Offensive Security Analyst II at JM Family Enterprises is responsible for designing, building, and scaling offensive security capabilities through adversary-focused testing, attack simulation, and ...
Offensive Security Analyst II at JM Family Enterprises is responsible for designing, building, and scaling offensive security capabilities through adversary-focused testing, attack simulation, and ...
Information Security - Offensive Security Analyst
Deerfield Beach, FL · On-site
$100K - $110K/yr
Information Security - Offensive Security Analyst Location: Deerfield Beach, FL (Hybrid 3/2) Duration: Direct Hire Compensation: $100,000 - $110,000 Work Requirements: US Citizen, GC Holders or ...
Information Security - Offensive Security Analyst
Deerfield Beach, FL · On-site
$100K - $110K/yr
Information Security - Offensive Security Analyst Location: Deerfield Beach, FL (Hybrid 3/2) Duration: Direct Hire Compensation: $100,000 - $110,000 Work Requirements: US Citizen, GC Holders or ...
As an Offensive Security Engineer, you will report to the Sr. Director Engineering, Application Security & Red Teaming and work with our Red Teaming and Application Security group. You will help us ...
As an Offensive Security Engineer, you will report to the Sr. Director Engineering, Application Security & Red Teaming and work with our Red Teaming and Application Security group. You will help us ...
They are seeking a Security Engineer to join their Offensive Security team, responsible for advanced vulnerability management and penetration testing services while ensuring client satisfaction and ...
They are seeking a Security Engineer to join their Offensive Security team, responsible for advanced vulnerability management and penetration testing services while ensuring client satisfaction and ...
Senior Offensive Security Engineer - Pentester
Jacksonville, FL · On-site
$106K - $145K/yr
They are seeking a Senior Offensive Security Engineer to identify and assess high-risk vulnerabilities across their global technology environment, focusing on penetration testing and security ...
Senior Offensive Security Engineer - Pentester
Jacksonville, FL · On-site
$106K - $145K/yr
They are seeking a Senior Offensive Security Engineer to identify and assess high-risk vulnerabilities across their global technology environment, focusing on penetration testing and security ...
Security Engineer, Offensive Security
Tampa, FL · On-site
$90 - $150/hr
Position Overview Thrive is looking for a security engineer to join our Offensive Security team. This team focuses on advanced vulnerability management and Pentesting as a service and delivers ...
New
Security Engineer, Offensive Security
Tampa, FL · On-site
$90 - $150/hr
Position Overview Thrive is looking for a security engineer to join our Offensive Security team. This team focuses on advanced vulnerability management and Pentesting as a service and delivers ...
New
Information Security Operations Analyst II
Deerfield Beach, FL · On-site
$100K - $110K/yr
Conduct offensive security activities including penetration testing, attack simulations, threat based assessments, and control validation across on prem, cloud, identity, and SaaS environments.
Information Security Operations Analyst II
Deerfield Beach, FL · On-site
$100K - $110K/yr
Conduct offensive security activities including penetration testing, attack simulations, threat based assessments, and control validation across on prem, cloud, identity, and SaaS environments.
Senior Penetration Tester
Tampa, FL · On-site
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
Senior Penetration Tester
Tampa, FL · On-site
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
Senior Penetration Tester
Tampa, FL · On-site
$152K - $260K/yr
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
Senior Penetration Tester
Tampa, FL · On-site
$152K - $260K/yr
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
Senior Penetration Tester
$152K - $260K/yr
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
Senior Penetration Tester
$152K - $260K/yr
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...
This role requires deep offensive security expertise across cloud, identity, network, and endpoint layers, using advanced tradecraft to uncover gaps and convert findings into actionable risk ...
This role requires deep offensive security expertise across cloud, identity, network, and endpoint layers, using advanced tradecraft to uncover gaps and convert findings into actionable risk ...
This role requires deep offensive security expertise across cloud, identity, network, and endpoint layers, using advanced tradecraft to uncover gaps and convert findings into actionable risk ...
New
This role requires deep offensive security expertise across cloud, identity, network, and endpoint layers, using advanced tradecraft to uncover gaps and convert findings into actionable risk ...
New
Principal InfoSec Engineer Application Security
Tampa, FL · On-site
$160K - $200K/yr
For instance, bring in Offensive Security specialists for targeted ethical hacking activities and integrate their findings into the overall advisory for projects in the PMI U.S. business unit. Also ...
Principal InfoSec Engineer Application Security
Tampa, FL · On-site
$160K - $200K/yr
For instance, bring in Offensive Security specialists for targeted ethical hacking activities and integrate their findings into the overall advisory for projects in the PMI U.S. business unit. Also ...
The ideal candidate combines hands-on offensive security experience with strong knowledge of secure development practices and common web application attack vectors. Work you'll do As a Penetration ...
The ideal candidate combines hands-on offensive security experience with strong knowledge of secure development practices and common web application attack vectors. Work you'll do As a Penetration ...
Supporting offensive security/red team/adversarial emulation testing * Executing Red Team engagements in a variety of networks using real-world adversarial Tactics, Techniques, and Procedures (TTPs ...
Supporting offensive security/red team/adversarial emulation testing * Executing Red Team engagements in a variety of networks using real-world adversarial Tactics, Techniques, and Procedures (TTPs ...
Responsibilities : • Supporting offensive security/red team/adversarial emulation testing • Executing Red Team engagements in a variety of networks using real-world adversarial Tactics ...
Responsibilities : • Supporting offensive security/red team/adversarial emulation testing • Executing Red Team engagements in a variety of networks using real-world adversarial Tactics ...
Validate whether prioritized exposures are exploitable and reachable using attack-path analysis, breach-and-attack simulation, and offensive security and penetration testing findings. * Assess ...
Validate whether prioritized exposures are exploitable and reachable using attack-path analysis, breach-and-attack simulation, and offensive security and penetration testing findings. * Assess ...
Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Cloud Security Professional (CCSP), AWS Certified Security Specialty, Azure Security Engineer Associate ...
New
Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Cloud Security Professional (CCSP), AWS Certified Security Specialty, Azure Security Engineer Associate ...
New
Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Cloud Security Professional (CCSP), AWS Certified Security Specialty, Azure Security Engineer Associate ...
New
Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Cloud Security Professional (CCSP), AWS Certified Security Specialty, Azure Security Engineer Associate ...
New
Offensive Security information
See Florida salary details
$42.6K - $51.4K
1% of jobs
$51.4K - $60.1K
4% of jobs
$60.1K - $68.9K
5% of jobs
$68.9K - $77.7K
9% of jobs
$82.5K is the 25th percentile. Wages below this are outliers.
$77.7K - $86.4K
11% of jobs
$86.4K - $95.2K
10% of jobs
The median wage is $98.5K / yr.
$95.2K - $103.9K
28% of jobs
$109K is the 75th percentile. Wages above this are outliers.
$103.9K - $112.7K
14% of jobs
$112.7K - $121.5K
11% of jobs
$121.5K - $130.2K
4% of jobs
$130.2K - $139K
4% of jobs
$42.6K
$99.4K
$139K
How much do offensive security jobs pay per year?
What is offensive security?
An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.
How much do offensive security engineers make?
What does a typical day look like for someone working in offensive security?
A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.
What is the salary of offensive security?
What are the key skills and qualifications needed to thrive in offensive security, and why are they important?
To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

Full-time
Re-posted 15 days ago
JM Family Enterprises rating
9.1
Based on 15 frontline employees who took The Breakroom Quiz
3rd of 150 rated car dealerships
Job description
They will support transformation of offensive security program from a predominantly tool- and vendor-driven model to a build-first approach, leveraging software engineering, automation, and AI-assisted techniques to improve the coverage, depth, and repeatability of offensive security activities.
Responsibilities include but are not limited to:
- Conduct offensive security activities including penetration testing, attack simulations, threat-based assessments, and control validation across on-prem, cloud, identity, and SaaS environments.
- Execute and assist in the development of red team and purple team exercises, collaborating with detection and response teams to validate defensive coverage.
- Perform vulnerability and exploitation analysis, including chaining weaknesses to demonstrate real-world attack paths and business risk.
- Identify, validate, and responsibly disclose security weaknesses to stakeholders, providing clear remediation guidance and risk context.
- Design, develop, and maintain custom offensive security tooling (Python, PowerShell, Bash, or similar), including frameworks, reusable modules, and automation that scale testing beyond point-in-time assessments.
- Evaluate when to build versus buy offensive security capabilities, with a bias toward internal tooling where it improves flexibility, visibility, or speed of iteration.
- Incorporate AI-assisted techniques (e.g., automation, chaining analysis, signal prioritization) to increase testing efficiency and analyst leverage.
- Contribute documentation such as test reports, playbooks, findings templates, and executive-level summaries.
- Contribute to the long-term architecture of the offensive security program, including shared libraries, testing pipelines, data models, and reporting outputs optimized for reuse and scale.
- Mentor junior analysts and contribute to team knowledge sharing.
- Partner with application and platform engineering teams not only to test systems, but to co-design secure patterns, reference implementations, and reusable testing components.
- Build developer-consumable assets (templates, scripts, sample exploits, safe test harnesses) that enable teams to self-validate security assumptions earlier in the SDLC.
- Provide developer-friendly remediation guidance, proof-of-concepts, and secure coding recommendations that are actionable and aligned to real-world development workflows.
- Support the integration and tuning of security testing tools within CI/CD pipelines, balancing detection depth with developer experience and signal quality.
- Collaborate with Security Engineering and Application teams to improve self-service security capabilities, documentation, and testing patterns that developers can reuse.
- Participate in post-testing debriefs with developers to educate, coach, and improve security outcomes-not just report findings
Qualifications:
- Hands-on experience with penetration testing, red team, purple team, or adversary emulation activities.
- Strong understanding of Windows, Active Directory, Azure/Entra ID, networking, cloud platforms, and SaaS architectures.
- Experience with common offensive security tools and frameworks (e.g., C2 frameworks, vulnerability scanners, exploit frameworks).
- Knowledge of MITRE ATT&CK, kill chains, and attacker tradecraft.
- Experience validating security controls such as EDR, SIEM, identity protections, email security, and cloud security controls.
- Strong scripting and automation skills; ability to customize or build tools to support testing objectives.
- Ability to translate technical findings into clear risk-based narratives for technical and non-technical audiences.
- Strong analytical, problem-solving, and critical-thinking skills.
- Ability to work independently while collaborating effectively in cross-functional teams.
- High attention to detail with a strong sense of ethics and responsible disclosure.
- Experience working directly with software engineers to remediate vulnerabilities and improve secure development practices.
- Understanding of modern SDLC and CI/CD pipelines, including how security testing fits into developer workflows.
- Familiarity with secure coding practices and common vulnerability classes in modern applications (web, APIs, cloud-native services).
- Ability to communicate security findings in a way that developers can quickly understand, prioritize, and fix.
- Mindset oriented toward enablement over enforcement, with a focus on reducing friction while improving security outcomes.
- Background in software engineering, platform engineering, or SRE, with a desire to specialize in security.
- Experience designing or maintaining production-quality code, not just scripts.
- Comfort working with APIs, data pipelines, CI/CD systems, and cloud-native services as part of security capability development.
- Curiosity and practical interest in applying AI/ML-assisted techniques to security testing, automation, and analysis.
#LI-AM1
#LI-HYBRID
This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of JM Family. All work arrangements are subject to associate performance, business need and manager discretion, and may be revised as necessary.
JM FAMILY IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER
JM Family Enterprises, Inc. is an Equal Employment Opportunity employer. We are committed to recruiting, hiring, retaining, and promoting qualified associates without regard any characteristic protected by law - whether actual or perceived - including race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, related medical conditions and lactation), gender identity gender expression, sexual orientation, marital status, military service, veteran status, disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, provincial, or local law.
DISABILITY ACCOMMODATIONS
If you have a disability and require a reasonable accommodation to complete the job application process, please contact JM Family's Talent Acquisition department at talentacquisition@jmfamily.com for assistance. If you have an accommodation request for one of our recruiting events, please notify us at least 72 hours prior so that we may provide assistance.
What JM Family Enterprises employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About JM Family Enterprises
Sourced by ZipRecruiter
Industry
Motor vehicle manufacturing
Company size
5,001 - 10,000 Employees
Headquarters location
Deerfield Beach, FL, US
Year founded
1968