More jobs:
Penetration Tester
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-08-17
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-17
Job specializations:
-
Engineering
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
- Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
- Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
- Participate in red team and blue team exercises in simulated environments.
- Execute attack scenarios and document findings.
- Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
- Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
- Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
- Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
- Assess and document the potential for lateral movement when access is gained during testing.
- Report high-risk findings immediately.
- Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
- Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
- A minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing.
- At least 2 years of relevant experience must be recent (performed within the last 3 years).
- Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
- Experience working within formal Rules of Engagement and producing structured penetration test reports.
- Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
- Experience with web application testing following OWASP methodology.
- Candidate must have the ability to obtain and maintain a Public Trust
- At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
- Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA. OSCP or GPEN preferred.
- Experience testing ICS/OT environments or critical infrastructure systems.
- Experience with wireless security testing or satellite communication systems.
- Experience with cloud penetration testing (AWS, Azure).
- Familiarity with aircraft systems, avionics, or aviation communication protocols.
- Prior red team experience in a government or military context.
- C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
- Blood Hound and Impacket for Active Directory attack path analysis and lateral movement.
- Nuclei for automated vulnerability detection at scale.
- Cloud pen testing tools (Pacu, Azure Hound) for cloud-hosted environments.
- SDR/HackRF tools for wireless and RF communications testing.
- AI-assisted fuzzing tools for expanding exploit discovery on complex systems.
Demonstrates extensive experience in penetration testing, including network, system, and web application assessments, while adhering to formal Rules of Engagement. Proficient in utilizing advanced penetration testing tools and frameworks to identify and exploit vulnerabilities across various environments.
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×