Washington with the most Internship Offensive Security Engineer job openings:

Web Developer Security Engineer

CMT Services, Inc.

Washington, DC • On-site

Full-time

Re-posted 13 days ago


Job description

ABOUT US:


CMT Services Inc. is a dynamic and small business supporting Federal, State, and Local government agencies. As an SBA-certified HUBZone, Woman Owned Small Business (WOSB), we deliver quality, professional services to supportthe missions and strategic business goals of our clients.

PositionTitle: Web Developer Security Engineer

Location:

US Congressional Budget Office

Ford House Office Building, 4th floor

2nd St SW, 441 D St SW

Washington, DC 20024

Period of Performance:

08/15/2026 - 08/14/2031

Place of Performance:

Remote work; however, at CBO's discretion employees may be required to work on-site at CBO facilities


Position Summary:

Protects CBO's mission-critical web applications, APIs, and sensitive data by embedding strong security throughout the software development lifecycle - making security a proactive, built-in part of design and delivery.

Key Responsibilities:

  • Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
  • Drive the end-to-end vulnerability lifecycle - proactive threat modeling, advanced security assessments, and remediation validation.
  • Support integration of security controls into application architectures, APIs, and services; advise on secure design patterns, data protection, and secure communication protocols.
  • Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat-intelligence integration; support end-to-end response to web application security events.
  • Maintain documentation of findings, remediation steps, and security controls.
  • Ensure web applications and cloud infrastructure comply with NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and authorization.

Required Qualifications:

  • Extensive hands-on secure software development, DevSecOps automation, and vulnerability remediation.
  • Proficiency in log analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF).
  • Minimum 3 years in Web Application Security, AppSec, or secure SDLC (SSDLC).
  • Development with modern web technologies and frameworks including .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.
  • Ability to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits.
  • Strong understanding of OWASP Top 10, secure coding standards, and mitigation of common web vulnerabilities.
  • Deploying, tuning, and maintaining WAF solutions tailored to custom applications and traffic patterns.
  • Configuring/managing File Integrity Monitoring (FIM) for web content directories.
  • Familiarity with security testing tools - Wireshark, SIEM, IDS/IPS, NDR, or EDR.
  • Evaluating/recommending/implementing security controls for mobile device and mobile-web interfaces.
  • Performing complex risk assessments, analyzing cyber threats, and providing remediation guidance for core systems and dependencies.
  • Implementing DevSecOps principles - integrating security controls throughout the CI/CD pipeline.
  • Developing security metrics, managing compliance reporting, and auditing systems against baselines.
  • Effective cross-team collaboration and independent work; providing Tier II support for security operations.

Education:

  • Bachelor's degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.

Certification:

  • Specialized AppSec: CSSLP (Certified Secure Software Lifecycle Professional); GWEB (GIAC Certified Web Application Defender); CASE (EC-Council Certified Application Security Engineer).
  • Offensive Security: OSWE (OffSec Web Expert); OSCP (Offensive Security Certified Professional).
  • Foundational Security: Security+; GSEC.


Join Our Team:

AtCMT Services, we believe that extraordinary results come from empowering exceptional people. If you're ready to lead innovative projects, solve complex challenges, and contribute to meaningful infrastructure development while advancing your career in a supportive, collaborative environment, we want to hear from you.

Disclaimer:

By submitting your resume for this job posting, you authorize CMT Services, Inc. to forward your resume to all applicable internal and external managers, agencies, and recruitment personnel for review and consideration to hire.