Job Requirements
Alexandria, VA
Public Trust Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Penetration Tester
We are seeking an experienced Penetration Tester to identify, exploit, and help remediate security weaknesses across applications, systems, and network infrastructure. This role executes advanced offensive security assessments, simulates adversary tactics, and delivers actionable findings to harden enterprise defenses. The ideal candidate pairs deep technical exploitation skills with strong scripting capabilities to evaluate complex environments and communicate risk effectively.
Key Responsibilities
• Offensive Security Assessments: Plan and execute comprehensive penetration tests across web applications, external/internal networks, cloud environments, and operating systems.
• Vulnerability Exploitation: Safely identify, validate, and exploit technical security flaws, logical weaknesses, and misconfigurations to measure real-world business risk.
• Red Teaming & Adversary Emulation: Simulate modern adversary tactics, techniques, and procedures (TTPs) to evaluate defensive controls and incident response detection capabilities.
• Tooling & Automation: Utilize standard penetration testing frameworks while developing custom scripts and tools to streamline assessment workflows and target specific systems.
• Technical Reporting & Remediation: Author detailed assessment reports detailing attack chains, proof-of-concept exploits, and prioritized technical remediation guidance for engineering teams.
• Stakeholder Collaboration: Partner with developers, system administrators, and security leads to debrief assessment findings and validate implemented patches through re-testing.
Qualifications Required:
• Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related field.
• Experience: 5+ years of hands-on experience conducting, supporting, or leading full-scope penetration tests.
• Core Technical Skills:
o Deep understanding of operating system internals (Windows, Linux) and network protocols (TCP/IP, HTTP/S, DNS, SMB).
o Hands-on proficiency with offensive testing frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike).
o Strong web application testing techniques (e.g., OWASP Top 10 exploitation).
o Scripting capability in Python, PowerShell, Bash, or Go for custom exploit payload delivery and automation.
Preferred Certifications:
• Offensive Security: OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), GPEN (GIAC Penetration Tester), or GWAPT (GIAC Web Application Penetration Tester).
Location: Hybrid to Alexandria, VA
Clearance: Public Trust
We are seeking an experienced Penetration Tester to identify, exploit, and help remediate security weaknesses across applications, systems, and network infrastructure. This role executes advanced offensive security assessments, simulates adversary tactics, and delivers actionable findings to harden enterprise defenses. The ideal candidate pairs deep technical exploitation skills with strong scripting capabilities to evaluate complex environments and communicate risk effectively.
Key Responsibilities
• Offensive Security Assessments: Plan and execute comprehensive penetration tests across web applications, external/internal networks, cloud environments, and operating systems.
• Vulnerability Exploitation: Safely identify, validate, and exploit technical security flaws, logical weaknesses, and misconfigurations to measure real-world business risk.
• Red Teaming & Adversary Emulation: Simulate modern adversary tactics, techniques, and procedures (TTPs) to evaluate defensive controls and incident response detection capabilities.
• Tooling & Automation: Utilize standard penetration testing frameworks while developing custom scripts and tools to streamline assessment workflows and target specific systems.
• Technical Reporting & Remediation: Author detailed assessment reports detailing attack chains, proof-of-concept exploits, and prioritized technical remediation guidance for engineering teams.
• Stakeholder Collaboration: Partner with developers, system administrators, and security leads to debrief assessment findings and validate implemented patches through re-testing.
Qualifications Required:
• Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related field.
• Experience: 5+ years of hands-on experience conducting, supporting, or leading full-scope penetration tests.
• Core Technical Skills:
o Deep understanding of operating system internals (Windows, Linux) and network protocols (TCP/IP, HTTP/S, DNS, SMB).
o Hands-on proficiency with offensive testing frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike).
o Strong web application testing techniques (e.g., OWASP Top 10 exploitation).
o Scripting capability in Python, PowerShell, Bash, or Go for custom exploit payload delivery and automation.
Preferred Certifications:
• Offensive Security: OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), GPEN (GIAC Penetration Tester), or GWAPT (GIAC Web Application Penetration Tester).
Location: Hybrid to Alexandria, VA
Clearance: Public Trust
group id: 91130095