1

Offensive Security Engineer Jobs in Washington, DC

... on offensive security, penetration testing, or vulnerability research * Prior experience performing security testing and assessment in IoT, embedded, or firmware based environments * Working ...

Senior Security Engineer

Mclean, VA · On-site

$115K - $158K/yr

Deep hands-on experience with offensive security: red teaming, penetration testing, or ... engineering teams * Bachelor's degree in Computer Science, Cybersecurity, or a related field, or ...

Senior Security Engineer

Columbia, MD · On-site

$131K - $237K/yr

Offensive security background -- penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

Senior Security Engineer

Reston, VA · On-site

$131K - $237K/yr

Offensive security background -- penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

Senior Security Engineer

Herndon, VA · On-site

$131K - $237K/yr

Offensive security background -- penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

Senior Security Engineer

Chantilly, VA · On-site

$131K - $237K/yr

Offensive security background -- penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

Senior Security Engineer

Chantilly, VA · On-site

$131K - $237K/yr

Offensive security background - penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

Showing results 41-60

Offensive Security Engineer information

See Washington, DC salary details

$69.4K

$172.4K

$231.9K

How much do offensive security engineer jobs pay per year?

As of Sep 2, 2026, the average yearly pay for offensive security engineer in Washington, DC is $172,381.00, according to ZipRecruiter salary data. Most workers in this role earn between $161,400.00 and $178,800.00 per year, depending on experience, location, and employer.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for identifying and exploiting vulnerabilities in systems, networks, and applications to assess an organization's security posture. They conduct penetration testing, simulate real-world cyber attacks, and provide recommendations to strengthen defenses. Their work helps organizations proactively detect and mitigate security risks before malicious hackers can exploit them. They often use tools like Metasploit, Burp Suite, and custom scripts to test security controls.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

Offensive Security Engineers need expertise in penetration testing, vulnerability assessment, networking, programming, and a solid understanding of security best practices, typically supported by a computer science degree or equivalent experience. Familiarity with tools like Metasploit, Burp Suite, Kali Linux, and certifications such as OSCP or CEH is highly valued. Strong problem-solving ability, effective communication, and a collaborative mindset help professionals excel in this dynamic field. These skills ensure the engineer can identify and exploit security weaknesses while clearly conveying findings to both technical teams and stakeholders, ultimately strengthening organizational security.

What are some common challenges faced by offensive security engineers on the job?

Offensive Security Engineers often encounter challenges such as keeping up with rapidly evolving threats, maintaining deep technical knowledge across various technologies, and identifying vulnerabilities in large or complex systems. They must balance rigorous testing with minimal disruption to live systems, which requires careful planning and coordination with other teams. Additionally, translating technical findings into actionable recommendations that are understandable to both technical and non-technical stakeholders is a key part of the role. These challenges make adaptability, continuous learning, and strong communication skills especially important in this field.

What are the most commonly searched types of Offensive Security Engineer jobs in Washington, DC?

The most popular types of Offensive Security Engineer jobs in Washington, DC are:

What are popular job titles related to Offensive Security Engineer jobs in Washington, DC?

For Offensive Security Engineer jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching Offensive Security Engineer jobs in Washington, DC look for?

The top searched job categories for Offensive Security Engineer jobs in Washington, DC are:

Infographic showing various Offensive Security Engineer job openings in Washington, DC as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, and 3% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $172,381 per year, or $82.9 per hour.

Web Developer Security Engineer (SMA 4)

E Logic

Washington, DC • On-site

Full-time

Posted 25 days ago


Job description

Job Description:

We are looking for a highly skilled and proactive Web Developer Security Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a Web Developer Security Engineer, you will play a pivotal role in protecting mission-critical web applications, APIs, and sensitive data. You will embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar. You will identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations, and drive the end-to-end vulnerability lifecycle.

Key Responsibilities:

  • Web Application Security: Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
  • Vulnerability Lifecycle: Drive the end-to-end vulnerability lifecycle--integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation.
  • Secure Design: Support integration of security controls into application architectures, APIs, and supporting services; advise on secure design patterns, data protection mechanisms, and secure communication protocols.
  • Monitoring & Incident Response: Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise; support the end-to-end response to web application security events.
  • Automation: Implement automation scripts for threat intelligence integration to optimize alert accuracy; leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js) to automate security monitoring and compliance audits.
  • Compliance: Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and security authorization processes.

Required Qualifications:

  • Certifications: Must hold at least one certification from each of the following three categories:
  • Specialized AppSec: CSSLP, GWEB, or CASE
  • Offensive Security: OSWE or OSCP
  • Foundational Security: Security+ or GSEC
  • Certifications must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
  • Clearance: Must be eligible to obtain and maintain a Public Trust Tier 2 clearance (background check conducted through U.S. Capitol Police).
  • Experience: Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
  • Technical Proficiency: Demonstrated hands-on experience with:
  • Modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
  • AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex)
  • Scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript)
  • Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions
  • Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
  • Security Knowledge: Strong understanding of OWASP Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.

Desired Experience:

  • Bachelor's degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
  • In-depth experience with federal cybersecurity frameworks (NIST SP 800-53, FISMA, FedRAMP) authorization processes.
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture.
  • Experience implementing secure DevOps/DevSecOps practices, specifically CI/CD pipeline and automating security gates.
  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).

Clearance Requirement: Must be eligible for a Public Trust Tier 2

Citizenship: U.S. Citizenship or Permanent Residence Status is required

Job Type: Full-time


Equal Opportunity Employer Statement

E-Logic, Inc. is an equal opportunity employer and is committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.