998,188open jobs
59,534companies
165,604added this week
Browse all
Salary
$170k – $250k per year
Location
In office (Chicago)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 10, 2026. mcmastercarr.com scores D on the Alion truth index.

Overview
Company
Impact
Profile match

Who We Are

McMaster-Carr is a leading e-commerce company that industrial customers have trusted for 125 years. Our products help them get manufacturing lines back up quickly, keep operations running smoothly, and prototype the next generation of innovative solutions. We earn and keep that trust by offering the right products, making them easy to find, and delivering them fast, so customers can solve problems with greater speed, precision, and ease.

Our industry-leading e-commerce experience, indispensable product selection, and world-class service bring hundreds of thousands of customers to mcmaster.com each day. But we're never standing still. Curious, exceptional people are at the heart of our evolution. They turn new challenges and disruptive technologies into opportunities to refine our operations, expand our offering, and deliver a better experience for every customer.

What you will do

McMaster-Carr is seeking a Senior Offensive Security Engineer to build and operate an independent security assurance capability within Internal Audit. Using penetration testing, adversary emulation, and purple-team techniques, you will evaluate whether our cybersecurity controls work as intended against realistic scenarios.

This is not a conventional penetration-testing role focused only on finding vulnerabilities. As a member of McMaster-Carr’s Internal Audit team, your work will help determine whether controls prevent attacks, whether monitoring produces meaningful alerts, whether response processes work, and where security investments should be strengthened. You will translate technical findings into practical risk insight and solutions for Information Security, business leaders, executive management, and the Audit Committee.

Work is independent yet collaborative with strong governance. You will partner closely with Information Security while remaining organizationally independent from the teams responsible for designing and operating the controls you assess.

  • Design and execute risk-based penetration tests, assumed-breach exercises, adversary simulations, and purple-team engagements across enterprise systems, applications, networks, identity platforms, and cloud environments.
  • Test whether preventive, detective, and responsive security controls perform as expected under realistic attack Evaluate attack paths, control weaknesses, detection coverage, alert quality, and the effectiveness of incident-response procedures.
  • Collaborate with Security Operations and other technical teams during purple-team exercises to validate detection and response
  • Develop test plans, objectives, techniques, targets, safeguards, and rules of engagement for management approval before execution.
  • Translate technical findings into risk-based remediation recommendations that help leaders of technical teams, Internal Audit leadership, executive management and the Audit Committee prioritize security improvements and
  • Build a repeatable, continuously improving offensive-security assurance program informed by a growing understanding of our environment.
  • Partner with external security firms when specialist expertise or independent corroboration is

 

Who You Are

We are seeking bright, curious, and ambitious individuals eager to make an impact. Ideal candidates have:

  • 5+ years of relevant offensive security experience, including at least three recent years conducting penetration tests, red team engagements adversary emulation exercises, or purple team assessments in complex military or civilian environments. 
  • A four-year college degree
  • Demonstrated ability to independently scope, plan, execute, document, and clearly communicate technically sophisticated security assessments to both engineering and executive-level audiences.
  • Broad knowledge of enterprise attack surfaces, including hands-on experience with several of the following domains: identity systems (LDAP, IAM), operating systems (Windows and Linux), network infrastructure, cloud platforms, web applications and APIs, endpoint systems, and security monitoring tools.
  • Practical experience identifying and validating exploitable attack chains, bypassing or testing security controls, and determining whether detection and response mechanisms function as intended.
  • Strong scripting or automation skills and the ability to adapt tools and techniques to assess unfamiliar environments effectively.
  • Ability to operate safely and effectively in production-sensitive environments while maintaining strict adherence to rules of engagement and approved scope.
  • Sound judgment, discretion, and a disciplined approach to handling privileged information and sensitive findings.
  • Excellent written and verbal communication skills that translate technical weaknesses into clear business impact and remediation priorities for both engineers and senior leaders.
  • A collaborative style that builds trust with Security and Systems teams while maintaining the objectivity required of an independent assurance function.
  • A track record of taking initiative, identifying high-impact areas for investigation, and driving work through remediation and retesting.

Compensation

Total cash compensation generally ranges from $170,000-$250,000 and includes profit sharing based on company performance. 

Growth & Learning

  • 100% tuition reimbursement
  • Informal and formal mentorship
  • Employee resource groups

Health & Wellbeing

  • Medical, dental, pharmacy and vision plans without monthly premiums
  • Inclusive, all-gender benefits

Family & Future

  • Paid parental leave for all new parents
  • Adoption and surrogacy assistance
  • First-time home buyer assistance
  • Industry-leading company-funded retirement accounts

Time Off

  • Paid vacation and personal time

Equal Opportunity Employer

We are proud to be an Equal Opportunity Employer and dedicated to providing employees a workplace with reasonable accommodations and free of discrimination, harassment, and retaliation. At McMaster-Carr, we do not make employment decisions based on age, ethnicity, citizenship status, military status, gender identity and expression, race, religion, disability status, marital status, sexual orientation, or any other legally protected group.

This position is not eligible for work authorization sponsorship by McMaster-Carr.

Data We Collect

We may collect professional, education and employment-related data, and any assessments made throughout the recruiting process, to evaluate candidacy for employment. To communicate with job applicants, we may collect applicant names, contact information, and other personal identifiers, including those outlined in the California customer records statute. Through voluntary disclosure, we may also collect protected classifications under federal or California law (e.g., race, gender, etc.). For additional details about the personal information we collect and its uses, please click  here.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
998,188 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Chicago
≈ $70k – $145k per year (Estimated) • In office • Full-Time • 3+ years exp • Associate's Degree • Greensboro
Management
Microsoft Office
Apply
≈ $105k – $207k per year (Estimated) • In office • 6+ years exp • Atlanta
DevOps
Azure
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
DLP
Apply
≈ $108k – $212k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Atlanta
DevOps
GCP
Azure
AWS
Cybersecurity
Zero Trust
Apply
$200k – $290k per year • Remote (United States) • Full-Time
DevOps
AWS
IAM
Cybersecurity
NIST 800-171
Apply
DevSecOps Engineer 2 days ago
$132k – $202k per year • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • New York
Python
JavaScript
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Kubernetes
Bicep
GitHub
Cybersecurity
Snyk
ISO 27001
Open Policy Agent
Wiz
MITRE ATT&CK
OWASP Top 10
SOC 2
HIPAA
Threat Modeling
Dependabot
Sysdig Secure
Apply
$87k – $144k per year • In office • Full-Time • 5+ years exp • New York
Java
SQL
COBOL
Java
Apache Tomcat
COBOL
IBM MQ
Databases
Db2
Oracle
MS SQL
Apache Kafka
DevOps
GCP
Red Hat
Helm
Azure
CI/CD
Windows Server
AWS
Docker
Kubernetes
Service Mesh
Amazon S3
Linux
Unix
Cybersecurity
HashiCorp Vault
LDAP
QA
Swagger
Apply
SREエンジニア 7 days ago
$505k – $684k per year • In office • South Korea
Python
Go
JavaScript
Kotlin
TypeScript
Databases
PostgreSQL
DynamoDB
Frontend
Vue.js
Nuxt.js
DevOps
Terraform
GitHub Actions
CI/CD
AWS
AWS Fargate
GitHub
GitLab
Amazon ECS
Linux
Management
Confluence
Apply
Software Engineer 7 days ago
$113k – $154k per year • Hybrid • 3+ years exp • Bachelor's Degree • Raleigh
Python
AI/ML
Copilot
Cursor
Claude Code
KServe
DevOps
Red Hat
OpenShift
Azure
CI/CD
AWS
Kubernetes
AIOps
Linux
Apply
≈ $76k – $140k per year (Estimated) • In office • Full-Time • 5+ years exp • Bogotá
DevOps
Windows
Apply
Remote (North America) • Full-Time • New York
DevOps
New Relic
Datadog
Dynatrace
PagerDuty
Docker
Cloudflare
GitHub
GitLab
Linux
Cybersecurity
Snyk
Aqua Security
Veracode
Sonatype Nexus IQ
Mend
Marketing
HubSpot
Apply
$123k – $142k per year • In office • 5+ years exp • Atlanta
Apply
$120k – $138k per year • In office • 5+ years exp • Bachelor's Degree • Chicago
Apply
$120k – $138k per year • Remote (United States) • 3+ years exp • Bachelor's Degree • Fort Worth
Apply
Customer Solutions 17 days ago
$106k – $122k per year • In office • Bachelor's Degree • Cleveland
Apply
$96k – $109k per year • In office • Bachelor's Degree • Cleveland
Apply
$78k – $108k per year • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Chicago
Cybersecurity
HIPAA
Management
Outlook
Apply
≈ $109k – $210k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • Louisville • Charlotte • Tampa • Fort Lauderdale • Washington
Cybersecurity
HIPAA
Apply
≈ $37k – $78k per year (Estimated) • Hybrid • 2+ years exp • Bachelor's Degree • Chicago
Analytics
Microsoft Excel
Management
Microsoft Office
Apply
$117k – $175k per year • Equity • In office • Full-Time • 5+ years exp • Chicago • Victoria • Toronto • Calgary • Montreal
Java
C#
C#
.NET
Apply
Data Scientist 1 day ago
$105k – $124k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Minneapolis • Atlanta • Chicago • Charlotte
Python
SQL
SAS
Databases
Databricks
AI/ML
Machine Learning
DevOps
Azure
Linux
Apply
See all jobs
This is one of many
998,188 more open roles from verified company boards, updated every day.