FewerJobs.
All jobs

Offensive Cybersecurity Operator

Department of Homeland Security - Multiple Locations

Posted Jun 2, 2026

Benefits

Parental leave
Not verified
Non-birth-parent leave
Not verified
Family-building benefits
  • Fertility benefits: Not verified
  • Adoption assistance: Not verified
  • Surrogacy assistance: Not verified
Mental health support
Not verified
Relocation assistance
Not verified
Childcare support
Not verified
Learning budget
Not verified
Verification
Not verified
Salary
$91K-$140K From the posting source checked Jun 20, 2026

Was this benefit information wrong? Tell us.

Market context

U.S. role benchmark (BLS OEWS)
$116,543 U.S. median for this role
Projected growth (BLS Employment Projections)
+9.8% - Much faster than average

About in line with the BLS role benchmark for software engineering aggregate.

Matched to SOC 15-1252 - Software Engineering aggregate by role bucket.

Source: U.S. Bureau of Labor Statistics, OEWS, May 2024 and Employment Projections, 2024-2034.

Role

Role function
Engineering From the posting source checked Jun 20, 2026
Seniority
Mid From the posting source checked Jun 20, 2026

Schedule

Shift type
Not verified
Weekend work
Not verified

Application

Cover letter
Not verified
Assessment
Required From the posting source checked Jun 20, 2026
Deadline
Jun 18, 2026 From the posting source checked Jun 20, 2026

Where they hire

Hires in: FL, VA From the posting source checked Jun 20, 2026

About this role

Offensive Cybersecurity Operator Multiple Locations Summary This announcement is issued under the Direct Hire Authority (DHA) to recruit for positions for which there is a critical hiring need. Selectee(s) will receive a career or career-conditional appointment in the competitive service and may be required to serve a one-year probationary period. The official title of this position is Information Technology Cybersecurity Specialist (INFOSEC) GS-2210-13/14. Duties You will plan and execute authorized offensive security engagements that show federal and critical infrastructure partners exactly how a real adversary would attempt to breach them, emulating threat-actor tradecraft against enterprise networks and cloud tenants, and then briefing leaders on how to prioritize fix actions. Typical work assignments at the full performance level include, but are not limited to: Lead full-lifecycle red team and penetration-test engagements against federal enterprise networks, cloud tenants (AWS / Azure / GCP), containerized and serverless workloads, web applications, and CI/CD pipelines - owning scoping, rules of engagement, operator tasking, deconfliction, and final reporting. Emulate real-world threat actors - design and run ATT&CK-aligned operations that chain initial access, identity/IAM abuse, privilege escalation, and lateral movement to reach crown-jewel systems, then prove impact without causing harm. Build and operate offensive infrastructure as code - stand up and tear down C2, redirectors, phishing, and lab/range environments repeatably with Terraform, Ansible, or comparable tooling, with disciplined OPSEC. Develop and extend offensive tooling - custom payloads, C2 profiles, exploit adaptations, and AI/LLM-augmented recon, code-review, and triage workflows - and feed that tradecraft back into team capability.

Read the full description at www.usajobs.gov. FewerJobs shows a preview and links to the original posting.

Apply at usajobs.gov

Apply link not verified; last-live date unavailable.

What verified means

Verified means a displayed claim has field-level provenance to a source FewerJobs pulled: a government or employer source, or the original job posting. Posting-sourced facts are employer-stated and are labeled separately from government records.

Related jobs