> Markdown version of [/jobs/ext/3079576-senior-offensive-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/3079576-senior-offensive-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Offensive Cybersecurity Engineer - **Company:** Parry Labs - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Automation of Tests, C++ (Programming Language), Cyber Security, System Configuration, Linux, Digital Signature, Distributed Systems, Fuzz Testing, Hardware Security Module, Python (Programming Language), Key Management, Network Interface, Software Requirements Analysis, TCP/IP, Information Technology, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://www.jofdav.com/jobs/59865118-senior-offensive-cybersecurity-engineer ## About the Role * Bachelor's degree in cybersecurity, computer science, engineering or a related field, or equivalent relevant experience. * 7+ years of security engineering experience, including hands-on offensive testing or vulnerability research. * Experience with authorized penetration testing, protocol analysis, fuzzing and vulnerability assessment. * Ability to review Rust or C/C++ and develop security test tooling in Python or a systems language. * Experience analyzing Linux and network behavior, including TCP/IP, service configuration and access controls. * Experience producing reproducible findings, explaining security impact and verifying remediation with engineering teams. * U.S. citizenship and eligibility to obtain and maintain a U.S. government security clearance if required. An active clearance is not required at hire., * Experience testing positioning, navigation and timing (PNT), distributed systems or embedded devices. * Knowledge of applied cryptography, post-quantum algorithms, hardware security modules or key management. * Experience with source-code security reviews, secure implementation practices or side-channel analysis. * Experience with DoD security testing, STIG verification or Risk Management Framework assessment evidence. ## Description You will lead authorized offensive security assessments of software, network interfaces and distributed mission systems. You will identify vulnerabilities, demonstrate their impact and work with engineers to verify fixes. You will report to a functional engineering manager, with technical direction from the Chief Engineer., * Develop threat models and security test plans linked to system requirements and potential failure modes. * Define authorized test scope, rules of engagement and stop conditions with program stakeholders. * Conduct penetration testing, protocol analysis and vulnerability research in approved test environments. * Build protocol and parser fuzzing tools. Add repeatable security checks to automated test workflows. * Assess Linux services and network interfaces. Review Rust or C/C++ code for security weaknesses. * Evaluate authentication, digital signatures, replay protection and key handling with software and cryptographic engineers. * Document reproducible findings, impact and remediation priorities. Retest fixes and preserve test evidence. * Support red-team and blue-team exercises. Keep assessment signoff separate from implementation ownership. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Hard?](https://www.wearedevelopers.com/magazine/448-is-software-engineering-hard)