×
Register Here to Apply for Jobs or Post Jobs. X

Security Software Engineer – Red Team Penetration Tester

Job in Dahlgren, King George County, Virginia, 22448, USA
Listing for: RPI Group
Full Time position
Listed on 2026-09-06
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Security Management & Operations
Job Description & How to Apply Below

Security Software Engineer – Red Team Penetration Testers

RPI Group is seeking a skilled, driven Security Software Engineer to support Red Team penetration testing for a mission-focused Navy customer. If you are energized by complex technical challenges, enjoy finding and analyzing security weaknesses, and want your work to inform real-world defensive decisions, this role is for you.

What We're Looking For

Five (5) years experience in:

  • Linux – firm grasp/demonstrated knowledge
  • Associated Training: COMPTIA Linux+ or FedVTE Linux+
  • Windows – foundational knowledge with good understanding of enterprise networks
  • Associated Training:
    Microsoft course (MCSA; Various)

Strong working knowledge of common Penetration Testing (PENTEST) tools:

  • Kali, Metasploit, NMAP, Cobalt Strike
  • Associated Training:
    Certified Ethical Hacker or Offensive Security Certified Professional and;

Documented experience in at least one of the following:

  • Penetration Testing (PENTEST) (government or contractor)
  • Red Team Operations (government or contractor)
  • Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties)
  • Programming languages:
    Python, C, C Sharp, C++, Go, Perl, Powershell

Web Dev/Web App Dev/Web Penetration testing

  • NSX, vCenter, vRealize Suite, Horizon View (VDI) and others
  • PAN-OS
  • Fire Power, Nexus, IOS, ASA
  • ONTAP, Snap Mirror
  • Active-Directory
  • Entra  (Azure AD), Active Directory, SSO, MFA, Azure application integration, Identity Federation.
  • Automation using Powershell, Power Automate, Logic Apps, Graph API.
  • Microsoft Entra  Microsoft 365 in a hybrid environment.
  • Experience with Palo Alto, Cisco, VMWare, Net App and Microsoft products.
  • Extending or integrating on premises AD with Entra .
  • Managing identity and access in Microsoft Entra  conducting Red Team operations in an MDE environment.
  • Experience with AWS, Cloud Audit, Serverless and Microservice Architecture
  • Experience working with AWS services (such as EC2, S3, KMS, RDS) and security best practices relevant to those services
  • Experience with Web Services penetration testing (RESTful and SOAP) Web Authentication protocols (e.g. OAuth2, SAML, LDAP)
  • PHP, ASP, SQL db's, Java, HTML, No SQL

Minimum certification as IAT Level II per DoD 8570.01, or successor.

Minimum certification as penetration tester and possess one of the following certificates:

  • Offensive Security Certs:
    Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), Offensive Security Wireless Professional (OSWP)
  • SANS Certs: SEC
    560 - Network Penetration Testing and Ethical Hacking (GPEN Certification), SEC
    542 - Web App Penetration Testing and Ethical Hacking (GWAPT Certification), SEC
    660 - Advance Penetration Testing. Exploit Writing, and Ethical Hacking (GXPN Certification), SEC
    642 - Advanced Web App Penetration Testing and Ethical Hacking, SEC
    564 -
  • Red Team Operations and Threat Emulation
  • OSD Sponsored Cyber Operation Academy Course (COAC) graduates.
  • Capture the Flag (CTF) participation (DEFCON, Over-The-Wire (OTW), Hack the Box, USS Secure CTF's)
  • Security research resulting in a Common Vulnerabilities and Exposures (CVE)

Possess the ability to:

  • Debug and reverse engineer software.
  • Analyze Windows Events and Linux syslog's, boot logs and dmesg logs.
  • Program and debug Web 2.0, Java, Perl, Ada, C + +, Tool Command Language (tcl / tk) scripts and graphical user interfaces (GUis) using Microsoft Visual tel and Rational Clear Case for software configuration management.
  • Recommend software modifications to systems to mitigate known vulnerabilities. Operate and administrate computer systems running HP-UX, UNIX, Solaris, Linux and Microsoft Windows.
  • Identify security flaws in compiled and human readable source code. Understand code utilizing real-time VxWorks and Lynx OS operating systems, Common Object Resource Broker Architecture (CORBA), firewalls and networking protocols.
  • Understand how to implement NSA approved encryption technologies and devices. Apply DISA Security Technical Implementation Guides (STIGs).
  • Apply virtual hosting and server technology in system architectures. Understand and apply the concept of deceptive technology such as honey pots in system architectures.
  • Participate in Code Reviews. Perform Static Source Code Analysis. Author recommendations for improving software and code design.
  • Contribute to a System Security Administrator and Operators Manual (SSAOM)

Must be a U.S. Citizen and Possess an Active Security Clearance RPI Group, Inc. is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary