1

Offensive Security Engineer Jobs in Virginia (NOW HIRING)

Overview We are seeking an experienced Senior Penetration Tester / Offensive Security Engineer to conduct hands-on security assessments, identify vulnerabilities, evaluate enterprise architectures ...

Senior Networking Security Analyst

Fort Belvoir, VA · On-site

$113K - $145K/yr

Offensive Security Exploitation Expert - Exploit development and reverse engineering at the highest level. * GXPN: GIAC Exploit Researcher & Advanced Penetration Tester - Advanced exploitation and ...

Showing results 41-60

Offensive Security Engineer information

See Virginia salary details

$61K

$151.5K

$203.7K

How much do offensive security engineer jobs pay per year?

As of Sep 4, 2026, the average yearly pay for offensive security engineer in Virginia is $151,463.00, according to ZipRecruiter salary data. Most workers in this role earn between $141,800.00 and $157,100.00 per year, depending on experience, location, and employer.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for identifying and exploiting vulnerabilities in systems, networks, and applications to assess an organization's security posture. They conduct penetration testing, simulate real-world cyber attacks, and provide recommendations to strengthen defenses. Their work helps organizations proactively detect and mitigate security risks before malicious hackers can exploit them. They often use tools like Metasploit, Burp Suite, and custom scripts to test security controls.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

Offensive Security Engineers need expertise in penetration testing, vulnerability assessment, networking, programming, and a solid understanding of security best practices, typically supported by a computer science degree or equivalent experience. Familiarity with tools like Metasploit, Burp Suite, Kali Linux, and certifications such as OSCP or CEH is highly valued. Strong problem-solving ability, effective communication, and a collaborative mindset help professionals excel in this dynamic field. These skills ensure the engineer can identify and exploit security weaknesses while clearly conveying findings to both technical teams and stakeholders, ultimately strengthening organizational security.

What are some common challenges faced by offensive security engineers on the job?

Offensive Security Engineers often encounter challenges such as keeping up with rapidly evolving threats, maintaining deep technical knowledge across various technologies, and identifying vulnerabilities in large or complex systems. They must balance rigorous testing with minimal disruption to live systems, which requires careful planning and coordination with other teams. Additionally, translating technical findings into actionable recommendations that are understandable to both technical and non-technical stakeholders is a key part of the role. These challenges make adaptability, continuous learning, and strong communication skills especially important in this field.

What are the most commonly searched types of Offensive Security Engineer jobs in Virginia?

The most popular types of Offensive Security Engineer jobs in Virginia are:

What are popular job titles related to Offensive Security Engineer jobs in Virginia?

For Offensive Security Engineer jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Offensive Security Engineer jobs in Virginia look for?

The top searched job categories for Offensive Security Engineer jobs in Virginia are:

What cities in Virginia are hiring for Offensive Security Engineer jobs?

Cities in Virginia with the most Offensive Security Engineer job openings:

Infographic showing various Offensive Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $151,463 per year, or $72.8 per hour.

Security Engineer (Offensive) - Red Team Adversary Emulation Tech Lead

Resource Management Concepts, Inc.

Quantico, VA • On-site

Full-time

Medical, Retirement, PTO

Posted yesterday

New


Job description

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.
We are seeking a highly skilled Red Team Adversary Emulation Tech Lead supporting Red Team Persistent Cyberspace Operations (PCO) to join one of only eleven Department of War (DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United States Cyber Command (USCYBERCOM). This team is based out of Quantico, VA. This is a unique opportunity to work on advanced cyber operations, contributing directly to national security. You will be part of an elite team, leveraging state-of-the-art tools and methodologies to stay ahead of adversaries.
The Red Team conducts full-spectrum offensive operations to assess and improve the security posture of enterprise and mission-critical environments. This includes both no-notice adversarial assessments and cooperative exercises with blue teams and system owners. Team members emulate advanced threat actors, identify vulnerabilities, and help stakeholders strengthen detection and response capabilities.
Requirements
Responsibilities
• Primary role will be to plan and conduct Red Team Persistent Cyberspace Operations (PCO) Adversary Emulation as a Tech Lead in this specific Red Team capability area. This includes conducting long-term persistence emulating an intel-driven Advanced Persistent Threat (APT).
• This position may likely include supporting and conducting other roles within the Red Team, to include:
  • Both Operational Technology (OT) and Information Technology (IT) vulnerability assessments
  • Acquisition Penetration Testing (APT) via Adversarial Assessments of DoW systems
  • Support exercise objectives and training goals as an Opposing Force Aggressor (OFA)
  • Assist in the instruction of the customer's Red Team Operations Course (RTOC)

• Plan and execute no-notice and cooperative Red Team operations across enterprise, application, and cloud environments.
• Identify and exploit network, host, and application-level vulnerabilities.
• Develop and refine proof-of-concept exploits and techniques to test defensive measures.
• Produce detailed technical findings and recommendations for remediation.
• Collaborate with defensive and engineering teams to improve detection and response.
• Continuously evolve team tactics, techniques, and procedures (TTPs), documentation, and training materials to reflect emerging adversary behaviors.
• Participate in after-action reviews and contribute to policy and playbook updates.
• Prepare, update, document, and present course materials that cover TTPs.
• Provide support required to maintain the customer's Cybersecurity Service Provider (CSSP) accreditation per the standards, including documentation and technical writing support as needed.
• Schedule: Mon-Fri onsite at Quantico, VA. May likely include some travel.
Minimum Qualifications
• TS/SCI eligibility
• 5 years of relevant cybersecurity experience (e.g., Red Team, penetration testing, vulnerability research, security engineering, incident response, detection engineering, etc.).
• Possess and maintain a DoD 8570 IAT Level III certification: SecurityX (CASP+), CISSP, CCNP Security, CISA, GCED, GCIH, CCSP.
• Possess and maintain a DoD 8570 CSSP Auditor certification: CySA+, CEH, CISA, GSNA, CFR, PenTest.
• Possess and maintain one of the following certifications to meet DoD 8140 DCWF 541 Vulnerability Assessment Analyst certification requirements: CySA+, SecurityX (CASP+), CISM, CISA, CISSP, CFR, GPEN, GSNA.
• Understanding of Windows and Linux systems, networking fundamentals, and enterprise services (e.g., Active Directory).
• Once placed in this role, candidates must pass the customer's Red Team Operations Course (RTOC) at the Red Team Certified Professional (RTCP) level upon the first attempt of the RTOC. Depending on timing and schedule of this course, course availability may or may not be immediate after starting the position.
Preferred Qualifications
• Experience with any of the following:
  • AV/EDR evasion and detection-bypass techniques.
  • Custom tooling, payload or, command-and-control (C2) development.
  • Software development in C, C++, or a similar language.
  • Malware analysis and reverse engineering.
  • Cloud platforms and services (AWS, Azure, GCP).
  • Physical security assessments or red-team intrusion exercises.
  • Industrial control systems (ICS), Internet of Things (IoT) environments, and Facility-Related Control Systems (FRCS).

• Offensive-security certifications such as OSCP, OSEP, OSCE, CRTO. CRTL, GXPN.
Benefits
At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.
RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.
Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $150,000 to $175,000 (annually).
#LI-LL1