1

Offensive Security Engineer Jobs in Houston, TX (NOW HIRING)

Responsibilities and Impact We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing and offensive security. The ideal candidate will conduct penetration tests ...

We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...

We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing ... This role requires strong offensive security skills combined with cloud and application ...

Senior Cybersecurity Advisor

Houston, TX · Hybrid

$106K - $143K/yr

Bachelor's degree in Engineering, Computer Science, Information Security, or a technical ... offensive security, penetration testing, red & purple teaming * Strong interpersonal skills ...

Senior Cybersecurity Advisor

Houston, TX · On-site

$130K - $130K/yr

Bachelor's degree in Engineering, Computer Science, Information Security, or a technical ... offensive security, penetration testing, red & purple teaming * Strong interpersonal skills ...

INTELLIGENCE SPECIALIST

Houston, TX · On-site

$89K - $113K/yr

... security, taking your passion for science and engineering to the next level. CRYPTOLOGIC TECHNICIAN NETWORKS Use state-of-the-art technology to perform offensive and defensive cyber operations ...

INTELLIGENCE SPECIALIST

The Woodlands, TX · On-site

$86K - $108K/yr

... security, taking your passion for science and engineering to the next level. CRYPTOLOGIC TECHNICIAN NETWORKS Use state-of-the-art technology to perform offensive and defensive cyber operations ...

Offensive Security Engineer information

See Houston, TX salary details

$58.7K

$145.9K

$196.2K

How much do offensive security engineer jobs pay per year?

As of Aug 21, 2026, the average yearly pay for offensive security engineer in Houston, TX is $145,894.00, according to ZipRecruiter salary data. Most workers in this role earn between $136,600.00 and $151,400.00 per year, depending on experience, location, and employer.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for identifying and exploiting vulnerabilities in systems, networks, and applications to assess an organization's security posture. They conduct penetration testing, simulate real-world cyber attacks, and provide recommendations to strengthen defenses. Their work helps organizations proactively detect and mitigate security risks before malicious hackers can exploit them. They often use tools like Metasploit, Burp Suite, and custom scripts to test security controls.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

Offensive Security Engineers need expertise in penetration testing, vulnerability assessment, networking, programming, and a solid understanding of security best practices, typically supported by a computer science degree or equivalent experience. Familiarity with tools like Metasploit, Burp Suite, Kali Linux, and certifications such as OSCP or CEH is highly valued. Strong problem-solving ability, effective communication, and a collaborative mindset help professionals excel in this dynamic field. These skills ensure the engineer can identify and exploit security weaknesses while clearly conveying findings to both technical teams and stakeholders, ultimately strengthening organizational security.

What are some common challenges faced by offensive security engineers on the job?

Offensive Security Engineers often encounter challenges such as keeping up with rapidly evolving threats, maintaining deep technical knowledge across various technologies, and identifying vulnerabilities in large or complex systems. They must balance rigorous testing with minimal disruption to live systems, which requires careful planning and coordination with other teams. Additionally, translating technical findings into actionable recommendations that are understandable to both technical and non-technical stakeholders is a key part of the role. These challenges make adaptability, continuous learning, and strong communication skills especially important in this field.

What are the most commonly searched types of Offensive Security Engineer jobs in Houston, TX?

The most popular types of Offensive Security Engineer jobs in Houston, TX are:

What are popular job titles related to Offensive Security Engineer jobs in Houston, TX?

For Offensive Security Engineer jobs in Houston, TX, the most frequently searched job titles are:

What job categories do people searching Offensive Security Engineer jobs in Houston, TX look for?

The top searched job categories for Offensive Security Engineer jobs in Houston, TX are:

What cities near Houston, TX are hiring for Offensive Security Engineer jobs?

Cities near Houston, TX with the most Offensive Security Engineer job openings:

Infographic showing various Offensive Security Engineer job openings in Houston, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $145,894 per year, or $70.1 per hour.

Lead Penetration Test Engineer

S&P Global

Houston, TX • On-site

$135 - $200/hr

Other

This job post has expired 1 day ago. Applications are no longer accepted.


S&P Global rating

7.3

Company rating: 7.3 out of 10

Based on 10 frontline employees who took The Breakroom Quiz


Job description

Lead Penetration Test Engineer

Location: Hybrid 2 days per week onsite on one of the following sites:

  • US: Boston, MA; Chicago, IL; Dallas, TX; Houston, TX; Englewood, CO; Raleigh, NC; Princeton, NJ; New York, NY; Southfield, MI; Washington, DC.
  • Canada: Toronto, ON; Calgary, AB.
About the Role

The S&P Global Corporate team focuses on protecting our clients and users from modern security threats. Our mission is to safeguard systems and data by developing innovative solutions to the industry’s most complex security challenges.

Responsibilities and Impact

We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing and offensive security. The ideal candidate will conduct penetration tests, re‑testing, vulnerability scanning, and threat assessments across diverse environments.

Penetration Testing & Vulnerability Assessments
  • Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
  • Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.
  • Apply cloud‑specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing.
Vulnerability Management & Remediation
  • Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security across development and production lifecycles.
  • Perform detailed security assessments using DAST, SAST, and SCA tools to ensure continuous validation and improvement of security controls.
Attack Simulations & Research
  • Lead and participate in attack simulations and tabletop exercises to validate security controls and improve organizational response capabilities.
  • Research emerging threats, attack vectors, and adversarial techniques to inform offensive and defensive strategies.
  • Partner with internal teams to design and execute threat assessments based on intelligence feeds and threat actor analysis.
Security Communication & Reporting
  • Communicate and present penetration testing and security assessment findings to both technical and non‑technical stakeholders.
  • Provide actionable remediation guidance and risk mitigation strategies to strengthen the organization’s overall security posture.
What We’re Looking For Basic Required Qualifications
  • Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.
  • Minimum 8 years of experience in information security with a strong focus on penetration testing, application security, and vulnerability management.
  • Hands‑on experience with penetration testing tools (e.g., Burp Suite, Nessus, Metasploit, Nmap) and methodologies (e.g., OWASP Top 10, MITRE ATT&CK, PTES).
  • Expertise in identifying and exploiting common infrastructure and web application vulnerabilities (e.g., XSS, SQL Injection, IDOR).
  • Familiarity with vulnerability classification and scoring frameworks (CVE, CVSS, CWE).
  • Strong scripting or programming skills (e.g., Bash, Python, Go, PowerShell, JavaScript).
  • Experience performing security assessments (DAST, SAST, SCA, credential scanning) and integrating security testing into CI/CD pipelines.
  • Ability to translate complex technical findings into clear, actionable reports and confidently brief cross‑functional teams and executives.
  • At least one recognized offensive security certification (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).
Preferred Qualifications
  • Experience with cloud security across AWS, Azure, or GCP.
  • Knowledge of AI/ML security and adversarial testing methods, including evaluating LLMs and other models for manipulation, evasion, and data integrity risks.
  • Demonstrated involvement in the infosec community (e.g., open‑source projects, bug bounties, CVE research, conference talks, or security publications).
  • Experience applying the MITRE ATT&CK Framework to offensive security operations and threat emulation.
  • Familiarity with secure software development practices and the software development lifecycle.
  • Experience with Java application technologies, deployment frameworks, and associated security best practices.
  • Ability to work collaboratively across teams while independently owning deliverables and maintaining accountability to deadlines.
Right to Work Requirements for US‑Based Candidates

This role is open only for candidates with indefinite right to work within the United States.

Compensation / Benefits Information (US Applicants Only)

Anticipated base salary range: $135,000 USD – $200,000 USD. Final base salary will be based on the individual’s geographical location as well as experience and qualifications for the role.

Additional benefits are available. For more information on S&P Global benefits, visit https://spgbenefits.com/benefit-summaries/us.

Right to Work Requirements for Canada‑Based Candidates

This role is open for candidates with indefinite right to work within Canada.

Compensation / Benefits Information (Canadian Applicants)

Anticipated compensation range: 135,000 CAD – 180,000 CAD. Final compensation will be based on performance, geographic location, and experience level, skill set, training, licenses, and certifications.

S&P Global will not use artificial intelligence in the hiring process. Candidates will be informed of hiring decisions within 45 days of their interview. This posting is for an existing vacancy.

Equal Opportunity Employer

S&P Global is an equal‑opportunity employer and all qualified candidates will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, or other legally protected status. Only electronic submissions will be considered for employment.

If you need an accommodation during the application process due to a disability, please send an email to EEO.Compliance@spglobal.com. Your request will be forwarded to the appropriate person.

#J-18808-Ljbffr

What S&P Global employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom