×
Register Here to Apply for Jobs or Post Jobs. X

Penetration Tester ​/ Red Team Operator

Job in McLean, Fairfax County, Virginia, USA
Listing for: Digital-Global-Connectors
Full Time position
Listed on 2026-08-23
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Network Security
Salary/Wage Range or Industry Benchmark: 110000 - 170000 USD Yearly USD 110000.00 170000.00 YEAR
Job Description & How to Apply Below

Penetration Tester / Red Team Operator

Location:

Bethesda, MD (Hybrid; On-site as Required)

Clearance:
Tier 2 Public Trust (Required)

Employment Type:

Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Penetration Tester / Red Team Operator to support a Federal information security program. The Penetration Tester is responsible for performing authorized security assessments that evaluate the effectiveness of technical, administrative, and operational security controls protecting enterprise information systems, cloud environments, applications, wireless networks, and supporting infrastructure.

This position conducts penetration tests, adversary emulation exercises, vulnerability exploitation, security validation, and red team assessments to identify weaknesses before they can be exploited by malicious actors. The Penetration Tester collaborates with Security Engineers, Security Architects, Threat Hunters, Incident Responders, ISSOs, System Owners, and program leadership to strengthen enterprise cybersecurity through proactive security testing and risk-based recommendations.

The successful candidate will possess extensive experience performing enterprise penetration testing, application security testing, network exploitation, and adversary simulation within complex enterprise environments.

Essential Duties and Responsibilities:

Penetration Testing

  • Conduct authorized internal and external penetration tests against enterprise systems.
  • Perform network, application, wireless, cloud, and infrastructure security assessments.
  • Validate vulnerabilities identified during automated vulnerability scans.
  • Identify exploitable weaknesses in enterprise environments.
  • Document attack paths and associated business risks.
  • Recommend remediation strategies to eliminate identified vulnerabilities.
Red Team Operations
  • Conduct adversary emulation exercises based on real-world threat actor tactics.
  • Simulate advanced persistent threat (APT) activities.
  • Evaluate the effectiveness of enterprise detection and response capabilities.
  • Test security monitoring, alerting, and incident response processes.
  • Coordinate red team activities with authorized stakeholders.
  • Support purple team engagements to improve defensive capabilities.
Web and Application Security Testing
  • Perform manual and automated web application security assessments.
  • Test for vulnerabilities consistent with the OWASP Top 10 and API Security Top 10.
  • Evaluate authentication, authorization, session management, and input validation.
  • Assess application programming interfaces (APIs) for security weaknesses.
  • Validate remediation of application vulnerabilities.
  • Document technical findings and business impacts.
Network Security Testing
  • Assess internal and external network security.
  • Evaluate firewalls, routers, switches, VPNs, wireless networks, and remote access solutions.
  • Test network segmentation and access controls.
  • Assess Active Directory security.
  • Evaluate identity and privilege escalation paths.
  • Validate network hardening measures.
Cloud Security Assessments
  • Perform security assessments of Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), and hybrid cloud environments.
  • Evaluate cloud identity configurations and privileged access.
  • Test cloud networking and storage configurations.
  • Assess cloud-native security controls.
  • Identify cloud misconfigurations and excessive permissions.
  • Recommend improvements to cloud security architecture.
Security Assessment Tools

Utilize technologies including:

  • Kali Linux
  • Metasploit Framework
  • Burp Suite Professional
  • Nmap
  • Nessus
  • Tenable Security Center
  • Blood Hound
  • Cobalt Strike (where authorized)
  • Impacket
  • Wireshark
  • OWASP ZAP
  • Microsoft Defender XDR
  • Microsoft Sentinel
  • Power Shell
  • Python
  • Security Information and Event Management (SIEM) platforms

Evaluate new tools and techniques to improve testing effectiveness.

Reporting and Documentation

Develop and maintain:

  • Penetration Test Reports
  • Executive Summary Reports
  • Technical Findings Reports
  • Risk Assessments
  • Remediation Recommendations
  • Red Team After-Action Reports
  • Attack Path Diagrams
  • Proof-of-Concept Documentation
  • Standard Operating Procedures
  • Lessons Learned

Ensure reports clearly communicate technical findings, business impacts, and recommended corrective actions.

Collaboration
  • Coordinate with Security Engineers, Security Architects, ISSOs, SOC Analysts, Threat Hunters, Incident Responders, System Owners, and Government stakeholders.
  • Support remediation planning and validation efforts.
  • Participate in security assessments and technical working groups.
  • Provide technical briefings to technical and executive leadership.
  • Mentor junior penetration testers when appropriate.
Continuous Improvement
  • Monitor emerging attack techniques, exploit methodologies, and threat actor tactics.
  • Evaluate new penetration testing tools and methodologies.
  • Recommend improvements to enterprise security testing capabilities.
  • Support purple team exercises and continuous security validation initiatives.
  • Maintain professional certifications and technical expertise.
Minimum…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary