About the Role The Senior Consultant, OT is a technical practitioner in IOActive's Operational ... offensive security services, with at least 2-3 years focused on OT, ICS, or other critical ...
About the Role The Senior Consultant, OT is a technical practitioner in IOActive's Operational ... offensive security services, with at least 2-3 years focused on OT, ICS, or other critical ...
Offensive Security Engineer, Advanced (Security Engineering, Sen with Security Clearance
Lexington Park, MD · On-site
$130K - $193K/yr
Summary The MIL Corporation is seeking an Offensive Security Engineer, Advanced (Security ... Workplaces in Consulting & Professional Servicesâ„¢ * 2021 Fortune Best Workplaces for ...
Offensive Security Engineer, Advanced (Security Engineering, Sen with Security Clearance
Lexington Park, MD · On-site
$130K - $193K/yr
Summary The MIL Corporation is seeking an Offensive Security Engineer, Advanced (Security ... Workplaces in Consulting & Professional Servicesâ„¢ * 2021 Fortune Best Workplaces for ...
Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Quick apply
Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
... security consulting on projects for internal clients to ensure conformity with corporate ... offensive security, with the ability to think like an adversary when hunting and responding to ...
... security consulting on projects for internal clients to ensure conformity with corporate ... offensive security, with the ability to think like an adversary when hunting and responding to ...
Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Quick apply
Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Senior Software Developer (Red Team) with Security Clearance
Fort Belvoir, VA · On-site
$61.75 - $81.50/hr
With over 20 years of expertise in training, consulting, technology, and operational support, the ... Offensive Security Experienced Penetration Tester (OSEP), Advanced Windows Exploitation/ Offensive ...
Senior Software Developer (Red Team) with Security Clearance
Fort Belvoir, VA · On-site
$61.75 - $81.50/hr
With over 20 years of expertise in training, consulting, technology, and operational support, the ... Offensive Security Experienced Penetration Tester (OSEP), Advanced Windows Exploitation/ Offensive ...
Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented ... Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite ...
Working knowledge and familiarity with GRC and Offensive Security consulting services (e.g. penetration testing, PCI audit, security assessment) is highly desirable (pre-sales perspective) * Broad ...
Working knowledge and familiarity with GRC and Offensive Security consulting services (e.g. penetration testing, PCI audit, security assessment) is highly desirable (pre-sales perspective) * Broad ...
Working knowledge and familiarity with GRC and Offensive Security consulting services (e.g. penetration testing, PCI audit, security assessment) is highly desirable (pre-sales perspective) * Broad ...
Working knowledge and familiarity with GRC and Offensive Security consulting services (e.g. penetration testing, PCI audit, security assessment) is highly desirable (pre-sales perspective) * Broad ...
Solutions Engineer
OR · Remote
At least 1 year of experience in offensive security consulting, supporting technical sales of offensive security solutions and services preferred. * Broad understanding of IT infrastructure, ...
Solutions Engineer
OR · Remote
At least 1 year of experience in offensive security consulting, supporting technical sales of offensive security solutions and services preferred. * Broad understanding of IT infrastructure, ...
Security Engineer
Charlotte, NC · On-site
Provide security consulting on projects for internal clients to ensure conformity with corporate ... Knowledge of offensive security, with the ability to think like an adversary when hunting and ...
Quick apply
Security Engineer
Charlotte, NC · On-site
Provide security consulting on projects for internal clients to ensure conformity with corporate ... Knowledge of offensive security, with the ability to think like an adversary when hunting and ...
Senior Consultant, Adversary Services (Red Team)
Chicago, IL · On-site
$152 - $189/hr
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team ... offensive security engagements that help clients measure detection, response, and resilience ...
Senior Consultant, Adversary Services (Red Team)
Chicago, IL · On-site
$152 - $189/hr
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team ... offensive security engagements that help clients measure detection, response, and resilience ...
Penetration Tester
Herndon, VA · On-site
... offensive security toolingManage and configure campaign infrastructureResearch and develop attacks on vulnerable systems and defensive tooling (e.g., AntiVirus, EDR, XDR)Provide ongoing consulting to ...
Quick apply
Penetration Tester
Herndon, VA · On-site
... offensive security toolingManage and configure campaign infrastructureResearch and develop attacks on vulnerable systems and defensive tooling (e.g., AntiVirus, EDR, XDR)Provide ongoing consulting to ...
Future Opening: Embedded AI Content Security Engineer HYBRID
Los Angeles, CA · On-site +1
$140K - $170K/yr
Lead initiatives to build and enhance offensive testing capabilities for both AI and non-AI ... ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland ...
Future Opening: Embedded AI Content Security Engineer HYBRID
Los Angeles, CA · On-site +1
$140K - $170K/yr
Lead initiatives to build and enhance offensive testing capabilities for both AI and non-AI ... ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland ...
Future Opening: Embedded AI Content Security Engineer HYBRID
Los Angeles, CA · On-site +1
$140K - $170K/yr
Lead initiatives to build and enhance offensive testing capabilities for both AI and non-AI ... ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland ...
Future Opening: Embedded AI Content Security Engineer HYBRID
Los Angeles, CA · On-site +1
$140K - $170K/yr
Lead initiatives to build and enhance offensive testing capabilities for both AI and non-AI ... ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland ...
At least 1 year of experience in offensive security consulting, supporting technical sales of offensive security solutions and services preferred. * Broad understanding of IT infrastructure, ...
At least 1 year of experience in offensive security consulting, supporting technical sales of offensive security solutions and services preferred. * Broad understanding of IT infrastructure, ...
In this role you will conduct offensive development for Windows environments. Oak Grove ... With over 20 years of expertise in training, consulting, technology, and operational support, the ...
In this role you will conduct offensive development for Windows environments. Oak Grove ... With over 20 years of expertise in training, consulting, technology, and operational support, the ...
With over 20 years of expertise in training, consulting, technology, and operational support, the ... Offensive Security Experienced Penetration Tester (OSEP), Advanced Windows Exploitation/ Offensive ...
With over 20 years of expertise in training, consulting, technology, and operational support, the ... Offensive Security Experienced Penetration Tester (OSEP), Advanced Windows Exploitation/ Offensive ...
Penetration Tester
Herndon, VA · On-site
OSCP (Offensive Security Certified Professional) * CPTS (Certified Penetration Testing Specialist ... Altus Consulting believes it's essential to keep innovating while safeguarding our digital ...
Penetration Tester
Herndon, VA · On-site
OSCP (Offensive Security Certified Professional) * CPTS (Certified Penetration Testing Specialist ... Altus Consulting believes it's essential to keep innovating while safeguarding our digital ...
Offensive Security Consultant information
See salary details
$10.10 - $19.08
14% of jobs
$25.22 is the 25th percentile. Wages below this are outliers.
$19.08 - $28.06
16% of jobs
$28.06 - $37.04
1% of jobs
$37.04 - $46.02
9% of jobs
The median wage is $50.51 / hr.
$46.02 - $55
20% of jobs
$61.18 is the 75th percentile. Wages above this are outliers.
$55 - $63.99
22% of jobs
$63.99 - $72.97
11% of jobs
$72.97 - $81.95
2% of jobs
$81.95 - $90.93
4% of jobs
$90.93 - $99.91
0% of jobs
$99.91 - $108.89
1% of jobs
$10
$50
$108
How much do offensive security consultant jobs pay per hour?
How does an offensive security consultant typically collaborate with clients and internal teams during a penetration testing engagement?
What does an offensive security consultant do?
What is the difference between Offensive Security Consultant vs Penetration Tester?
| Aspect | Offensive Security Consultant | Penetration Tester |
|---|---|---|
| Certifications | OSCP, OSWE, CEH | OSCP, CEH, GPEN |
| Work Environment | Consulting projects, client sites, security assessments | Security testing, vulnerability assessments, simulated attacks |
| Employer & Industry Usage | Security firms, corporate security teams, consulting agencies | Security firms, internal security teams, freelance roles |
While both roles focus on identifying security vulnerabilities, an Offensive Security Consultant often provides strategic advice and comprehensive security solutions for clients, whereas a Penetration Tester primarily conducts hands-on testing to find specific vulnerabilities. The roles overlap in certifications and work environments, but the Consultant role emphasizes broader security consulting and client interaction.
What are the key skills and qualifications needed to thrive as an offensive security consultant, and why are they important?
What job categories do people searching Offensive Security Consultant jobs look for?
The top searched job categories for Offensive Security Consultant jobs are:

Full-time
Re-posted 26 days ago
Job description
"Making the world a safer and more secure place."
It's our mission, plain and simple. It drives everything we do - from research to client work to community involvement. And it unifies our global team into an elite force with integrity, fierce passion, and relentless creativity that doesn't just "push the envelope" or "think outside the box." We shred the envelope, crush the box, and we have fun doing it. We are always looking for people who share our mission to join us.
About IOActive:
IOActive, a trusted partner for Global 1000 enterprises, provides research-fueled security services across all industries. Our cutting-edge cybersecurity teams provide highly specialized technical and programmatic services including full-stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker's perspective to every engagement to maximize cybersecurity investments and improve the security posture and operational resiliency of our clients. Founded in 1998, IOActive is headquartered in Seattle with global operations, including state of the art hardware hacking labs in Seattle, WA, Madrid, Spain and Cheltenham, UK.
About the Role
The Senior Consultant, OT is a technical practitioner in IOActive's Operational Technology practice. The Senior Consultant leads complex and sensitive OT engagements across industrial control systems, critical infrastructure, embedded industrial devices, and OT/IT convergence environments - turning IOActive's deep research credibility into engagements that genuinely change how clients protect their most sensitive operational environments.
The Senior Consultant is expected to be a force multiplier for the OT practice through informal mentorship of junior consultants, contribution to research and methodology, and visible technical leadership on engagements as well as in the broader OT security community.
What You'll Do
Client Engagement
- Serve as the senior technical voice in client discussions, technical deep-dives, and interviews with industrial systems engineers, control system vendors, and OT security teams
- Lead delivery on OT engagements as the senior consultant on project teams - owning technical approach, methodology, hands-on testing, and findings
- Protect the integrity, safety, and availability of clients' critical assets by leveraging your experience in non-disruptive and non-destructive OT assessment methodologies[AM1]
- Perform hands-on technical work spanning industrial protocols and embedded industrial device analysis
- Conduct network architecture reviews using the Purdue model and industrial segmentation principles; identify safety, availability, and security risks
- Lead threat modeling exercises tailored to OT environments - incorporating safety, availability, and process integrity considerations alongside traditional security risks
- Translate technical findings into business and operational risk language for client engineering, plant operations, and security leadership
- Author and quality-review engagement deliverables to IOActive's standard
- Build trusted technical relationships with client Security Architects, OT Security Leads, Heads of Industrial Cybersecurity, and engineering directors
- Support pre-sales conversations with technical credibility - scoping calls, capability discussions, proposal input
Practice Contribution and Mentorship
Mentor junior and mid-level consultants in OT methodology, tools, and client engagement - even without direct reporting authority
- Contribute to IOActive's OT methodologies, testing playbooks, report templates, and intellectual property
- Identify opportunities to extend IOActive's OT capability - new service offerings, tooling, or research directions
- Collaborate with the Hardware and Silicon practice on embedded industrial device work and component-level analysis where engagements span boundaries
Research and Market Presence
- Contribute to IOActive's OT research - vulnerability discovery, protocol analysis, attack technique development, and published findings
- Build personal profile in the OT security community through attending events, conference talks, published research, working group participation, etc.
- Represent IOActive in OT security industry conversations, standards bodies, and customer advisory engagements as opportunities arise
What You'll Bring
Experience and Background
- 5+ years in offensive security services, with at least 2-3 years focused on OT, ICS, or other critical infrastructure work
- Hands-on engagement delivery experience across multiple OT domains - pen testing, threat modeling, ICS assessments, embedded industrial device security, or red-team / purple-team work in OT environments
- Working knowledge across the breadth of the OT landscape and industrial protocols
- Familiarity with relevant standards and frameworks[AM2]
- Experience working in or alongside plant operations, with appreciation for safety, availability, and process integrity considerations that differentiate OT from IT security work
Capabilities
- Strong technical credibility and the comfort to operate as the senior voice on engagements
- Excellent written communication - you produce reports that clients act on rather than file
- Strong verbal communication, including in technical workshops with engineering audiences and in business conversations with client leadership
- Comfort with the physical and operational realities of OT engagements - plant visits, equipment rooms, control rooms, occasional non-standard hours during testing windows
- Collaborative mindset - OT engagements typically involve close coordination with delivery teams across services lines
- Genuine curiosity about how systems work - OT consultants who succeed at IOActive are the ones who find the problems interesting
Credentials
- Bachelor's degree in Engineering (Computer, Electrical, Industrial, Mechanical), Computer Science, or equivalent experience
- Relevant industry certifications strongly preferred
- Willingness to travel approximately 30%, including on-site work at industrial facilities, sometimes in non-traditional environments, plants, substations, refineries, field locations)
- Ability to obtain relevant security clearances if engagements require it (US: clearance preferred, not required; EMEA: equivalent clearances where applicable)
What We Offer
A chance to work with an industry leader in cyber security
Access to world-class technical teams and research
A high-energy, collaborative team that values innovation
Flexibility-work remotely or from the office as needed
Opportunities for travel
Competitive compensation and performance-based incentives
- Salary range is broadly targeted between $100,000 - $175,000, depending on location, background and experience level
If this sounds like your kind of challenge, we'd love to hear from you. Let's talk!
Why IOActive:
We have over 25 years of experience that's established and stable; yet high-growth with the energy, passion and dynamic work environment of a startup. We are renowned for our innovation and thought leadership within our high-profile, cutting edge space. We're one of "the good guys" doing crazy cool stuff to thwart bad guys in a critically important business, social and political arena. Our work is great fun with great importance. Above all else, we value our people and our customers. Relationships matter.
IOActive is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. IOActive makes hiring decisions based solely on qualifications, merit, and business needs at the time.
About IOActive
Sourced by ZipRecruiter
Industry
Network security
Company size
51 - 200 Employees
Headquarters location
Seattle, WA, US
Year founded
1998