2

Offensive Security Engineer Remote Jobs in Oregon

This is a remote role. We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall ...

Senior Security Engineer (Cloud)

OR · On-site +1

$114K - $156K/yr

Senior Security Engineer (Cloud) United States - Remote The role in a nutshell: We're looking for a Senior Security Engineer to engineer and secure our multi-cloud environment, the same cloud ...

This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one ... As Our Product Security Engineer, You Will: * Get involved early in new products and features ...

This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one ... As Our Product Security Engineer, You Will: * Get involved early in new products and features ...

Senior Enterprise Security Engineer

OR · On-site +1

$114K - $156K/yr

As a Senior Security Engineer focused on Enterprise Security , you will play a critical role in ... Remote (US), Burlingame (CA), Columbus (OH), Austin (TX), New York City Time Zone Requirements ...

Senior Security Engineer, Blue Team

OR · On-site +1

$130K - $185K/yr

As a Senior Security Engineer on the Blue Team at BetterHelp, you'll join a diverse team of ... Remote work with regular in-person bonding experiences sponsored by the company * Competitive ...

Senior Software Engineer (Remote)

OR · On-site +1

$122K - $161K/yr

This is a remote role anywhere in the USA. Meet the Team Our software engineering team develops ... We are looking for an experienced engineer who enjoys solving complex security problems through ...

Senior Software Engineer (Remote)

Portland, OR · Remote

$129K - $171K/yr

This is a remote role anywhere in the USA. Meet the Team Our software engineering team develops ... We are looking for an experienced engineer who enjoys solving complex security problems through ...

Senior Director of Sales, Enterprise

OR · On-site +1

$150K - $187K/yr

Today our diverse, fully remote team is committed to helping organizations of all sizes with seamless, effective and collaborative Offensive Security Testing that empower organizations to OPERATE ...

We own software security across the full range of enterprise technology in scope ... We act asa strategic partnertoProduct Management, Engineering, and IT and Enterprise Operations ...

We own software security across the full range of enterprise technology in scope ... We act asa strategic partnertoProduct Management, Engineering, and IT and Enterprise Operations ...

DevSecOps Engineer

OR · On-site +1

$125K - $155K/yr

Our team combines deep security expertise, human-focused design, and exceptional customer service ... Setup for Remote Success. Our team is both decentralized and effective. We reimburse up to $400 for ...

Infrastructure Engineer

OR · On-site +1

$107K - $140K/yr

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Who You Are and What You'll Do As an Infrastructure Engineer, you are a service owner who designs ...

AI Engineer

OR · On-site +1

AI Engineer Remote, USA; potential for minimal ad hoc travel EMKS is seeking an AI Engineer to ... Ability to obtain and maintain necessary security clearances as required for access to classified ...

Penetration Tester

OR · On-site +1

As leaders in continuous offensive security and penetration testing, we deliver world-class ... Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java ...

Showing results 21-40

Offensive Security Engineer Remote information

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote offensive security engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are popular job titles related to Offensive Security Engineer Remote jobs in Oregon?

For Offensive Security Engineer Remote jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Offensive Security Engineer Remote jobs in Oregon look for?

The top searched job categories for Offensive Security Engineer Remote jobs in Oregon are:

What cities in Oregon are hiring for Offensive Security Engineer Remote jobs?

Cities in Oregon with the most Offensive Security Engineer Remote job openings:

Infographic showing various Offensive Security Engineer Remote job openings in Oregon as of September 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 100% Remote job distribution.

Information Security Engineer

OR • On-site, Remote

HSP Group
Business Management Consulting • 51 - 200 employees

Full-time

Re-posted yesterday


Job description

About Us

HSP Group is the premier provider of global expansion services, helping companies simplify the complex challenges of operating internationally. We deliver a seamless experience across legal entity setup, global HR, payroll, compliance, tax, and advisory, enabling our clients to scale faster, stay compliant, and reduce risk in every market they enter. 

With scale-up organizations and innovative technology firms expanding at unprecedented speed, HSP is uniquely positioned to become their trusted global partner. 

Job Description

This is a remote role.

We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall security program. This role sits at the intersection of technical security operations and governance. You will manage vulnerabilities across our products and infrastructure, contribute to corporate security policies, lead SOC 2 efforts, and serve as a key voice in customer and vendor security conversations.

Our entire technology stack runs in Microsoft Azure, and we leverage the broader Microsoft security ecosystem (Intune, Defender, Purview) alongside best-in-class tooling like Datadog, GitHub, and Snyk. You will work closely with Engineering, IT, Legal, and Product teams to drive measurable improvements to our security posture.

Responsibilities: Vulnerability & Product Security
  • Lead the company's SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit.
  • Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
  • Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
  • Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
  • Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
Cloud & Endpoint Security
  • Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
  • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
  • Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
Governance, Risk & Compliance
  • Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
  • Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
  • Support vendor risk assessments and third-party security reviews.
  • Assist with internal and external audits, evidence collection, and remediation of findings.
Security Program & Collaboration
  • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
  • Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
  • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Requirements: 
  • 4-6 years of professional experience in information security, application security, cloud security, or a closely related role.
  • Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
  • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
  • Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
  • Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk.
  • Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design.
  • Experience writing or substantially contributing to security policies, standards, or procedures.
  • Experience in responding to customer security questionnaires and supporting compliance efforts.
  • Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders.
Nice to Have: 
  • Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.
  • Experience with container and Kubernetes security.
  • Exposure to threat modeling, secure code review, or penetration testing.
  • Prior experience in a SaaS company or regulated industry.

If you're a driven individual who wants to make your mark in the heart of the innovation economy, we'd love to meet you. Join our #HSPGlobalSolutionTeam and help us power the next wave of global growth.


HSP Group logo

About HSP Group

Sourced by ZipRecruiter

Industry

Business management consulting

Company size

51 - 200 Employees

Headquarters location

Tampa, FL, US

Year founded

2020