1

Offensive Security Jobs in Kentucky (NOW HIRING)

$120 - $160/hr

Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and ...

$250 - $350/hr

Incident Response, Vulnerability Management and Exploits, Threat Intelligence and Operations, Governance, Risk and Compliance (GRC) and Privacy, and Offensive Security. You will set the strategy ...

$100 - $160/hr

Strong understanding of cybersecurity, ideally including offensive security, penetration testing, ASM, autonomous pentesting, or related technologies * Experience selling to CISOs and senior security ...

$180 - $280/hr

Incident Response, Vulnerability Management and Exploits, Threat Intelligence and Operations, Governance, Risk and Compliance (GRC) and Privacy, and Offensive Security. You will set the strategy ...

$110 - $160/hr

As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global ...

$124 - $209/hr

The successful candidate will lead this newly combined organization, uplifting our offensive and intelligence capabilities to continually test the security of our products, enterprise, and response ...

New

$185 - $190/hr

Offensive Security Certified Professional (OSCP) * Certified Ethical Hacker (CEH) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Demonstrated experience conducting advanced ...

New

$120 - $170/hr

Senior Security Consultant (Mainframe Penetration Tester) Job Category : Services Requisition ... Experience with offensive toolkits used for network and application penetration testing * Strong ...

New

$100 - $195/hr

... offensive security. * + Clearly interested in stepping away from purely manual research and moving toward the development of AI systems. * + Building something massive matters more to you than ...

$120 - $170/hr

Bring an offensive-security perspective to your analysis, drawn from hands‑on red teaming, penetration testing, or equivalent work, and use it to anticipate how adversaries operate. * Have a strong ...

$144 - $288/hr

Partner with security, engineering, and threat intelligence teams to translate offensive findings into defensive improvements * Support alignment of offensive capabilities with business and security ...

$144 - $288/hr

Partner with security, engineering, and threat intelligence teams to translate offensive findings into defensive improvements * Support alignment of offensive capabilities with business and security ...

$90 - $130/hr

We're comprised of top talent from private industry, government, intelligence, and law enforcement who are specialists in threat detection, incident response, digital forensics, offensive security ...

$195 - $220/hr

Experience in offensive security engagements. * Familiarity with static code analysis and/or fuzz testing. * Contributions and participation in the security community and/oropen sourcesoftware.

$95 - $135/hr

Hands-on experience with offensive security tools (e.g. Kali, Metasploit, Burp, etc.) required. * Minimum of 7 years experience in Information Technology. * Minimum of 4 years overall in Information ...

$120 - $180/hr

... offensive security infrastructure. You will engage security leaders, engineering teams, and executive stakeholders to help organizations modernize how they approach application and cloud security.

$86 - $138/hr

Offensive Security Certified Professional (OSCP) * Offensive Security Certified Professional (OSCP) * Hack the Box Certified Penetration Testing Specialist (CPTS) * TCM Security Practical Network ...

New

$160 - $253/hr

This position invites you to apply your solid security background and keen interest in offensive security validating detection methods, helping to create effective and reliable detection content that ...

$131 - $237/hr

Offensive security background -- penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained ...

$110 - $150/hr

SANS Offensive Security Certification - SANS Institute**Travel**Less than 25%**Workstyle**HybridThe total compensation for this position includes base salary or wages, and may include components such ...

Showing results 21-40

Offensive Security information

See Kentucky salary details

$49.5K

$115.5K

$161.5K

How much do offensive security jobs pay per year?

As of Sep 4, 2026, the average yearly pay for offensive security in Kentucky is $115,481.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,400.00 and $130,300.00 per year, depending on experience, location, and employer.

What is offensive security?

An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.

What does a typical day look like for someone working in offensive security?

A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.

What are the key skills and qualifications needed to thrive in offensive security, and why are they important?

To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

What are popular job titles related to Offensive Security jobs in Kentucky?

For Offensive Security jobs in Kentucky, the most frequently searched job titles are:

Infographic showing various Offensive Security job openings in Kentucky as of August 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $115,481 per year, or $55.5 per hour.

$120 - $160/hr

Other

Posted 17 days ago


BDO USA rating

8.2

Company rating: 8.2 out of 10

Based on 29 frontline employees who took The Breakroom Quiz

9th of 23 rated bookkeepers and accountants


Job description

Job Summary:

The Senior Cyber Security Penetration Tester performs offensive security testing for BDO clients and provides practical, risk-based remediation guidance. This role works with client stakeholders to define scope, rules of engagement, and objectives, executes testing to simulate realistic attacker behaviors, and communicates results clearly to both technical and executive audiences. Engagements may include external and internal network penetration testing, Active Directory attack path testing, web and API application testing, cloud and Microsoft 365 security assessments, and AI enabled application testing. The role may also support red team and purple team exercises in collaboration with client SOC teams and contributes to internal tooling and automation through shared repositories.

Job Duties:
  • Participates in client penetration testing and vulnerability assessment engagements across external and internal networks, Active Directory, web applications, APIs, cloud platforms, and Microsoft 365, including reconnaissance, attack surface discovery, and service enumeration
  • Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and validates exploitability end to end for High and Critical findings and when feasible for other findings
  • Performs authenticated testing when appropriate by coordinating access approvals, applying least privilege, safeguarding secrets, and confirming access removal or rotation at engagement closeout
  • Performs and reviews web and API security testing using Burp Suite and related techniques, focusing on authentication, session management, access control, injection, insecure deserialization, and business logic, and documents reproducible steps and payloads for remediation and retesting
  • Reviews AI-enabled applications and LLM integrations for common risks (for example, prompt injection, sensitive data exposure, insecure output handling, and tool or function calling abuse) and provides practical mitigation guidance aligned to OWASP Top 10 for LLM Applications
  • Supports scoping and delivery under the direction of an assigned Project Manager by documenting objectives and rules of engagement, coordinating technical logistics with client teams, providing timely status updates across concurrent engagements, and ensuring testing is performed safely within approved scope
  • For internal and Active Directory engagements, maps and demonstrates feasible attack paths, for example, using BloodHound or equivalent, including privilege escalation and lateral movement, validates root causes in configuration and permissions, and provides actionable remediation
  • Documents reproducible workpapers and evidence with appropriate data protection practices, participates in peer review and quality assurance, and escalates critical findings quickly to support timely mitigation
  • Produces high-quality client deliverables, including test plans, technical reports, and executive readouts, with clear evidence, proof-of-exploit artifacts, risk ratings, reproduction steps, and prioritized remediation recommendations, and facilitates results discussions and remediation workshops
  • Facilitates red team style engagements in collaboration with client SOC teams by coordinating deconfliction, leveraging SIEM telemetry to validate detection and response, and supporting threat hunting and purple team activities tied to observed attacker behaviors
  • Performs validation and retesting to confirm remediation effectiveness and documents retest results for client stakeholders
  • Maintains internal offensive security tooling, scripts, and reusable testing components, including automation and agent-based utilities, to improve assessment repeatability and quality. Contributes through Git workflows, pull requests, and code review
  • Other duties as required
Supervisory Responsibilities:
  • N/A
Qualifications, Knowledge, Skills, and Abilities: Education:
  • High school diploma or GED, required
  • Bachelor’s degree in Cybersecurity, Information Security, or Computer Science, preferred
Experience:
  • Four (4) or more years of hands-on penetration testing and security assessment experience (network, web, API, wireless, cloud, and/or Microsoft 365), including scoping, execution, reporting, and client presentations, required
  • Demonstrated experience producing professional services deliverables (test plans, technical reports, executive summaries) and communicating complex technical issues to non-technical stakeholders, required
  • Exposure to testing AI-enabled applications (including LLM-based features) and familiarity with emerging guidance such as OWASP Top 10 for LLM Applications, preferred
  • Experience supporting social engineering assessments, such as phishing, vishing, baiting, and tailgating, preferred
  • Strong fundamentals in Windows and Linux administration, TCP/IP networking, and DNS, required
  • Hands-on experience administering and troubleshooting Active Directory in enterprise environments, including users and groups, group policy, permissions, and DNS integration, plus foundational knowledge of authentication protocols and identity flows such as Kerberos, NTLM, SAML, OAuth 2.0, and OpenID Connect, required
  • Two (2) or more years of experience supporting IT Penetration and Security projects such as PTES, OWASP, SANS, or other cyber security frameworks, preferred
  • Experience working with SIEM platforms and core SOC workflows, including basic threat hunting and alert triage to validate detections during red team or purple team activities, preferred
  • Hands-on experience with scripting/automation and light tool development to improve testing efficiency and repeatability (e.g., Python, PowerShell, Bash), required
  • DevOps and engineering fundamentals, including Git version control, pull request workflows, and exposure to CI/CD and containers (for example, GitHub Actions, Azure DevOps pipelines, Docker), preferred
  • Experience conducting internal network and Active Directory penetration tests, including attack path mapping (for example, using BloodHound or equivalent), privilege escalation, lateral movement, and prioritized remediation guidance, preferred
  • Experience working within a national consulting organization or professional services, preferred
License(s)/Certification(s):
  • OSCP (or equivalent hands‑on penetration testing certification), strongly preferred; additional certifications such as OSCE, OSWE/OSWA, GIAC (GPEN, GXPN), CRTO (or equivalent), CEH, LPT, CompTIA PenTest+, CISSP, or other relevant certifications, preferred
  • AWS Cloud Practitioner or Microsoft 365 Certified: Security Administrator Associate, preferred
Software:
  • Proficient with offensive security and assessment toolsets (e.g., Kali Linux toolchain, Burp Suite, Metasploit, Nmap, Nessus/Tenable, and common AD assessment tooling such as BloodHound), including scan configuration/tuning, manual verification, and evidence collection, required
  • Proficient with Git-based source control and collaboration platforms (for example, GitHub), including branching, pull requests, and peer review, required
  • Proficient in the use of Windows and Microsoft Office Suite, specifically Word, Excel, and PowerPoint, required
  • Familiarity with SIEM tooling and log investigation workflows (for example, Splunk and Microsoft Sentinel) to support validation of detection and response during engagements, preferred
  • Experience using AI-assisted development tools (for example, GitHub Copilot and Claude Code) to accelerate scripting and tool development, with the ability to use these tools responsibly without exposing client confidential data or sensitive credentials, preferred
  • Experience with cloud platforms and identity/security services (e.g., Microsoft Azure and Microsoft 365) and the ability to script/automate tasks (e.g., Python, PowerShell, Bash), preferred
  • Familiarity with AI/LLM security testing approaches and tooling (e.g., structured prompt testing, abuse‑case libraries, and API-driven test harnesses) and the ability to use AI‑assisted tooling responsibly without exposing client confidential data, preferred
Language(s):
  • Multilingual capabilities (read, speak and/or write), preferred
Other Knowledge, Skills, & Abilities:
  • Ability to maintain a high level of confidentiality and professionalism
  • Ability to communicate with professionals at all organizational levels
  • Ability to build and maintain strong relationships with BDO and client personnel
  • Solid organizational and excellent verbal and written communication skills
  • Ability to successfully multi‑task while working independently or within a group environment
  • Ability to translate technical vulnerabilities into clear risk statements and actionable remediation guidance, including prioritization and validation steps
Keyword:
  • Cyber, Security, Penetration Tester, Black Box Testing, Certified Ethical Hacker, Microsoft 365 Azure Cloud, AWS Cloud, GIAC, GPEN, GXPN, Licensed Penetration Tester Master, LPT, Security Administrator, IT Network Security Assessments, Wired, Wireless

Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate’s qualifications, experience, skills, and geography.

National Range: $120,000 - $160,000
Maryland Range: $120,000 - $160,000
NYC/Long Island/Westchester Range: $120,000 - $160,000

#J-18808-Ljbffr

What BDO USA employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


BDO logo

About BDO

Sourced by ZipRecruiter

At BDO, culture is the first order of business. We succeed when we cultivate a conscious and caring corporate culture that puts people at the center of everything we do. In essence, the business of our business is to help people thrive every day. This mindset powers our growth by supporting the development of our people, the success of our clients, and the betterment of our communities. It means taking an expansive view of what’s possible, and committing ourselves to achieving exceptional outcomes. At BDO, we are cultivating a culture where our professionals thrive in their work of providing middle market leaders with insight-driven perspectives and assurance, tax and advisory services, helping companies take business as usual to better than usual.

Industry

Administrative assistance services and accounting services

Company size

10,000+ Employees

Headquarters location

Chicago, IL, US