Senior Offensive Security Engineer

Revolutional, LLC
  • Mclean, VA
  • Remote
  • $175,000–$185,000 Per Year
Today

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Title: Senior Offensive Security Engineer
Location: Remote
Terms: Full-time
Salary: $175-185k DOE
Clearance: Ability to obtain and maintain public trust as required

Project Description

This position supports cybersecurity operations and offensive security testing efforts for the Department of Veterans Affairs (VA). The role focuses on conducting time based penetration testing activities that support the Authority to Operate (ATO) process for system owners across enterprise environments.

The environment includes modern web applications, APIs, cloud infrastructure, operating systems, databases, and network devices across both on-premises and cloud hosted systems.

The core challenge: proactively identifying vulnerabilities and security weaknesses before adversaries can exploit them while supporting mission critical healthcare and federal systems and raising the bar of the offensive security team that performs this work.

Position Description

As a Senior Offensive Security Engineer at Revolutional, you will serve as a technical subject matter expert on an Offensive Security Team; driving the quality, depth, and consistency of penetration testing, web, and Red Team operations support across enterprise systems, applications, cloud infrastructure, and networks.

Beyond executing the most complex assessments yourself, you will help lead the team executing the assessments and aid in providing technical guidance, engagement with government leaders, review findings, mentoring junior and mid-level operators, and elevating the team's tradecraft. You will be expected to be able to conduct assessments and solve hard technical problems end to end, support development of custom tooling and automation (including AI assisted capabilities), and ensure the team efficiently executes and reports offensive engagements.  

This role is for a seasoned offensive operator who can think like the adversary, discovery security vulnerabilities that are more than the results of some automated scanning tool, experience using OPSEC minded on target operations as part of a red team campaign and deliver technically accurate reports and articulate the results to leaders that can help improve the security posture of federal systems.  

Responsibilities: 

  • Serves as a senior leader on an offensive security team providing technical expertise across penetration testing, web application testing, and Red Team operations, ensuring a high standard for depth and quality of testing occurs
  • Help lead the offensive security team: planning and resourcing engagements, reviewing peer findings, and providing hands on technical mentorship to junior and mid-level penetration testers
  • perform time based penetration tests against web applications, APIs, databases, network devices, operating systems, cloud environments, and infrastructure
  • Perform advanced manual web application testing against modern frameworks and APIs, going well beyond OWASP Top 10 to identify complex, business logic, and chained vulnerabilities
  • Lead and support advanced Red Team operations, including threat modeling, initial access, command and control (C2), post exploitation, lateral movement, and EDR evasion
  • Design and build custom tools, scripts, exploits, and automation to expand and mature the Offensive Security Team's capabilities
  • Integrate AI assisted tooling and automation into penetration testing and application security workflows to increase speed, coverage, and consistency
  • Review newly published vulnerabilities and develop impact assessments and detection/exploitation guidance for customer environments
  • Analyze vulnerabilities and determine associated risk based on exploitability and operational impact
  • Author clear, concise, and actionable reports; present findings, metrics, and remediation recommendations to customers, system owners, and executive stakeholders
  • Define and evolve testing methodologies, operational procedures, and reporting standards for the team
  • Maintain offensive security infrastructure, hardware, and software used for assessments and attack simulations
  • Support assessments that may require work outside standard business hour

Technical Environment

Operating Systems

  • Kali Linux Suite
  • Windows, Unix, and Linux

Offensive Security Tooling

  • Burp Suite Professional, Nessus (Tenable), NMAP, Metasploit
  • Command and control (C2) frameworks (e.g., Cobalt Strike or equivalent) and Active Directory attack tooling (e.g., BloodHound)
  • Nuclei, Project discovery tools

Cloud & Web Application

  • Cloud security assessment across AWS, Azure, and/or GCP; modern web frameworks and API testing

Scripting, Automation & Development

  • Bash, PowerShell, and Python; additional development languages (e.g., Go, C#, C/C++) a plus
  • AI/LLM assisted tooling and security automation frameworks

Security Practices

  • Penetration Testing
  • Web Application Testing
  • Vulnerability Analysis
  • Threat Modeling
  • Red Team Operations
  • Security Reporting
  • Tool Development

What You Bring (Requirements):

  • Baseline Requirements:
    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (5 years of additional relevant experience may substitute for education)
    • 6+ years of overall experience in cybersecurity or IT, with 5+ years dedicated to offensive security or penetration testing
    • Demonstrated experience leading engagements and mentoring or developing other testers
    • At least one industry recognized offensive security certification (e.g., OSCP or higher)
    • Ability to obtain and maintain required federal clearance / public trust as needed
  • Technical Capabilities:
    • Proven, hands on experience conducting penetration tests using industry standard offensive security tools across Windows, Unix, and Linux
    • Deep expertise in identifying, validating, and exploiting web application vulnerabilities, including complex and business logic flaws
    • Experience assessing cloud infrastructure and internal networks, including Active Directory attack paths
    • Experience developing custom tools, scripts, or exploits to enhance offensive security operations
    • Experience with Red Team TTPs, including C2, post exploitation, and EDR evasion
    • Strong scripting and automation skills in Bash, PowerShell, Python, or similar languages
    • Experience applying AI assisted tools or automation to penetration testing and vulnerability analysis
    • Ability to communicate technical findings clearly through written reports and customer/executive briefings
  • Core Strengths: 
    • Strong analytical and problem solving skills with an adversarial mindset
    • Technical leadership: the ability to set direction, review others' work, and raise the team's tradecraft
    • Strong ownership mindset and accountability for outcomes
    • Effective written and verbal communication skills
    • Ability to operate in fast paced and mission focused environments
    • Strong collaboration and teamwork skills
  • Nice to Have (Differentiators): 
    • Web application specialization: GIAC Web Application Penetration Tester (GWAPT)
    • Advanced offensive certifications such as OSCE³ (OSEP + OSWE + OSED), OSEP, OSWE, or OSED
    • Red Team leadership: Certified Red Team Operator (CRTO / CRTO II) or equivalent
    • Experience applying AI/LLM assisted tooling, automation frameworks, or scripted solutions to enhance penetration testing and vulnerability analysis
    • Experience with advanced Red Team operations including reverse engineering, malware development, C2, and EDR evasion
    • Experience supporting federal government cybersecurity programs

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.  Some of these recognitions include:  

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company 
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family!   In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans 
  • 100% employer-paid dental and vision insurance options 
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities 
  • Team and company-wide events, recognition, and appreciation-- and so much more! 

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!   

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.  To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily.  Other duties in addition to those listed may be assigned as necessary to meet business needs.  Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.  If you are in need of an accommodation, please contact

HR@harmonia.com

.  

Numbers & Facts

LocationMclean, VA (
Remote
)
Salary$175,000–$185,000 Per Year

Skills

  • Affirmative Actionunmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Automationunmatched
  • Bash Scriptingunmatched
  • C Programming Languageunmatched
  • C++ Programming Languageunmatched
  • Campaignsunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Department of Veterans Affairsunmatched
  • Establish Prioritiesunmatched
  • Federal Governmentunmatched
  • Go Programming Language (Golang)unmatched
  • Governmentunmatched
  • Health Insuranceunmatched
  • Healthcareunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Linux Operating Systemunmatched
  • Machine Toolunmatched
  • Malwareunmatched
  • Mentoringunmatched
  • Metasploitunmatched
  • Metricsunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft C# (C Sharp)unmatched
  • Microsoft Windows Operating Systemunmatched
  • NMapunmatched
  • Nessusunmatched
  • Operating Systemsunmatched
  • Operational Measurementunmatched
  • Operational Supportunmatched
  • Operations Processesunmatched
  • Operations Security (OPSEC)unmatched
  • Penetration Testingunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Python Programming/Scripting Languageunmatched
  • Quality Assurance Methodologyunmatched
  • Reporting Skillsunmatched
  • Reverse Engineeringunmatched
  • Riskunmatched
  • Sales Presentationunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Infrastructureunmatched
  • Small Businessunmatched
  • Software Testingunmatched
  • Team Lead/Managerunmatched
  • Team Playerunmatched
  • Technical Deliveryunmatched
  • Technical Leadershipunmatched
  • Test Automationunmatched
  • Test Plan/Scheduleunmatched
  • Threat Modelingunmatched
  • Unix Operating Systemsunmatched
  • Web Testingunmatched
  • Windows PowerShellunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder