1

Offensive Security Jobs in Chicago, IL (NOW HIRING)

Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to ...

Senior Manual Ethical Hacker

Chicago, IL ยท On-site

$103K - $132K/yr

Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to ...

The ideal candidate should be a seasoned, trusted adversary with advanced expertise in offensive security methodologies to help lead the battle-hardening of McDonald's information assets worldwide.

Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and ...

Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and ...

Security Engineer

Chicago, IL ยท On-site

$145K - $195K/yr

About The Role We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack ...

Security Engineer

Chicago, IL ยท On-site

$145 - $195/hr

About The Role We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack ...

Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH, CSSLP, GPEN, GWAPT, or UL 2900 training. CHI: $130,000-$180,000 The expected salary range above is ...

Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH, CSSLP, GPEN, GWAPT, or UL 2900 training. CHI: $130,000-$180,000 The expected salary range above is ...

Cyber Threat Analyst

Chicago, IL ยท On-site

$70 - $108/hr

Preferred - 2 of Cyber Threat Intelligence, Offensive Security, Threat Hunting, Detection Engineering or related In Lieu of Education * 2 years of Cyber Threat Intelligence, Offensive Security ...

Cyber Threat Analyst

Chicago, IL ยท On-site

$69K - $108K/yr

Preferred - 2 of Cyber Threat Intelligence, Offensive Security, Threat Hunting, Detection Engineering or related In Lieu of Education * 2 years of Cyber Threat Intelligence, Offensive Security ...

Cyber Threat Analyst

Chicago, IL ยท On-site

$69K - $108K/yr

Preferred - 2 of Cyber Threat Intelligence, Offensive Security, Threat Hunting, Detection Engineering or related In Lieu of Education * 2 years of Cyber Threat Intelligence, Offensive Security ...

Cyber Threat Analyst

Chicago, IL ยท Hybrid

$69K - $108K/yr

Preferred - 2 of Cyber Threat Intelligence, Offensive Security, Threat Hunting, Detection Engineering or related In Lieu of Education * 2 years of Cyber Threat Intelligence, Offensive Security ...

Learn modern cybersecurity concepts, offensive security methodologies, and consultative selling skills from experienced mentors. What You'll Bring * 1-4 years of experience in Sales Engineering ...

Showing results 21-40

Offensive Security information

See Chicago, IL salary details

$58.7K

$137K

$191.6K

How much do offensive security jobs pay per year?

As of Sep 5, 2026, the average yearly pay for offensive security in Chicago, IL is $136,970.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,300.00 and $154,500.00 per year, depending on experience, location, and employer.

What is offensive security?

An Offensive Security job involves proactively identifying and exploiting security vulnerabilities in systems, networks, and applications to help organizations strengthen their defenses. Professionals in this field, such as ethical hackers and penetration testers, simulate real-world cyberattacks to find weaknesses before malicious actors can exploit them. They use various tools, techniques, and frameworks to assess security risks, provide recommendations, and improve overall cybersecurity posture. Offensive security experts often work for security firms, enterprises, or government agencies to ensure robust digital protection.

What does a typical day look like for someone working in offensive security?

A typical day in Offensive Security involves conducting penetration tests, vulnerability assessments, and red teaming exercises to identify and exploit potential weaknesses in systems and networks. You may spend time analyzing findings, preparing detailed reports, and collaborating with IT teams to discuss remediation strategies. The role often requires staying current with emerging threats and tools, as well as participating in team meetings to review attack simulations or incident scenarios. Regular communication with clients or internal stakeholders is also common to explain technical concepts in an accessible way. The dynamic nature of the work keeps each day interesting and fosters continuous learning and problem-solving.

What are the key skills and qualifications needed to thrive in offensive security, and why are they important?

To thrive as an Offensive Security professional, you need a deep understanding of networks, operating systems, penetration testing methodologies, and typically hold a degree in computer science or a related field. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like OSCP or CEH, is often required. Strong analytical thinking, attention to detail, effective communication, and ethical judgment are essential soft skills. These abilities are crucial for identifying vulnerabilities, communicating risks, and helping organizations improve their security posture.

What are popular job titles related to Offensive Security jobs in Chicago, IL?

For Offensive Security jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Offensive Security jobs in Chicago, IL look for?

The top searched job categories for Offensive Security jobs in Chicago, IL are:

Infographic showing various Offensive Security job openings in Chicago, IL as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $136,970 per year, or $65.9 per hour.

Senior Application Security & DevSecOps Engineer

MrBeast

Chicago, IL โ€ข On-site

$60.50 - $80.75/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted yesterday


Key responsibilities

  • Lead secure code review and threat modeling for web, mobile, and API surfaces.

  • Own the application vulnerability lifecycle, including discovery, triage, remediation guidance, and verification.

  • Own the security posture of CI/CD pipelines and deployment toolchains, including integrating security scans and automating deployment steps.


Job description

About Us
Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson, popularly known as MrBeast, the most watched person in the world. Renowned for revolutionizing digital content creation, Beast Industries encompasses a diverse portfolio of ventures that extend far beyond its origins on YouTube. With a mission to entertain, inspire, and create significant social impact, Beast Industries operates across various domains including digital media, philanthropy, consumer products, and innovative business initiatives. At Beast Industries, we believe in the transformative power of digital media and its potential to entertain, educate, and effect positive change. Our commitment to innovation, creativity, and philanthropy drives us to explore new frontiers, create unforgettable experiences, and build a legacy that inspires future generations.
Location: (On-site / Hybrid / Remote - NY, Bay Area, Chicago, Greenville)
Department: Technology
About The Role
This is a hands-on Application Security role, not a generalist security position. As Senior Application Security & DevSecOps Engineer, you will own the security of our web and mobile applications and the APIs behind them - finding the vulnerabilities before anyone else does, running our offensive testing and bug bounty programs, and building security into the pipelines that ship our code.
You'll work close to the code. Our stack is heavily automated and developer-centric: a custom DSL layer governs how code reaches production, translating into Kubernetes and Terraform deployment tasks, and our backend leans on Kotlin and Gradle. You should be able to read and reason about production code, write your own tooling, and own the security of the build and release process end to end - not hand the hard parts to DevOps.
If you think like an attacker, are fluent in mobile and API internals, and want to own AppSec for products that millions of people use, this role is for you.
What You'll Do
Application Security (core)
  • Lead secure code review and threat modeling for web, mobile, and API surfaces, and drive secure-by-design practices with engineering teams.
  • Own the application vulnerability lifecycle - discovery, triage, severity, remediation guidance, and verification - and partner with engineers on durable fixes, not just findings.
  • Build internal AppSec tooling and lightweight security libraries that make the secure path the easy path for developers.
Mobile Application Security
  • Own security for our iOS and Android apps: secure local storage (Keychain / Keystore), certificate pinning, jailbreak/root and tampering detection, anti-reverse-engineering, and secure app-to-API communication.
  • Assess apps against OWASP MASVS / MASTG, and review third-party SDKs and dependencies for risk.
  • Perform mobile-focused testing with tooling such as Frida, objection, MobSF, Burp Suite, and static/dynamic RE tools.
Offensive Security & Penetration Testing
  • Run internal penetration tests and red-team-style assessments against our apps, APIs, and supporting services.
  • Validate and weaponize findings to demonstrate real impact, then drive them to resolution.
  • Pressure-test authentication, authorization, session handling, and business-logic flows (OAuth/OIDC, GraphQL/REST, IDOR, privilege escalation).
Bug Bounty Program
  • Own and operate our bug bounty program (e.g., HackerOne / Bugcrowd): scope definition, researcher communication, triage, deduplication, severity, and payout coordination.
  • Close the loop by feeding bounty findings back into secure code review, threat models, and CI/CD checks so the same class of bug doesn't recur.
  • Track program health and report on trends, top vulnerability classes, and time-to-fix.
CI/CD & Pipeline Security
  • Own the security posture of our CI/CD pipelines and deployment toolchain, including the custom DSL that translates to Kubernetes and Terraform.
  • Integrate and tune SAST, DAST, and dependency/SCA scanning (e.g., Semgrep, CodeQL) as meaningful, low-noise gates in GitHub Actions.
  • Implement secrets scanning, build/release integrity, artifact signing, and supply-chain controls (SBOMs, provenance).
  • Drive a security-focused cleanup of existing pipelines and automate the manual, one-off deployment steps that exist today.
What You Bring
Required Experience
  • 8+ years focused on Application Security and/or offensive security (penetration testing, exploit development).
  • Strong software-development skills - you can read, write, and review production code rather than just operating tools. Experience with Kotlin and Gradle (and/or Swift/Android for mobile) is highly relevant to our stack; Python for automation and custom tooling.
  • Deep mobile application security expertise across iOS and Android: OWASP MASVS/MASTG, cert pinning, secure storage, anti-tampering/RE, and mobile testing tooling (Frida, objection, MobSF, Burp).
  • Hands-on penetration testing of web apps, mobile apps, and APIs, with the ability to demonstrate real exploitability.
  • API security depth - OAuth/OIDC, REST and GraphQL, authn/authz and business-logic flaws.
  • CI/CD security experience with GitHub Actions, including SAST/DAST/SCA integration, secrets scanning, and securing the build/release pipeline.
  • Strong security fundamentals, including applied cryptography - a clear command of certificates and PKI, encryption vs. key management, and where HSMs fit.
Strongly Preferred
  • Experience running or scaling a bug bounty / VDP program (HackerOne, Bugcrowd, or similar).
  • Offensive security certifications (OSCP, OSWE, GMOB, or equivalent demonstrated skill).
  • Experience securing consumer fintech/Gaming/Reels apps and the regulatory expectations that come with handling user funds and data for teens and their subscriptions.
  • Software-supply-chain security experience (SBOMs, artifact signing, provenance).
  • Reverse engineering / binary analysis (Ghidra, Hopper, IDA).
What Success Looks Like
  • Critical and high-severity application vulnerabilities are found internally - by you and your tooling - before they reach users or external researchers.
  • Our mobile apps meet a defined, measurable security bar across iOS and Android.
  • The bug bounty program is well-run, fairly triaged, and consistently feeds improvements back into the SDLC.
  • Every meaningful change ships through CI/CD with security checks that engineers trust because they're accurate, not noisy.
  • Manual, one-off deployment steps are automated away, and the build/release path is hardened end to end.
Why This Role Is Different
  • You'll own application security for products used by millions - not review tickets for a generic security backlog.
  • You'll work close to the code in a Kotlin/Gradle, highly automated stack where AppSec and software engineering are the same discipline.
  • You'll run real offensive testing and a real bug bounty program, then turn those findings into lasting fixes.
  • You'll operate at the intersection of Application Security, Offensive Security, and CI/CD - and build the systems, not just audit them.

Benefits
The Perks, Why Work On the MrBeast Team
We are redefining what entertainment and storytelling look like at global scale. Every piece of content we publish reaches millions and influences culture in real time. This is your opportunity to lead the team that decides how those moments come to life across every screen.
  • Competitive Salary
  • Generous Medical (Blue Cross Blue Shield), Dental, Vision and company-paid Life Insurance
  • Company contributions to employee Health Savings Accounts (HSA)
  • 401k Plan with Safe Harbor company-matching
  • Flexible vacation policy and paid company holidays
  • Company-provided technology package
  • Relocation assistance where applicable, including travel and company-provided housing for the first 90 days