1

Offensive Security Jobs in Virginia (NOW HIRING)

Offensive Security Engineer

Mclean, VA · On-site

$120 - $160/hr

We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...

next page

Showing results 1-20

Offensive Security information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do offensive security jobs pay per year?

As of Aug 28, 2026, the average yearly pay for offensive security in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

What is offensive security?

An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.

What does a typical day look like for someone working in offensive security?

A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.

What are the key skills and qualifications needed to thrive in offensive security, and why are they important?

To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

What are popular job titles related to Offensive Security jobs in Virginia?

For Offensive Security jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Offensive Security jobs in Virginia look for?

The top searched job categories for Offensive Security jobs in Virginia are:

What cities in Virginia are hiring for Offensive Security jobs?

Cities in Virginia with the most Offensive Security job openings:

Infographic showing various Offensive Security job openings in Virginia as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $131,822 per year, or $63.4 per hour.

Senior Offensive Security Engineer

Mclean, VA • Remote

$175/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Title: Senior Offensive Security Engineer
Location: Remote
Terms: Full-time
Salary: $175-185k DOE
Clearance: Ability to obtain and maintain public trust as required

Project Description

This position supports cybersecurity operations and offensive security testing efforts for the Department of Veterans Affairs (VA). The role focuses on conducting time based penetration testing activities that support the Authority to Operate (ATO) process for system owners across enterprise environments.

The environment includes modern web applications, APIs, cloud infrastructure, operating systems, databases, and network devices across both on-premises and cloud hosted systems.

The core challenge: proactively identifying vulnerabilities and security weaknesses before adversaries can exploit them while supporting mission critical healthcare and federal systems and raising the bar of the offensive security team that performs this work.

Position Description

As a Senior Offensive Security Engineer at Revolutional, you will serve as a technical subject matter expert on an Offensive Security Team; driving the quality, depth, and consistency of penetration testing, web, and Red Team operations support across enterprise systems, applications, cloud infrastructure, and networks.

Beyond executing the most complex assessments yourself, you will help lead the team executing the assessments and aid in providing technical guidance, engagement with government leaders, review findings, mentoring junior and mid-level operators, and elevating the team's tradecraft. You will be expected to be able to conduct assessments and solve hard technical problems end to end, support development of custom tooling and automation (including AI assisted capabilities), and ensure the team efficiently executes and reports offensive engagements.  

This role is for a seasoned offensive operator who can think like the adversary, discovery security vulnerabilities that are more than the results of some automated scanning tool, experience using OPSEC minded on target operations as part of a red team campaign and deliver technically accurate reports and articulate the results to leaders that can help improve the security posture of federal systems.  

Responsibilities: 

  • Serves as a senior leader on an offensive security team providing technical expertise across penetration testing, web application testing, and Red Team operations, ensuring a high standard for depth and quality of testing occurs
  • Help lead the offensive security team: planning and resourcing engagements, reviewing peer findings, and providing hands on technical mentorship to junior and mid-level penetration testers
  • perform time based penetration tests against web applications, APIs, databases, network devices, operating systems, cloud environments, and infrastructure
  • Perform advanced manual web application testing against modern frameworks and APIs, going well beyond OWASP Top 10 to identify complex, business logic, and chained vulnerabilities
  • Lead and support advanced Red Team operations, including threat modeling, initial access, command and control (C2), post exploitation, lateral movement, and EDR evasion
  • Design and build custom tools, scripts, exploits, and automation to expand and mature the Offensive Security Team's capabilities
  • Integrate AI assisted tooling and automation into penetration testing and application security workflows to increase speed, coverage, and consistency
  • Review newly published vulnerabilities and develop impact assessments and detection/exploitation guidance for customer environments
  • Analyze vulnerabilities and determine associated risk based on exploitability and operational impact
  • Author clear, concise, and actionable reports; present findings, metrics, and remediation recommendations to customers, system owners, and executive stakeholders
  • Define and evolve testing methodologies, operational procedures, and reporting standards for the team
  • Maintain offensive security infrastructure, hardware, and software used for assessments and attack simulations
  • Support assessments that may require work outside standard business hour

Technical Environment

Operating Systems

  • Kali Linux Suite
  • Windows, Unix, and Linux

Offensive Security Tooling

  • Burp Suite Professional, Nessus (Tenable), NMAP, Metasploit
  • Command and control (C2) frameworks (e.g., Cobalt Strike or equivalent) and Active Directory attack tooling (e.g., BloodHound)
  • Nuclei, Project discovery tools

Cloud & Web Application

  • Cloud security assessment across AWS, Azure, and/or GCP; modern web frameworks and API testing

Scripting, Automation & Development

  • Bash, PowerShell, and Python; additional development languages (e.g., Go, C#, C/C++) a plus
  • AI/LLM assisted tooling and security automation frameworks

Security Practices

  • Penetration Testing
  • Web Application Testing
  • Vulnerability Analysis
  • Threat Modeling
  • Red Team Operations
  • Security Reporting
  • Tool Development

What You Bring (Requirements):

  • Baseline Requirements:
    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (5 years of additional relevant experience may substitute for education)
    • 6+ years of overall experience in cybersecurity or IT, with 5+ years dedicated to offensive security or penetration testing
    • Demonstrated experience leading engagements and mentoring or developing other testers
    • At least one industry recognized offensive security certification (e.g., OSCP or higher)
    • Ability to obtain and maintain required federal clearance / public trust as needed
  • Technical Capabilities:
    • Proven, hands on experience conducting penetration tests using industry standard offensive security tools across Windows, Unix, and Linux
    • Deep expertise in identifying, validating, and exploiting web application vulnerabilities, including complex and business logic flaws
    • Experience assessing cloud infrastructure and internal networks, including Active Directory attack paths
    • Experience developing custom tools, scripts, or exploits to enhance offensive security operations
    • Experience with Red Team TTPs, including C2, post exploitation, and EDR evasion
    • Strong scripting and automation skills in Bash, PowerShell, Python, or similar languages
    • Experience applying AI assisted tools or automation to penetration testing and vulnerability analysis
    • Ability to communicate technical findings clearly through written reports and customer/executive briefings
  • Core Strengths: 
    • Strong analytical and problem solving skills with an adversarial mindset
    • Technical leadership: the ability to set direction, review others' work, and raise the team's tradecraft
    • Strong ownership mindset and accountability for outcomes
    • Effective written and verbal communication skills
    • Ability to operate in fast paced and mission focused environments
    • Strong collaboration and teamwork skills
  • Nice to Have (Differentiators): 
    • Web application specialization: GIAC Web Application Penetration Tester (GWAPT)
    • Advanced offensive certifications such as OSCE³ (OSEP + OSWE + OSED), OSEP, OSWE, or OSED
    • Red Team leadership: Certified Red Team Operator (CRTO / CRTO II) or equivalent
    • Experience applying AI/LLM assisted tooling, automation frameworks, or scripted solutions to enhance penetration testing and vulnerability analysis
    • Experience with advanced Red Team operations including reverse engineering, malware development, C2, and EDR evasion
    • Experience supporting federal government cybersecurity programs

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.  Some of these recognitions include:  

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company 
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family!   In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans 
  • 100% employer-paid dental and vision insurance options 
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities 
  • Team and company-wide events, recognition, and appreciation-- and so much more! 

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!   

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.  To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily.  Other duties in addition to those listed may be assigned as necessary to meet business needs.  Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.  If you are in need of an accommodation, please contact HR@revolutional.com.