1

Offensive Security Consultant Jobs (NOW HIRING)

It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of ... Summary We're looking for a Senior/Staff Offensive Security Software Engineer with extensive web ...

Security Research Engineer

New York, NY · On-site

$120K - $175K/yr

  • Medical

  • Dental

  • Vision

Experience with AI/LLM-assisted offensive security or building security automation on top of LLMs * Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or ...

Security Research Engineer

Manhattan, NY · On-site

$120 - $175/hr

  • Medical

  • Dental

  • Vision

Experience with AI/LLM-assisted offensive security or building security automation on top of LLMs * Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or ...

Application Security Consultant

Parsippany, NJ · On-site

$70 - $80/hr

  • Medical

  • Dental

  • Retirement

We are seeking an experienced Application Security Consultant to join our Cybersecurity team. In ... Required Qualifications: * 3+ years of hands-on Application Security experience in both offensive ...

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining ... We are now hiring a Senior AI/LLM Security Consultant to help clients stay ahead of emerging AI ...

Staff Attack Engineer, OCI

  • Medical

  • Dental

  • Vision

  • PTO

It is used by IT Ops/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of ... Conduct offensive security research against OCI compute, networking, storage, databases, IAM ...

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining ... We are now hiring a Senior AI/LLM Security Consultant to help clients stay ahead of emerging AI ...

Senior Security Engineer

San Jose, CA · On-site

$209K - $310K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Staff Augmentation (W2 employee of Innovation Consulting) Location: San Jose, CA (Onsite - Monday ... Identify, validate, and respond to security incidents with minimal oversight Offensive Security ...

... as the Offensive Security Group and Cyber Architecture team. Core Responsibilities * Support ... Work with other consultants in a collaborative setting to support and assist the execution and ...

... consulting, vulnerability triage, and security incident response. Examples of what you may work on ... Help run penetration testing and offensive security exercises against Figma's AI infrastructure ...

Showing results 21-40

Offensive Security Consultant information

See salary details

$10

$50

$108

How much do offensive security consultant jobs pay per hour?

As of Aug 14, 2026, the average hourly pay for offensive security consultant in the United States is $50.91, according to ZipRecruiter salary data. Most workers in this role earn between $24.76 and $63.70 per hour, depending on experience, location, and employer.

How does an offensive security consultant typically collaborate with clients and internal teams during a penetration testing engagement?

An Offensive Security Consultant works closely with both clients and internal security teams throughout a penetration testing engagement. At the outset, they meet with clients to define the scope, objectives, and rules of engagement. During the assessment, consultants maintain clear communication to share progress updates and any critical findings that require immediate attention. After the test, they collaborate with internal report reviewers and the client's technical team to present findings, answer questions, and recommend practical remediation steps. This collaborative approach ensures transparency, client trust, and actionable security improvements.

What does an offensive security consultant do?

An Offensive Security Consultant is a cybersecurity professional who specializes in identifying and exploiting vulnerabilities in computer systems, networks, and applications. Their work involves conducting penetration tests, simulating cyberattacks, and providing detailed reports on security weaknesses and how to fix them. By proactively testing security defenses, they help organizations strengthen their overall security posture and protect sensitive data from real-world threats. Offensive Security Consultants often use a variety of tools and techniques to mimic the tactics of malicious hackers, but their goal is to improve, not harm, the client's security.

What is the difference between Offensive Security Consultant vs Penetration Tester?

AspectOffensive Security ConsultantPenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentConsulting projects, client sites, security assessmentsSecurity testing, vulnerability assessments, simulated attacks
Employer & Industry UsageSecurity firms, corporate security teams, consulting agenciesSecurity firms, internal security teams, freelance roles

While both roles focus on identifying security vulnerabilities, an Offensive Security Consultant often provides strategic advice and comprehensive security solutions for clients, whereas a Penetration Tester primarily conducts hands-on testing to find specific vulnerabilities. The roles overlap in certifications and work environments, but the Consultant role emphasizes broader security consulting and client interaction.

What are the key skills and qualifications needed to thrive as an offensive security consultant, and why are they important?

To thrive as an Offensive Security Consultant, you need a deep knowledge of penetration testing, vulnerability assessment, and network security, typically supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, Nmap, and certifications such as OSCP or CEH are highly valued. Strong analytical thinking, effective communication, and problem-solving abilities help you translate technical findings into actionable recommendations for clients. These skills are crucial for identifying security weaknesses and helping organizations defend against cyber threats.
More about Offensive Security Consultant jobs

What job categories do people searching Offensive Security Consultant jobs look for?

The top searched job categories for Offensive Security Consultant jobs are:

Infographic showing various Offensive Security Consultant job openings in the United States as of August 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 100% In-person job distribution, with an average salary of $105,890 per year, or $50.9 per hour.

Principal Security Consultant (Red Team Operator - US)

NetSPI LLC

Minneapolis, MN

Full-time

Re-posted 28 days ago


Job description

NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

Join our mission as a Principal Security Consultant. We're seeking a seasoned security professional who combines deep technical expertise in adversarial simulation with exceptional communication skills to engage both executives and technical teams with equal impact.

On our globally deployed Red Team you will compromise some of the world's most sophisticated and heavily fortified networks. As an operator, you'll collaborate with industry-leading experts while wielding cutting-edge proprietary tools that set the standard for offensive security operations.

In this role, you'll leverage your strategic problem-solving abilities, foster high-performance team dynamics, and drive innovative methodologies to deliver transformative engagements that consistently surpass client expectations.

Responsibilities:

  • Lead comprehensive red team operations by serving as the primary technical operator on both threat intelligence-driven and standard adversarial engagements, where you'll strategically plan scenario execution, orchestrate team resources and timelines, and make critical technical decisions that drive successful outcomes in complex, high-stakes environments.
  • Leverage deep technical expertise in operating systems, network architecture, and infrastructure fundamentals to execute sophisticated attack chains and navigate complex enterprise environments during red team operations.
  • Pioneer cutting-edge offensive security capabilities in coordination with our dedicated malware and capability developers by researching, developing, and operationalizing innovative techniques, proprietary tools, and advanced methodologies that push the boundaries of adversarial simulation and red team effectiveness.
  • Offer mentorship or coaching to growing team members, while sharing knowledge externally through blogs, webinar presentations, or presenting at conferences.
  • Collaborate with cross-functional teams on key activities, including scoping initiatives, providing subject matter expertise in high-stakes sales presentations, and contributing strategic technical insights to marketing campaigns that showcase our capabilities.
  • Help define, document, and continuously refine internal technical processes, service methodologies, and TTPs that standardize excellence across all engagements.
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.

Minimum Qualifications:

  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
  • 5+ years of work experience performing adversarial simulation related engagements
  • Recognized Red Team or Penetration testing specific qualifications such as CCSAS, CCSAM, CRTO, OSED, OSCE (GXPN, GPEN, OSCP, GWAPT or similar certifications may also be considered)
  • Familiarity with offensive tools, based on applicable skillset
  • Deep technical familiarity with offensive and defensive IT concepts and protocols
  • Working knowledge of Windows, Linux and MacOS operating systems internals
  • Extensive understanding of the MITRE ATT&CK framework, OWASP Top 10, and other security frameworks
  • Ability to work independently and as part of a team
  • Proficient communication skills, both written and verbal
  • Willingness to travel up to 10% minimum
  • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs

Preferred Qualifications:

  • Ability to provide technical and QA oversight on the Red Team service line
  • Experience in one or more of the following programming or scripting languages (e.g., Python, PowerShell, Perl, C, C++, C#, Java, Nim, Rust, etc.)

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.