2

Offensive Security Engineer Remote Jobs in Springfield, VA

Web Developer Security Engineer

Washington, DC · On-site +1

$135K - $155K/yr

EC-Council Certified Application Security Engineer (CASE) * Offensive Security: * OffSec Web Expert ... Offensive Security Certified Professional (OSCP) * Foundational Security: * Security+ * GSEC ...

General information Job Posting Title Lead Security Engineer - Remote Date Wednesday, August 12, 2026 City Remote Country United States Working time Full-time Description & Requirements The Lead ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on ...

AI Red Teamer, Cyber

Washington, DC · Remote

$100K - $120K/yr

This role is ideal for someone who enjoys offensive security, creative problem-solving, and ... Collaborate with engineers, researchers, and subject-matter experts to improve system security

next page

Showing results 1-20

Offensive Security Engineer Remote information

See Springfield, VA salary details

$64.2K

$159.6K

$214.7K

How much do offensive security engineer remote jobs pay per year?

As of Sep 4, 2026, the average yearly pay for offensive security engineer remote in Springfield, VA is $159,576.00, according to ZipRecruiter salary data. Most workers in this role earn between $149,400.00 and $165,600.00 per year, depending on experience, location, and employer.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote offensive security engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are popular job titles related to Offensive Security Engineer Remote jobs in Springfield, VA?

For Offensive Security Engineer Remote jobs in Springfield, VA, the most frequently searched job titles are:

What cities near Springfield, VA are hiring for Offensive Security Engineer Remote jobs?

Cities near Springfield, VA with the most Offensive Security Engineer Remote job openings:

Infographic showing various Offensive Security Engineer Remote job openings in Springfield, VA as of August 2026, with employment types broken down into 74% Full Time, and 26% Contract. Highlights an 100% Remote job distribution, with an average salary of $159,576 per year, or $76.7 per hour.

Web Developer Security Engineer

Spry Methods

Washington, DC • On-site, Remote

$135K - $155K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 22 days ago


Key responsibilities

  • Identify, analyze, and remediate vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.

  • Drive the vulnerability lifecycle through threat modeling, security assessments, and validation of remediation actions.

  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.


Job description

Company Overview
Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments. 

Who We're Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   
What Your Day-To-Day Looks Like (Position Responsibilities):
  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs. 

  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions. 

  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services. 

  • Review and analyze web server and application logs to detect anomalies and indicators of compromise. 

  • Implement automation scripts for threat intelligence integration and application security monitoring. 

  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks. 

What You Need to Succeed (Minimum Requirements):
  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work. 

  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 

  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL). 

  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts. 

  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools. 

  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies. 

  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field. 

  • Ability to meet federal screening and suitability requirements prior to start. 

  • Current security certifications maintained for a minimum of five years: 

    • Specialized AppSec:
      • Certified Secure Software Lifecyle Professional (CSSLP)
      • GIAC Certified Web Application Defender (GWEB)
      • EC-Council Certified Application Security Engineer (CASE)
    • Offensive Security:
      • OffSec Web Expert (OSWE)
      • Offensive Security Certified Professional (OSCP)
    • Foundational Security:
      • Security+
      • GSEC
Ideally, You Also Have (Preferred Qualifications):
  • In-depth experience with federal cybersecurity frameworks and authorization processes. 

  • Experience with threat modeling, resilient security architecture, cloud security, and container security. 

$135,000 - $155,000 a year
Final compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.

Perks of Working for Us (Benefits):

Medical Coverage - Cigna - 4 Options

- Traditional - PPO Open Access Plus Network

- (2) HDHP - PPO Open Access Plus Network

- HDHP - EPO Open Access Plus Network

Dental Coverage - Cigna - PPO Base & Buy-Up Plans

Vision Coverage - Principal - VSP Choice Network

Paid Holidays: Full-time employees receive 11 paid federal holidays

Paid Time Off (PTO) - PTO accrual starts at 15 days per year

Training Benefit - Annual training allowance available toward any job-related training or education

401(k) - Multiple Fund Choices through Fidelity with a company match

For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/

 
EEO Statement
At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.
 
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job