Talent.com
Offensive Security Engineer II

Offensive Security Engineer II

Finance of America Holdings LLCConshohocken, PA, US
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Job Description

Job Description

About Us

At Finance of America, we help homeowners unlock the joy that comes from realizing the full potential of their retirement. Many people have significant wealth tied up in their homes and want to use it meaningfully in their next chapter. Our unique range of reverse mortgages allow homeowners 55+ to access that wealth while maintaining control over their home and financial future. With options tailored to their unique goals, we provide the financial flexibility they need to move forward with confidence.

Finance of America is guided by five values : We are customer obsessed, they are why we exist. We raise the bar. We take extreme ownership. We practice genuine collaboration. And we unleash our excellence. Together we are actualizing our vision to be the most beloved brand for homeowners in their next chapter.

To learn more about us, visit www.financeofamerica.com

Purpose of Role

Responsible for application security testing, adversary simulation, and cloud security research with a strong emphasis on adaptability and security. Researches new threat scenarios and works alongside the blue teams to validate defenses.

Key Responsibilities and Expectations

  • Conducts penetration tests and threat simulations across applications, infrastructure, and cloud environments (AWS and Azure).
  • Performs application security reviews, including secure code review and SAST / DAST configuration in CI / CD pipelines.
  • Supports red and purple team exercises, using tactics aligned with the MITRE ATT&CK framework, to measure and improve SOC readiness.
  • Researches and tests emerging threats, vulnerabilities, and exploitation techniques, including those targeting cloud and AI / ML applications.
  • Partners with development, cloud, and SOC teams to communicate risks and recommend practical remediation strategies.
  • Creates or adapts custom offensive tools and scripts to support testing scenarios.
  • Documents and clearly communicates technical findings to both technical and non-technical audiences.
  • Conducts security research and attends trainings, conferences, and capture-the-flag (CTF) events.
  • Performs other duties as assigned.

Reports To

  • Director, Vulnerability Management and Discovery
  • Qualifications - Experience / Skills / Competencies

  • Minimum 3 years of experience in offensive security, penetration testing, or application security.
  • Proficiency in web application security testing (e.g., OWASP Top 10, business logic flaws, authentication / authorization bypasses).
  • Familiarity with cloud security testing in AWS (IAM, S3, EC2, Lambda, etc.); exposure to Azure strongly preferred.
  • Knowledge of AI / ML application security testing, including risks such as prompt injection, data poisoning, and model extraction preferred.
  • Scripting proficiency in Python (preferred), PowerShell, or Bash.
  • Strong understanding of operating systems (Linux, Windows, MacOS) and networking protocols.
  • Experience with CI / CD pipeline security integration (e.g., Azure DevOps, GitHub Actions).
  • Exposure to adversary simulation tooling (e.g., C2 frameworks like Cobalt Strike, Sliver, Mythic).
  • Familiarity with the MITRE ATT&CK framework and its application to offensive testing.
  • Certifications such as OSCP, OSWE, OSEP, GXPN, or CRTO preferred.
  • Prior experience collaborating with SOC and IR teams in purple team exercises.
  • Strong written and verbal communication skills, with the ability to explain technical findings clearly to developers, engineers, and non-technical stakeholders.
  • Ability to exercise judgment when policies or precedents are incomplete or not well-defined.
  • Self-motivated, driven, and passionate about cybersecurity, with a continuous learning mindset.
  • Qualifications - Education - Required

  • Bachelor's Degree or comparable qualifications
  • Qualifications - Education - Field(s) / Profession(s)

  • Computer Science, Cybersecurity, or related field.
  • Compensation

    The base salary range for this position is ($85,300 - $142,100) inclusive of all geographical differences in the labor market. The base salary for the position will be determined based on factors such as the candidate’s work location, skills, education, and experience. In addition to those factors, we believe in the importance of pay equity and consider the internal equity of our current team members in determining any final offer. We offer a competitive benefits package including health, dental, vision, life insurance, paid time-off benefits, flexible spending account, 401(k) with employer match, and ESPP.

    Additional Information

    The application deadline for this job opportunity is 11 / 3 / 2025.

    The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified.

    Finance of America is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, sex (including pregnancy), sexual orientation, religion, creed, age, national origin, physical or mental disability, gender identity and / or expression, marital status, veteran status or other characteristics protected by law.

    serp_jobs.job_alerts.create_a_job

    Security Engineer Ii • Conshohocken, PA, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    VirtualVocationsNewark, Delaware, United States
    serp_jobs.job_card.full_time
    A company is looking for a FIPS 140 Security Engineer to support national defense through IT security projects.Key Responsibilities Work on varied FIPS 140 validation projects including general s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Information Systems Security Engineer III

    Information Systems Security Engineer III

    Armada LtdPhiladelphia, PA, USA
    serp_jobs.job_card.full_time +1
    serp_jobs.filters_job_card.quick_apply
    Philadelphia, PA (Travel - CONUS locations, less than 5%).CONTINGENT UPON AWARD • • • • • • • • • • • • • • •.Duties & Responsibilities : . The Information Systems Security Engineer III (ISSE III) shall assist w...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Information System Security Engineer (ISSE) III

    Information System Security Engineer (ISSE) III

    Diligent Consulting IncPhiladelphia, PA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Information System Security Engineer (Contingent Upon Award) Hiring Company : Diligent Consulting Inc.Naval Surface Warfare Center, Philadelphia Division (NSWCPD) Location : Philadelphia, PA Clearanc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    VirtualVocationsNewark, Delaware, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer to join their cybersecurity team.Key Responsibilities Administer and maintain identity providers and manage endpoint protection platforms Monitor and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    PAM Security Engineer

    PAM Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM / PAM Security Engineer to implement cybersecurity strategies for protecting digital identities within a federal agency's IT environment.Key Responsibilities Imple...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cloud Security Engineer to join their team.Key Responsibilities Manage enterprise-wide security tools and platforms, including SIEM, DLP, and vulnerability manag...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    IAM Security Architect

    IAM Security Architect

    VirtualVocationsNewark, Delaware, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM and Security Services Architect.Key Responsibilities Define IAM and security services architecture roadmap, standards, and reference models Architect identity sol...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Systems Security Engineer II

    Information Systems Security Engineer II

    Armada LtdPhiladelphia, PA, US
    serp_jobs.job_card.full_time +1
    Philadelphia, PA (Travel - CONUS locations, less than 5%).Duties & Responsibilities : .The Information Systems Security Engineer II (ISSE II) shall assist with the developing, maintaining, and tr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Engineer to join their Information Security and Technology team.Key Responsibilities Drive decision-making for platform and application security a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocationsNewark, Delaware, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior / Staff Security Engineer to enhance and secure its corporate infrastructure.Key Responsibilities Design, implement, and manage security for corporate endpoints an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Software Engineer

    Senior Security Software Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Software Engineer.Key Responsibilities Develop and maintain embedded software with a focus on security Implement and manage security protocols and auth...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Information System Security Engineer III

    Information System Security Engineer III

    CenturiaPhiladelphia, Pennsylvania, United States, 19102
    serp_jobs.job_card.temporary
    Job Title : Information System Security Engineer (ISSE) III.Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions to the F...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Engineer, IDAM

    Security Engineer, IDAM

    VirtualVocationsNewark, Delaware, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, IDAM Operations.Key Responsibilities Manage user access provisioning and resolve access issues Support complex application account provisioning and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Tanium Security Engineer

    Senior Tanium Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Tanium Security & Asset Visibility Engineer.Key Responsibilities Implement cybersecurity and IT asset lifecycle management strategies Protect digital networks, ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Information Systems Security Engineer II (ISSE II)

    Information Systems Security Engineer II (ISSE II)

    Dynamic Solutions Technology LLCPhiladelphia, PA, US
    serp_jobs.job_card.full_time +1
    Dynamic Solutions Technology, LLC.IT and Service needs for commercial and government clients, is seeking a full-time.Information Systems Security Engineer II (ISSE II). This position is an exempt ro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Border Patrol Agent

    Border Patrol Agent

    U.S. Customs and Border ProtectionBechtelsville, PA, United States
    serp_jobs.job_card.full_time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityPhiladelphia, PA, United States
    serp_jobs.job_card.full_time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityPhiladelphia, PA, United States
    serp_jobs.job_card.full_time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30