Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management

Rohde & Schwarz

Maryland

On-site

USD 96,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Rohde & Schwarz is seeking a Cybersecurity Engineer – Offensive Security to identify, validate, and reduce risk across critical systems in North America. You will lead vulnerability management, conduct authorized pen tests, and support security testing across Linux, Windows, IP networks, VoIP, and embedded devices.

The role requires on-site work in Frederick, MD, citizenship, and collaboration with global teams.

Qualifications

  • BS degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical field. Master’s degree preferred.
  • 7+ years of relevant cybersecurity, penetration testing, vulnerability management, or security engineering experience.
  • Strong understanding of vulnerability assessment, penetration testing, attack methodologies, and remediation practices.
  • Hands-on experience with security tools such as Nessus, Nmap, Wireshark, Burp Suite, Metasploit, or comparable tools.
  • Strong knowledge of TCP/IP networking, routing, switching, VLANs, firewalls, ACLs, network segmentation, and common network protocols.
  • Working knowledge of Linux and Windows security and system hardening.
  • Experience analyzing CVEs, security advisories, vulnerability scan results, and technical security findings.
  • Ability to distinguish theoretical vulnerabilities from vulnerabilities that present meaningful risk within a specific system architecture.
  • Experience documenting findings, assigning risk, developing remediation recommendations, and communicating results to engineering teams.
  • Knowledge of NIST SP 800-53, NIST CSF, DISA STIGs, CIS Benchmarks, or similar security frameworks.
  • Scripting experience using Python, PowerShell, Bash, or similar languages.

Responsibilities

  • Perform vulnerability assessments of systems, networks, applications, operating systems, COTS products, appliances, and embedded devices.
  • Plan, coordinate, and perform authorized penetration testing and security validation activities within controlled laboratory and customer environments.
  • Identify security weaknesses, attack paths, insecure configurations, exposed services, and potential control deficiencies.
  • Perform vulnerability scanning using tools such as Nessus, Nmap, and other approved security assessment tools.
  • Analyze CVEs and vendor security advisories to determine applicability, exploitability, operational impact, and remediation requirements.
  • Develop vulnerability assessment reports, technical findings, risk ratings, remediation recommendations, and supporting evidence.
  • Maintain and improve vulnerability tracking and remediation processes throughout the system lifecycle.
  • Validate remediation activities and verify that identified vulnerabilities have been appropriately mitigated.
  • Perform network and protocol analysis using tools such as Wireshark and related diagnostic/security tools.
  • Support security testing of IP networks, firewalls, switches, routers, Linux and Windows systems, VoIP systems, applications, and embedded devices.
  • Evaluate system attack surfaces, trust boundaries, data flows, interfaces, authentication mechanisms, and externally accessible services.
  • Participate in threat modeling, attack-path analysis, misuse-case development, and security architecture reviews.
  • Work with engineering and R&D teams to reproduce security findings and develop practical remediation solutions.
  • Support incident response, forensic analysis, and investigation activities when required.
  • Contribute to System Security Plans, security assessment reports, risk assessments, customer documentation, and other cybersecurity deliverables.
  • Support FAT, SAT, customer deployments, onsite assessments, and witness testing.
  • Develop scripts, tools, and repeatable methodologies to improve vulnerability assessment, security testing, evidence collection, and reporting.
  • Research emerging threats, vulnerabilities, exploitation techniques, and defensive technologies relevant to Rohde & Schwarz products and customer environments.
  • Collaborate with cybersecurity, product, and engineering teams in Europe and North America.
  • Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.

Skills

Vulnerability testing
Penetration testing
Nessus
Nmap
Wireshark
Burp Suite
Metasploit
TCP/IP networking
Linux security
Windows security
CVEs analysis
Security frameworks
Scripting (Python/PowerShell)

Education

BS degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related field
Master's degree preferred

Tools

Nessus
Nmap
Wireshark
Burp Suite
Metasploit

Job description

The Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management plays a critical role in identifying, validating, and reducing cybersecurity risk across mission-critical systems delivered by Rohde & Schwarz North America. This position will serve as a versatile member of the U.S. cybersecurity organization while providing primary expertise in vulnerability management, penetration testing, security assessment, and offensive security. The engineer will evaluate systems, networks, products, and COTS components for security weaknesses; determine the applicability and impact of vulnerabilities; validate security controls; and work directly with engineering teams to develop practical remediation strategies. While Offensive Security and Vulnerability Management will be the position's primary area of specialization, the successful candidate will also support broader cybersecurity activities including secure architecture, compliance, system hardening, product security, security testing, documentation, patch management, and customer/program support. Initially, the position will support Air Traffic Control (ATC) programs, with the opportunity to support additional Rohde & Schwarz products, programs, and business areas as the North American cybersecurity capability grows. This role requires being on site in our Frederick, MD facility and requires US citizenship.

Your tasks
  • Perform vulnerability assessments of systems, networks, applications, operating systems, COTS products, appliances, and embedded devices.
  • Plan, coordinate, and perform authorized penetration testing and security validation activities within controlled laboratory and customer environments.
  • Identify security weaknesses, attack paths, insecure configurations, exposed services, and potential control deficiencies.
  • Perform vulnerability scanning using tools such as Nessus, Nmap, and other approved security assessment tools.
  • Analyze CVEs and vendor security advisories to determine applicability, exploitability, operational impact, and remediation requirements.
  • Develop vulnerability assessment reports, technical findings, risk ratings, remediation recommendations, and supporting evidence.
  • Maintain and improve vulnerability tracking and remediation processes throughout the system lifecycle.
  • Validate remediation activities and verify that identified vulnerabilities have been appropriately mitigated.
  • Perform network and protocol analysis using tools such as Wireshark and related diagnostic/security tools.
  • Support security testing of IP networks, firewalls, switches, routers, Linux and Windows systems, VoIP systems, applications, and embedded devices.
  • Evaluate system attack surfaces, trust boundaries, data flows, interfaces, authentication mechanisms, and externally accessible services.
  • Participate in threat modeling, attack-path analysis, misuse-case development, and security architecture reviews.
  • Work with engineering and R&D teams to reproduce security findings and develop practical remediation solutions.
  • Support incident response, forensic analysis, and investigation activities when required.
  • Contribute to System Security Plans, security assessment reports, risk assessments, customer documentation, and other cybersecurity deliverables.
  • Support Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), customer deployments, onsite assessments, and witness testing.
  • Develop scripts, tools, and repeatable methodologies to improve vulnerability assessment, security testing, evidence collection, and reporting.
  • Research emerging threats, vulnerabilities, exploitation techniques, and defensive technologies relevant to Rohde & Schwarz products and customer environments.
  • Collaborate with cybersecurity, product, and engineering teams in Europe and North America.
  • Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.
Your Qualifications
  • BS degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field. Master's degree preferred.
  • 7+ years of relevant cybersecurity, penetration testing, vulnerability management, network security, or security engineering experience.
  • Strong understanding of vulnerability assessment, penetration testing, attack methodologies, and remediation practices.
  • Hands-on experience with security tools such as Nessus, Nmap, Wireshark, Burp Suite, Metasploit, or comparable tools.
  • Strong knowledge of TCP/IP networking, routing, switching, VLANs, firewalls, ACLs, network segmentation, and common network protocols.
  • Working knowledge of Linux and Windows security and system hardening.
  • Experience analyzing CVEs, security advisories, vulnerability scan results, and technical security findings.
  • Ability to distinguish theoretical vulnerabilities from vulnerabilities that present meaningful risk within a specific system architecture and operating environment.
  • Experience documenting findings, assigning risk, developing remediation recommendations, and communicating results to engineering teams.
  • Knowledge of NIST SP 800-53, NIST CSF, DISA STIGs, CIS Benchmarks, or similar security frameworks.
  • Strong analytical, troubleshooting, documentation, and technical communication skills.
  • Experience working in laboratory or controlled test environments preferred.
  • Familiarity with mission-critical, safety-critical, aviation, transportation, defense, or critical infrastructure systems preferred.
  • Familiarity with IP networking, VoIP/SIP/RTP, RF communications, embedded systems, PLCs, appliances, and related technologies is beneficial.
  • Cybersecurity certifications such as OSCP, GPEN, GCIH, GWAPT, PNPT, CISSP, Security+, or similar are preferred.
  • Scripting experience using Python, PowerShell, Bash, or similar languages is beneficial.
  • In order to be considered, candidates must be a U.S. citizen or permanent resident able to obtain an interim or final suitability determination, subject to completion and favorable adjudication of the required background investigation.

The total compensation for this position is $96K-$130K. Total compensation includes base salary, variable pay (when applicable) plus benefits. The range is determined by the position, geographic location and level. Individual pay within the range is determined by several factors including location, education or training, relevant work history, sales incentive structure and job-related skills.

Rohde & Schwarz is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age or any other characteristic protected by law.

Rohde & Schwarz is a global technology company with approximately 14,000 employees and three divisions: Test & Measurement, Technology Systems and Networks & Cybersecurity. For 90 years, the company has been developing cutting-edge technology, pushing the boundaries of what is technically possible and enabling customers from various sectors such as business, government and public authorities to maintain their technological sovereignty.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer – Patch Management, Testing & Automation
Cybersecurity Engineer – Patch Management, Testing & Automation

Rohde & Schwarz • Maryland

On-site
USD 96,000 - 130,000
Cybersecurity Engineer, Governance & Compliance - Frederick, MD
Cybersecurity Engineer, Governance & Compliance - Frederick, MD

Rohde & Schwarz • Maryland

On-site
USD 96,000 - 130,000
Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management
Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management

Rohde & Schwarz (China) Technology Co., Ltd. • Frederick (MD)

On-site
USD 100,000 - 140,000
Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management
Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management

ROHDE & SCHWARZ GmbH & Co. KG • Frederick (MD)

On-site
USD 95,000 - 140,000
Technical Project Lead - Frederick, MD
Technical Project Lead - Frederick, MD

Rohde & Schwarz • Maryland

On-site
USD 112,000 - 150,000
IT Infrastructure Engineer - Columbia, MD
IT Infrastructure Engineer - Columbia, MD

Rohde & Schwarz • Columbia (MD)

On-site
USD 96,000 - 130,000
Flexible working hours
Training & continuing education
Privately owned company
+2
Systems Engineer – Defense, Security, & Critical Infrastructure - Columbia, MD
Systems Engineer – Defense, Security, & Critical Infrastructure - Columbia, MD

Rohde & Schwarz • Columbia (MD)

On-site
USD 90,000 - 120,000
Flexible working hour models
Training & continuing education
Privately owned company
Systems Engineering Manager, ATC and FAA - Frederick, MD
Systems Engineering Manager, ATC and FAA - Frederick, MD

Rohde & Schwarz • Maryland

On-site
USD 165,000 - 200,000
Offensive Security Engineer: Pen Testing & Vuln Mgmt
Offensive Security Engineer: Pen Testing & Vuln Mgmt

Rohde & Schwarz • Maryland

On-site
USD 96,000 - 130,000
Cybersecurity Engineer: Offensive Security & Pen Testing
Cybersecurity Engineer: Offensive Security & Pen Testing

ROHDE & SCHWARZ GmbH & Co. KG • Frederick (MD)

On-site
USD 95,000 - 140,000