2

Offensive Security Engineer Remote Jobs in Crofton, MD

Principal Cyber Investigator

Washington, DC · On-site +1

$150K - $180K/yr

Deep subject-matter expertise in one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations * Familiarity with LLM systems and how ...

Be Seen First

Full Stack Engineer (US - Remote) Position summary We are seeking a highly skilled Full Stack ... security requirements, and software development best practices. The Full Stack Engineer will ...

Our teams support the federal government's most critical national security and defense priorities ... This position is based in Washington, DC and may require a combination of on-site and remote ...

Showing results 41-60

Offensive Security Engineer Remote information

See Crofton, MD salary details

$62.2K

$154.5K

$207.8K

How much do offensive security engineer remote jobs pay per year?

As of Aug 8, 2026, the average yearly pay for offensive security engineer remote in Crofton, MD is $154,502.00, according to ZipRecruiter salary data. Most workers in this role earn between $144,600.00 and $160,300.00 per year, depending on experience, location, and employer.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote offensive security engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.
What cities near Crofton, MD are hiring for Offensive Security Engineer Remote jobs? Cities near Crofton, MD with the most Offensive Security Engineer Remote job openings:

Engineer, Security & Identity

Washington Nationals Baseball Club

Washington, DC • On-site, Remote

$100K - $120K/yr

Full-time

Posted 8 days ago


Job description

Reporting to the Director, IT Operations, the Security & Identity Engineer is the senior IT Operations staff member responsible for implementing, maintaining, and continuously improving the organization’s cybersecurity and identity management capabilities across all enterprise systems. This position ensures the protection of organizational assets through secure access controls, proactive threat detection, and adherence to governance, risk, and compliance standards. The Engineer advances the organization’s Zero Trust security model, secures cloud and SaaS environments, enables safe adoption of AI and automation, and serves as the senior escalation point and design authority for all cybersecurity and identity matters. This position works cross-functionally with IT Operations, Business Strategy & Analytics, Baseball R&D and Risk Management to provide cybersecurity guidance. The Security & Identity Engineer shares Event and On-Call coverage responsibilities on a rotation with the IT team.

The Nationals are a military-friendly organization actively recruiting veterans and spouses.

Essential Duties and Responsibilities:

Security Architecture & Engineering (Core Function)

  • Participate in the design, implementation, and operation of enterprise security architecture.
  • Implement and maintain Zero Trust principles, including identity-first controls and network segmentation.
  • Secure cloud, SaaS, and hybrid environments through appropriate configuration and controls; evaluate and implement new security technologies.

Identity & Access Management

  • Administer and manage identity platforms (e.g., Azure AD/Entra ID, Okta, SSO, MFA, conditional access).
  • Design and enforce role-based and least-privilege access models.
  • Manage and/or audit identity lifecycle processes including provisioning, deprovisioning, and access reviews.
  • Implement and maintain privileged access management (PAM) controls.

Security Operations & Incident Response

  • Monitor, investigate, and respond to security events and alerts across systems and platforms.
  • Coordinate and participate in incident response activities, including root cause analysis and remediation.
  • Support implementation and tuning of security monitoring tools (SIEM, endpoint protection, etc.).
  • Develop and maintain incident response procedures and playbooks.

Vulnerability & Risk Management

  • Conduct recurring vulnerability assessments and security reviews, identifying risks and driving remediation.
  • Partner with relevant teams to remediate identified vulnerabilities.
  • Track and report on risk posture, remediation progress, and security metrics.

Governance, Compliance & Policy

  • Enforce enterprise security policies, standards, and procedures; support audits, compliance initiatives, and regulatory requirements.
  • Assist in the development and maintenance of security documentation, baselines, and guidelines.

AI, SaaS & Data Security

  • Implement controls to support secure AI adoption, including data protection and access governance; ensure secure configuration and usage of SaaS platforms.
  • Collaborate with Business Strategy & Analytics, Baseball R&D and IT Operations to ensure security is embedded in new solutions.

Projects, Change & Budget

  • Develop and execute cybersecurity projects to completion, discuss challenges and key decision points with IT Leadership.
  • Participate in and drive the organization’s change management process for all cybersecurity changes.
  • Participate in the planning, adherence, and analysis of the cybersecurity portion of the operational budget; recommend security investments.
  • Manage cybersecurity vendors; coordinate maintenance windows and resolve cybersecurity issues.

Collaboration, Guidance & Reporting

  • Generate and publish metrics, reports, and dashboards for IT Leadership.
  • Provide guidance, training, and escalation support to the IT Operations team.
  • Collaborate with internal departments, vendors, and external partners.

Event & On-Call Support

  • Provide on-site Event and remote On-Call support on a shared rotation.

Governance, Documentation & Standards

  • Develop and maintain documentation including SOPs, installation methodologies, project plans, and environment configurations.
  • Adhere to all company and departmental policies, procedures, and operating standards.
  • Other duties as assigned.

Compensation:

The projected annual salary range for this position is $100,000 - $120,000 per year. Actual pay is based on several factors, including but not limited to the applicant’s qualifications, skills, expertise, education/training, certifications, and other organization requirements. Starting salaries for new employees are frequently not at the top of the applicable salary range.

Benefits:

The Nationals offer a competitive and comprehensive benefits package that presently includes:

  • Paid vacation and sick leave, paid holidays throughout the year and a holiday break in December
  • Medical, dental, vision, life and AD&D insurance
  • Short- and long-term disability insurance
  • Flexible spending accounts
  • 401(k) and pension plan
  • Access to complimentary tickets to Nationals home games
  • Employee discounts
  • Free onsite fitness center

Equal Opportunity Employer:

The Nationals are dedicated to offering equal employment and advancement opportunities to all individuals regardless of their race, color, religion, national origin, sex, age, marital status, personal appearance, sexual orientation, gender identity or expression, family responsibilities, matriculation, political affiliation, genetic information, disability, or any other protected characteristic under applicable law.