Skip to content
PalantirPalantirWashington, DC

Offensive Security Engineer

The engineer conducts web, network, Active Directory, cloud, and container penetration tests, develops offensive security automation, and drives remediation with engineering and external testing partners. The role requires at least four years of offensive security experience plus scripting or programming proficiency.

Salary not listed
Hybrid4+ YOESecurity Engineering

About the role

Responsibilities

  • Conduct hybrid web application penetration tests combining source code review with runtime exploitation across products and internal tooling.
  • Perform external network penetration tests against internet-facing infrastructure, identifying exposed services, misconfigurations, and paths to obtain an initial foothold.
  • Perform internal network and Active Directory security assessments, identifying privilege escalation paths, lateral movement opportunities, and misconfigurations.
  • Assess cloud and containerized infrastructure, including identity, network, and workload configurations.
  • Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques.
  • Scope and manage third-party penetration testing engagements end-to-end, critically review results, and convert findings into prioritized remediation.
  • Partner with engineering to reproduce, prioritize, and verify fixes.
  • Design and build offensive security tooling and automation.
  • Author clear, actionable write-ups and readouts for technical and non-technical stakeholders.

Requirements

  • 4+ years of professional experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Proficiency in at least one scripting or programming language, such as Python or Go, sufficient to build and adapt testing tooling.
  • Experience assessing cloud environments such as AWS, Azure, or Google Cloud and containerized environments such as Docker and Kubernetes.
  • Strength in web application penetration testing, including source code review and runtime testing.
  • Strength in external and internal network penetration testing.
  • Experience with offensive security tooling, including Burp Suite, BloodHound, SharpHound, Certipy, Impacket, Responder, Pacu, ScoutSuite, and Nuclei.
  • Working knowledge of CI/CD pipelines and infrastructure as code.
  • Working knowledge of cloud, container, and orchestration security principles.
  • Understanding of identity and cloud attack paths, including Kerberos abuse, delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven pivots.
  • Strong organizational, written, and verbal communication skills.
  • Willingness and eligibility to obtain a U.S. security clearance preferred.

Nice to Have

  • Offensive security certifications such as OSCP or OSWE.
  • Experience with CTF competitions or bug bounty programs.

Skills

PythonGoburp suitebloodhoundsharphoundcertipyimpacketresponderpacuscoutsuitenucleiAWSAzureGCPKubernetes
AlertMedia

Security Engineer

AlertMediaUnited States

Hands-on Security Engineer responsible for securing cloud applications and AWS infrastructure, strengthening detection and incident response, embedding controls into CI/CD, and supporting audits and enterprise customer security reviews. Requires 3+ years of security experience and practical AWS security expertise.

Salary not listedRemote3+ YOESecurity Engineering
Plaid

Security Analyst, Third-Party Ecosystem Risk Management

PlaidNew York, NY +3

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

119k – 176k/yrHybrid4+ YOESecurity Engineering
Vanta

Manager, Security Operations

VantaUnited States

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

178k – 209k/yrRemote5+ YOESecurity Engineering
Decagon

Governance, Risk, and Compliance Manager

DecagonSan Francisco, CA

Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.

190k – 275k/yrOn-site5+ YOESecurity Engineering
OpenRouter

Third-Party Risk Analyst

OpenRouterUnited States

Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.

Salary not listedRemote4+ YOESecurity Engineering