Red Team Penetration Tester
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, Information Security & Data Protection
Red Team Penetration Tester
The Opportunity:
We’re mission accelerators who protect and advance national interests by harnessing cutting-edge technology. As a penetration tester, you'll play a pivotal role in safeguarding our critical digital environments. Your ability to provide support by developing detailed test and assessment plans to be used during onsite and remote security assessments and by understanding and carrying-out attack stages such as foot printing and scanning, enumeration, gaining access, escalation or privileges, maintaining access, network exploitation, and covering tracks using one or more Tactics, Techniques, and Procedures (TTPs) will ensure the security of US Navy computer systems, applications, servers, and networks.
You will be providing support to customers by utilizing vulnerability scans, compliance checks, and other configuration data including Group Policy Object’s (GPOs) and Windows Software Update Service (WSUS) to accurately identify specific inconsistencies within system documentation such as vendor claims, Risk Management Framework (RMF) artifacts, CONOPS, systems engineering plans, design specifications, and interface descriptions and the actual applied security controls as developed or deployed within an Information System, Platform Information Technology (PIT) system, Information Technology (IT) product, or provided in IT services.
You will also provide customer support by performing packet-level analysis using appropriate tools such as Wireshark and tcp dump in order to identify specific information within network packets indicating anomalous or malicious behavior within network traffic flows. In this role, you’ll be instrumental in providing support by utilizing automated tools to conduct penetration tests of networks, applications, web applications, servers, endpoints, wireless, and mobile technologies and performing physical security testing to exploit physical security vulnerabilities by attempting to circumvent locks, badge readers, and other physical security controls, typically to gain unauthorized access to specific hosts.
Work with us as we help keep our customers’ digital environments secure. Join us. The world can't wait.
- 5+ years of experience in software engineering applied to program development and modeling and simulation applied to DoD or Information Technology systems
- Experience with Penetration Testing (PENTEST), Red Team Operations, Tool or Software Development, such as exploits and malware, C2, reverse engineering, and bug bounties, PHP, ASP, SQL db's, Java, HTML, or No SQL
- Knowledge of Linux and Windows based systems
- Knowledge of common Penetration Testing (PENTEST) tools such as Kali, Metasploit, NMAP, and Cobalt Strike
- Ability to debug and reverse engineer software
- Top Secret clearance
- HS diploma or GED
- IAT Level II per DoD 8570.01 or successor
- Certification Ability to obtain OSCP, OSCE, OSEE, OSWP, SANS, SEC
560 - Network Penetration testing and Ethical Hacking - SEC
542 - Web App Penetration Testing and Ethical Hacking - SEC
660 - Advance Penetration Testing, Exploit Writing, and Ethical Hacking - SEC
642
-Advanced Web App Penetration Testing and Ethical Hacking, or SEC
564 - Red Team Operations and Threat Emulation Certification within 3 months of hire date - Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Top Secret clearance is required.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).