1

Offensive Security Intern Jobs (NOW HIRING)

$150 - $200/hr

From intern to CEO, we celebrate diversity and bring a wide array of experience from technology ... You have an offensive security mindset: you don't just navigate a web app; you actively map its ...

Current Top Secret/Specialized Compartmented Information Security Clearance and the ability to ... Offensive and Defensive space control; Information Operations (IO) that support or require the ...

Space Operations Integrator

Eglin, FL · On-site

$14 - $18.25/hr

Current Top Secret/Specialized Compartmented Information Security Clearance and the ability to ... Offensive and Defensive space control; Information Operations (IO) that support or require the ...

Shadow at TV Family Med

Oakland, CA · On-site

$17.25 - $22.50/hr

Refrain from wearing clothing that may be deemed offensive or inappropriate, such as: * Shorts ... To ensure the confidentiality and security of this information, please follow these guidelines:

Showing results 41-47

Offensive Security Intern information

See salary details

$11

$20

$26

How much do offensive security intern jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for offensive security intern in the United States is $20.34, according to ZipRecruiter salary data. Most workers in this role earn between $16.11 and $22.36 per hour, depending on experience, location, and employer.

What does an offensive security intern do?

An Offensive Security Intern assists with identifying and exploiting security vulnerabilities in computer systems and networks to help organizations strengthen their defenses. Typical tasks include participating in penetration testing, conducting vulnerability assessments, and creating reports on findings. Interns work closely with experienced security professionals to learn ethical hacking techniques and tools while ensuring all activities comply with legal and ethical guidelines. This role is ideal for those looking to start a career in cybersecurity and gain hands-on experience in offensive security practices.

What types of projects and tasks can an offensive security intern expect to work on during their internship?

As an Offensive Security Intern, you can expect to be involved in a variety of hands-on projects, such as assisting with penetration testing, vulnerability assessments, and security research. You'll likely work closely with experienced security analysts and engineers, learning to identify and exploit security weaknesses in networks, applications, and systems. Interns often participate in drafting reports, developing proof-of-concept exploits, and helping to create remediation recommendations. Collaboration with other cybersecurity teams is common, providing a valuable opportunity to build technical and communication skills while working on real-world security challenges.

What are the key skills and qualifications needed to thrive as an offensive security intern, and why are they important?

To thrive as an Offensive Security Intern, you need a solid understanding of networking, operating systems, and cybersecurity concepts, often supported by relevant coursework or certifications like CompTIA Security+ or OSCP. Familiarity with penetration testing tools such as Metasploit, Burp Suite, and Kali Linux is typically expected. Attention to detail, critical thinking, and strong problem-solving abilities help you excel in identifying and reporting vulnerabilities. These skills and qualities are essential for effectively simulating attacks, learning from real-world scenarios, and supporting organizational security efforts.

What is the difference between Offensive Security Intern vs Penetration Tester?

AspectOffensive Security InternPenetration Tester
CertificationsBasic security certifications (e.g., OSCP, CompTIA Security+)Advanced certifications (e.g., OSCP, CEH, GPEN)
Work EnvironmentInternship, learning-focused, entry-levelProfessional, client-facing, project-based
ResponsibilitiesAssisting in security assessments, learning tools and techniquesConducting security tests, identifying vulnerabilities, reporting
Experience LevelEntry-level, gaining practical skillsMid-level to senior, with hands-on experience

The Offensive Security Intern role is an entry-level position focused on learning and supporting security assessments, often requiring basic certifications. In contrast, a Penetration Tester is a professional role involving independent security testing, requiring more advanced skills and certifications. Interns gain foundational knowledge, while Penetration Testers perform comprehensive security evaluations for clients.

What cities are hiring for Offensive Security Intern jobs?

Cities with the most Offensive Security Intern job openings:

What states have the most Offensive Security Intern jobs?

States with the most job openings for Offensive Security Intern jobs include:

What are popular job titles related to Offensive Security Intern jobs?

For Offensive Security Intern jobs, the most frequently searched job titles are:

Infographic showing various Offensive Security Intern job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $42,304 per year, or $20.3 per hour.

Senior Software Engineer, Browser Automation

On-site

Horizon3 AI, Inc.
Network Security • 51 - 200 employees

$150 - $200/hr

Other

Medical, Dental, Vision, PTO

Posted 10 days ago


Job description

At Horizon3, we’re building a team of bold thinkers, problem solvers, and Learn-it-Alls.
We’re looking for individuals who:

Love solving tough problems, especially the ones no one else has cracked.

Thrive in high-performing teams that celebrate success and lift each other up.

Have the grit and tenacity to take on complex, mission-critical challenges.

Want to make a real impact by helping organizations stay ahead of attackers.

Continuously learn and adapt, embracing new technologies, perspectives, and ideas.

Are passionate about disruption, driving innovation in the cybersecurity space.

If you’re eager to grow, driven to contribute, and ready to shape the future of cybersecurity, we want to hear from you.

The Perks of working with Horizon3

Our Culture

We’re a team of learn-it-alls who love building awesome products. From intern to CEO, we celebrate diversity and bring a wide array of experience from technology startups, Fortune 500s, and the US Military.

Remote Work Options

With offices in San Francisco, Chicago, and Amsterdam, we have hybrid and remote positions available globally.

Build Something Meaningful

We’re motivated to create a safer, more secure environment, convert new ideas to exceptional solutions and deliver great customer experiences.

Be part of a passionate and talented team which have entrepreneurial spirit, because it makes a huge difference.

Think Long Term

You’ll have complete ownership and responsibility along with huge potential for growth. We envision the future and build it one step at a time.

Competitive pay, great health & dental care for you and your loved ones, and a 4 weeks + generous holidays and vacation packages globally.

Positions

We’re a remote-first company with teammates clustered around the globe.

Location

US, Remote

Employment Type

Full time

Location Type

Remote

Department

Get to Know Us

Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZero platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.

We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox" security culture, the cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn-it-alls, committed to a culture of respect, collaboration, ownership, and results.

Summary

Essential Functions

Tackle the gnarly realities of modern web apps: SPA routing and hydration timing, authenticated sessions, multi-step flows, file uploads, WebSocket/Socket.IO traffic, infinite scroll, and crawler traps.

Extend our agentic login and authentication capabilities, including complex auth flows, MFA/TOTP, and credentialed access reliable enough to run unattended against customer environments.

Improve crawl coverage, determinism, and throughput. This involves endpoint and parameter discovery, dedupe, queueing, and state management, while keeping everything production-safe and side-effect-aware.

Help draw the line between deterministic automation and LLM-driven navigation, applying models surgically rather than as a default, and keeping the system fast, debuggable, and cheap to run.

Collaborate with the attack-team engineers who consume your crawl output, and help shape the graph-backed application map the rest of the pipeline depends on.

A bias toward determinism and debuggability, and the judgment to reach for an LLM only when a deterministic approach genuinely can't do the job.

Ownership mentality: you are comfortable taking a critical subsystem from "works" to "works unattended, at scale, against someone else's production environment."

Desired/Nice to Have

Background in web application security or offensive tooling — familiarity with broken access control, IDOR/BOLA, SQLi, XSS, SSRF, or SSTI in the wild.

Familiarity with graph data models (e.g., Neo4j) for representing application structure.

Experience with large-scale crawling, endpoint discovery (e.g., parsing/analyzing client-side JS), or session/credential management for automated access.

Comfort working in an environment where correctness against a live customer system is a hard, non-negotiable constraint.

What makes you stand out:

You’ve gone beyond using tools like Playwright or Puppeteer to actually hacking on their internals or contributing to the core.

You’ve successfully outmaneuvered sophisticated WAFs, anti-bot defenses, and fingerprinting mechanisms in production environments.

You have an offensive security mindset: you don’t just navigate a web app; you actively map its attack surface and hunt for unreachable paths.

You have battle-tested experience with LLMs in production. You understand the engineering trade-offs: knowing when AI is an asset and when it introduces unacceptable latency or nondeterminism compared to a deterministic script.

Perks of Horizon3

Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.

Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.

Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.

Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.

Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.

Compensation and Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

In accordance with various State’s transparency regulations, we provide the following salary range information for this position:

Base salary range: $169,000 - $208,000 annually. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills.

Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.

You Belong Here

Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, hair length or any other legally protected status by law.

Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.

We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.

#J-18808-Ljbffr