Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Engineer

Varite Inc

VARITE is looking for qualified WAF Adversarial Engineer


WHAT THE CLIENT DOES?
An American computer software company that offers a wide range of programs from web design tools, photo manipulation and vector creation, through video/audio editing, mobile app development, print layout and animation software.


WHAT WE DO?
Established in the Year 2000, VARITE is an award-winning minority business enterprise providing global consulting & staffing services to Fortune 1000 companies and government agencies. With 850+ global consultants, VARITE is committed to delivering excellence to its customers by leveraging its global experience and expertise in providing comprehensive scientific, engineering, technical, and non-technical staff augmentation and talent acquisition services.


Job Title: WAF Adversarial Engineer
Location: Seattle preferred, open to remote
Contract Duration: 12 months (Possible Extension)
Pay Rate Range: $65.00/hr. to $70.42/hr. on W2
Work Authorization: Only USC or GC

HERE'S WHAT YOU'LL DO
Duties:
  • Run adversarial test campaigns against Client's WAF stack (Akamai, AWS WAF, Fastly, and Cloudflare) after each rule update cycle.
  • Target encoding evasion, parsing differentials between WAF and origin, request smuggling, chunked encoding manipulation, multipart boundary abuse, Unicode normalization gaps, and logic layer bypasses.
  • Build and maintain a versioned WAF bypass library, organized by vulnerability class (SQLi, XSS, SSRF, path traversal, SSTI, etc.), validated against staging and production WAF configurations, and updated as platforms and rules evolve.
  • Conduct adversarial testing of API endpoints behind the WAF, including business logic abuse, BOLA/BFLA, mass assignment, and parameter manipulation. Document explicitly which classes of attack the WAF can and cannot reliably cover.
  • Triage complex false positive investigations that cannot be resolved through log analysis alone - reproduce the ambiguous traffic from the attacker side and recommend targeted rule adjustments.
  • Produce concise validation reports that translate offensive findings into testable rule candidates the team can refine and deploy. Each deliverable is a reproducer plus a rule recommendation, not a "bypass confirmed " note.
  • Provide adversarial perspective during active edge incidents - likely attacker behavior, blind spots, next probable moves.
  • Operate as the continuous validation function for the WAF program, integrated with the team's rule update cadence rather than running standalone pentest engagements.
Skills:
  • Demonstrated WAF bypass experience against at least two commercial WAF platforms (Akamai, AWS WAF, Fastly, or Cloudflare).
  • Deep working knowledge of protocol edge cases that affect WAF inspection: request smuggling primitives, chunked transfer encoding abuse, multipart boundary manipulation, Unicode normalization differentials, and header injection patterns.
  • Web application penetration testing track record with WAF-specific scope. OSCP, BSCP, OSWE, or a portfolio of disclosed bypasses, conference talks, or prior validation engagements against WAF-protected assets. Tool-running alone does not qualify. - Proven ability to translate offensive findings into defensive artifacts - reproducer plus rule candidate, not just a finding.
  • Strong scripting in Python or Go for building test harnesses, payload generators, and replay tooling.
  • Comfortable working in CI/CD pipelines and cloud environments (AWS or Azure). Plug into existing infrastructure rather than build it.
Preferred:
  • API-specific attack surface depth: GraphQL injection, BOLA/BFLA, mass assignment.
  • Akamai platform internals: KRS / ASE rule engine, custom Lua / EdgeWorkers exposure.
  • Bot evasion at the behavioral layer: headless browser fingerprinting bypass, behavioral mimicry.
  • Familiarity with edge-layer LLM/GenAI guardrails (OWASP LLM Top 10, prompt injection mitigation at the WAF tier).
  • Public security research, CVE disclosures, or conference talks demonstrating original bypass work.

Education:
  • Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related technical field, or equivalent demonstrated experience.

BENEFITS:
We offer a comprehensive benefits package designed to support the health, well-being, and financial security of our employees and their families. Eligible employees may receive:
  • Health Insurance: Medical, dental, and vision coverage
  • Retirement Plans: Participation in a company-sponsored retirement savings plan.
  • Legal Service Plans: Offering access to attorneys for legal advice and representation.

If this opportunity interests you, please respond by clicking on EasyApply.


Know someone who would be perfect for this role? Refer to us and if they are hired, you could be eligible for our employee referral bonus! Help us grow our team with top talent from your network.
VARITE is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in United States vacancy
  • $195k - $240k

     ...Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations continuously...  ...cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking... 
    Suggested
    Work at office

    Datadog

    New York, NY
    4 days ago
  • $145k - $155k

     ...solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and...  ...for a security engineer to join our Offensive Security team. This team focuses on advanced... 
    Suggested
    Weekday work

    THRIVE

    New York, NY
    1 day ago
  • $150k - $165k

     ...preservation of the people and environment of the United States of America. We are seeking a highly skilled Cyber Security Engineer – Red Team (Offensive Security) – to join our Cyber Defense Team in Quantico, VA. This is a unique opportunity to work on advanced cyber... 
    Suggested
    Full time
    Contract work
    Relocation package
    Monday to Friday
    Shift work
    Day shift

    Resource Management Concepts

    Quantico, VA
    2 days ago
  •  ...About the Team We are looking for an enthusiastic Offensive Application Security Intern to join our team, where you'll conduct simulated...  ...of: C, C++, PHP, Go,x86, ARM, CAN, cryptography, reverse engineering, wireless networks Strong understanding of common web... 
    Suggested
    Full time
    Temporary work
    Part time
    Internship
    Flexible hours

    Tesla

    Austin, TX
    2 days ago
  • $135k - $236.25k

     ...communication will only be sent from @Rippling.com addresses. About The Role Rippling is looking for a hands-on Security Engineer - Offensive Security to join our growing security team. In this role, you'll design and execute offensive security initiatives that... 
    Suggested
    Work at office
    3 days per week

    Rippling

    Seattle, WA
    4 days ago
  • $40 per hour

     ...this role, you will evaluate AI-generated security content, solve technical cybersecurity...  ..., vulnerability assessments, and offensive security techniquesDesign and solve security...  ...teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    California, MO
    3 days ago
  • $293k

     ...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits...  ...the Role We're seeking an exceptional Principal-level Offensive Security Engineer to challenge and strengthen OpenAI's security posture.... 

    OpenAI

    San Francisco, CA
    14 hours ago
  • $65 - $70.42 per hour

     ...is looking for qualified WAF Adversarial Engineer WHAT THE CLIENT DOES? An American...  ...concise validation reports that translate offensive findings into testable rule candidates...  ...mitigation at the WAF tier). Public security research, CVE disclosures, or conference... 
    Contract work
    Remote work

    Varite

    United States
    6 days ago
  •  ...We are looking for experienced security engineers with an offensive security mindset that are willing to go above and beyond to help our clients defend their most critical digital assets.You'll need to go through several challenging exercises and develop complex exploits... 
    Immediate start

    Calif. , company

    Wichita, KS
    3 days ago
  • $165k - $242k

     ...You'll Do: CoreWeave's Information Security team ensures that both internal and...  ...and compliant. Our team partners with engineering and product teams to identify vulnerabilities...  .... About the role: As an Offensive Security Engineer at CoreWeave, you will... 
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Livingston, NJ
    4 days ago
  •  ...Offensive Security Engineer Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    San Mateo, CA
    4 days ago
  •  ...Offensive Security Engineer Responsibilities: # Perform manual penetration tests of network services, network infrastructure, IoT devices, and software # Clearly document and communicate findings and remediation recommendations to leadership and device/software... 

    Right Hire IT

    Detroit, MI
    14 hours ago
  •  ...your home. The Mission Praetorian is an expert-driven offensive security company. Our mission is to prevent breaches before they...  ...Looking For We are looking for an Offensive Security Engineer who operates with clear ownership. You're not just filling... 
    Internship
    Shift work

    Praetorian

    Austin, TX
    3 days ago
  • Senior Offensive Security Engineer (Application Security) Full Time Bachelors 7+ Years 3+ Locations The Company ISA Consulting is an IT company offering end-to-end solutions in Digital Transformation, Digital Consulting and Business Process Services - supporting all Tech... 
    Full time
    Work experience placement

    ISA Consulting Group

    Tampa, FL
    3 days ago
  • A leading technology company in New York is seeking a hands-on Security Engineer specializing in Offensive Security. The successful candidate will design and execute Red Team operations, driving threat-informed defense across HR, IT, Payments, Identity, and Infrastructure... 
    Work at office
    3 days per week

    Rippling

    New York, NY
    4 days ago
  • A leading technology firm in San Francisco is seeking a hands-on Security Engineer specializing in Offensive Security. This role involves designing and executing Red Team operations to assess readiness against advanced threats. Candidates should have over 2 years of experience... 
    Work at office
    3 days per week

    Rippling

    San Francisco, CA
    4 days ago
  • A leading technology company is seeking a hands-on Security Engineer - Offensive Security in Seattle. This role involves designing and executing offensive security operations, conducting threat emulations, and influencing security investment across various teams. Candidates... 

    Rippling

    Seattle, WA
    4 days ago
  • $100k - $110k

    INSPYR Solutions is seeking an Offensive Security Analyst to join their team in Deerfield Beach, FL. This hybrid position involves conducting penetration testing and building security capabilities through custom tooling and automation. The ideal candidate will possess... 

    INSPYR Solutions

    Deerfield Beach, FL
    1 day ago
  • $186.07k - $218.9k

     ...collaboration, connection, and alignment. Attendance is expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a highly skilled and experienced Penetration Tester with a... 
    Local area

    Coinbase

    Boise, ID
    3 days ago
  • $175k - $250k

     ...What Impact You'll Have Seeking experienced offensive security professionals to conduct security assessments, red team operations,...  ...offensive security certifications Experience with reverse engineering and exploit development Background in offensive cyber operations... 
    Contract work
    Work experience placement
    Immediate start

    GRVTY

    Boulder, CO
    14 hours ago
  •  ...Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting...  ...of system and network administration. Prior experience in offensive security is required. In this role, the successful candidate... 
    Work experience placement
    Local area
    Remote work

    Crane Co.

    United States
    2 days ago
  • $145k - $155k

     ...Thrive is seeking a Security Engineer to join their Offensive Security team in the United States. This role involves vulnerability management, penetration testing, and client relationship management. Ideal candidates will possess strong understanding of network protocols... 

    THRIVE

    New York, NY
    1 day ago
  •  ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Boston, Massachusetts; Washington, District of Columbia; Chicago, Illinois; Jacksonville, Florida To proceed... 
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Denver, CO
    2 days ago
  • $96k - $181k

     ...associated efforts are to promote and advance an information security processes, culture and must reflect compliance with best...  ...through proactive threat centric defense. The Senior Offensive Security Engineer is a key member of the Cyber Defense Cyber Adversary and Exposure... 
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Key Bank

    Brooklyn, OH
    2 days ago
  • $110k - $165k

     ...against the world’s most advanced cyber security adversaries? The Information Security...  ...engagements with DFIR/SOC and Detection Engineering to convert TTPs into durable detections...  ...and developing novel capabilities for offensive use. Contribute to program maturity: metrics... 
    Full time
    Remote work
    Worldwide

    Procter & Gamble

    Cincinnati, OH
    14 hours ago
  • $181k

     ...Senior Offensive Security Engineer San Francisco, CA, USA About the Role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services, applications, and infrastructure to discover security... 
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Chime

    San Francisco, CA
    20 days ago
  • $160k - $230k

     ...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers...  ...Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs, builds...  ...in Northern California, USA. SENIOR OFFENSIVE SECURITY ENGINEER As a Senior... 
    Permanent employment
    Flexible hours

    Astranis

    San Francisco, CA
    7 days ago
  •  ...Senior Offensive Security Engineer This role sits at the core of a mature offensive security function focused on simulating real-world adversaries and strengthening enterprise defenses. You will design and execute advanced red team and purple team engagements to uncover... 
    Full time
    Remote work
    Home office

    Jobgether

    United States
    4 days ago
  •  ...Offchain Labs is seeking a Security Engineer to enhance infrastructure security by conducting penetration tests and leading red team exercises...  ...building detection tools. The role requires experience in offensive security, strong knowledge of AWS, and proficiency in... 
    Remote work

    Offchain Labs

    New York, NY
    1 day ago
  • $60 per hour

     ...FocusKPI is seeking a Senior Offensive Security Engineer (Web & AI systems) to join one of our clients, a high-tech SaaS company.  Team is looking for a Senior Offensive Security Engineer to proactively identify, exploit, and help eliminate security weaknesses across... 
    Contract work
    Work at office

    FocusKPI Inc.

    Mountain View, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!