Quick Overview
Seniority
Mid Senior
Employment type
Employee
Work mode
Hybrid
Location
Alexandria, VA, United States
Posted
Yesterday
PythonPowerShellBashOWASPPenetration TestingTCP/IPHTTPDNS
Job Description
Penetration Tester Position Summary: We are seeking an experienced Penetration Tester to identify, exploit, and help remediate security weaknesses across applications, systems, and network infrastructure. This role executes advanced offensive security assessments, simulates adversary tactics, and delivers actionable findings to harden enterprise defenses. The ideal candidate pairs deep technical exploitation skills with strong scripting capabilities to evaluate complex environments and communicate risk effectively.
Key Responsibilities
- Offensive Security Assessments: Plan and execute comprehensive penetration tests across web applications, external/internal networks, cloud environments, and operating systems.
- Vulnerability Exploitation: Safely identify, validate, and exploit technical security flaws, logical weaknesses, and misconfigurations to measure real-world business risk.
- Red Teaming & Adversary Emulation: Simulate modern adversary tactics, techniques, and procedures (TTPs) to evaluate defensive controls and incident response detection capabilities.
- Tooling & Automation: Utilize standard penetration testing frameworks while developing custom scripts and tools to streamline assessment workflows and target specific systems.
- Technical Reporting & Remediation: Author detailed assessment reports detailing attack chains, proof-of-concept exploits, and prioritized technical remediation guidance for engineering teams.
- Stakeholder Collaboration: Partner with developers, system administrators, and security leads to debrief assessment findings and validate implemented patches through re-testing.
Qualifications Required
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related field.
- Experience: 5+ years of hands-on experience conducting, supporting, or leading full-scope penetration tests.
- Core Technical Skills: o Deep understanding of operating system internals (Windows, Linux) and network protocols (TCP/IP, HTTP/S, DNS, SMB). o Hands-on proficiency with offensive testing frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike). o Strong web application testing techniques (e.g., OWASP Top 10 exploitation). o Scripting capability in Python, PowerShell, Bash, or Go for custom exploit payload delivery and automation.
Preferred Certifications
- Offensive Security: OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), GPEN (GIAC Penetration Tester), or GWAPT (GIAC Web Application Penetration Tester).
Location: Hybrid to Alexandria, VA Clearance: Public Trust
Similar jobs
- FL
Security Engineer, Corporate Security
NewFlexport
United States🇺🇸20 hours agoMFAOAuthSAML+10Technology - FL
Security Engineer, Corporate Security
NewFlexport
San Francisco🇺🇸20 hours agoMFAOAuthSAML+10Technology - ON
Senior Corporate Security Systems Engineer
NewOnebrief
United States | Remote🇺🇸RemoteYesterdayMFASSOSplunk+4Technology - DR
Senior Threat Detection Engineer
NewDragos
United States🇺🇸10 hours agoLuaRubyRust+6Engineering - DU
Senior Security Data Engineer
NewDoorDash USA
United States - Remote🇺🇸Remote13 hours agoDockerGCPRust+19Technology - DU
Senior Analyst, Protective Services
NewDoorDash USA
Austin🇺🇸YesterdaySQLSnowflakeCase Management+3