Senior Information Security Engineer, Offensive Security at GRVTY
San Antonio, TX
—
Jul 19, 2026
San Antonio, TX
Jul 21, 2026
What this job asks for AI summary
A hands-on offensive security role focused on conducting penetration tests, red team operations, and network exploitation assessments for clients, then communicating findings through written reports and briefings. The position also involves analyzing malware and security tools, building scripts to support operations, and mentoring junior staff. It suits experienced practitioners with a background in offensive cyber operations who can obtain a TS/SCI with polygraph.
Senior level · 3+ years · National · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
Location is not specified in the posting; the company (GRVTY) appears to be US-based (703 area code, national security focus), but no city or metro is stated. Remote is unlikely given the TS/SCI with polygraph requirement and classified operations context.
Clearance gate: the JD states candidates 'must be able to obtain and maintain an Active TS/SCI with poly' — this is a hard gate on the ability to obtain TS/SCI with polygraph. A currently active TS/SCI with poly is listed under 'Nice to Have', suggesting it is preferred but not strictly required at hire.
Degree requirement: the JD accepts either a Bachelor's in CS/related field OR 5 years of direct work experience as an equivalent substitute, so no degree is hard-required.
The 3-year minimum experience requirement is stated explicitly; the 5-year figure applies only as a degree substitute, not as a separate role-level gate.
SOC classification is Medium confidence: the role is primarily offensive security / red team operations (15-1212), but the scripting/tool development and exploit development components introduce a meaningful software development dimension (15-1252).
Scripting and tool development are called out as required responsibilities ('develop scripts and tools to improve operational efficiency') but no specific language or framework is named, so 'scripting' is captured as a generic required skill.
OSCP and GXPN certifications appear under 'What Would be Nice to Have' and are preferred, not required.
Ignored 4 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): packet analysis, malware analysis, reverse engineering, exploit development.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.