Penetration Tester

SteelToad

Dahlgren (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Vision and dental insurance
Disability and life insurance
Health Savings Account
401(k) Savings Plan with match
11 paid holidays
120 accrued PTO hours per year
Professional Development Program
Salary determined by education and exp

Job summary

SteelToad is seeking a Vulnerability Assessment Analyst and Penetration Tester to deliver continuous cyber assessments, perform manual penetration testing, and develop tools to mitigate threats for DoD and regulated clients.

You will mentor engineers, automate tasks with scripting, and contribute to threat mitigation plans while upholding high security standards across systems and applications.

Qualifications

  • DoD 8570.01-M Baseline Certification: CSSP Auditor.
  • One of OSCP, OSCE, OSEE, or OSWP.

Responsibilities

  • Perform manual application, service, and hardware penetration testing.
  • Automate repetitive tasks with scripting languages.
  • Mentor and lead engineers through complex penetration tests and assessments.
  • Advance testing capabilities through automation and tooling.
  • Create threat mitigation plans.

Skills

Metasploit
NMAP
Kali Linux
Cobalt Strike
Scripting languages (Python/C++)
Linux
Windows
macOS

Education

Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline.

Tools

Metasploit
NMAP
Kali Linux
Cobalt Strike

Job description

Company Description

SteelToad is a cybersecurity firm focused on mitigating risk, increasing organizational resilience, and protecting critical data while supporting regulatory compliance. As a HUBZone Certified Small Business with over 20 years of cybersecurity experience across its team, SteelToad delivers cyber assessments, security services, and governance, risk, and compliance (GRC) solutions to public sector and Defense Industrial Base (DIB) clients. The company holds multiple accreditations and certifications, including ISO 9001, ISO 20000-1:2018, ISO 27001:2022, and operates as a CMMC Third-Party Independent Assessment Organization (C3PAO) and A2LA accredited provider. SteelToad is deeply familiar with frameworks such as NIST SP 800-53/30/66, CMMC, RMF, HIPAA, and FISMA, and designs tailored solutions addressing complex security needs. Team members collaborate closely with government agencies and regulated organizations to strengthen cyber resilience through services like penetration testing, red teaming, vulnerability management, and continuous monitoring.

Role Description

the Vulnerability Assessment Analyst and Penetration Tester delivers continuous cyber assessments, solves complex technology problems, builds tools, and helps identify, influence, and mitigate threats. This role performs manual assessments of systems, services, and software, specializing in security issues beyond those identified by static analysis tools. The individual helps ensure services, applications, and websites are designed and implemented to the highest security standards. Responsibilities include application and hardware penetration testing, automating repetitive tasks with scripting languages, mentoring and leading engineers through complex penetration tests and vulnerability assessments, advancing penetration testing capabilities through automation and tooling, and creating threat mitigation plans.

Education

Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline.

Required Certificaton/Qualification
  • DoW 8570.01-M in accordance with DFARS 252.239-7001 Baseline Certification: minimum CSSP Auditor.
  • One of the following certifications: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP).
Experience

Seven (7) years of full-time professional experience conducting penetration testing or offensive cyber operations in the following areas:

  • Developing and using penetration testing tools such as Metasploit, NMAP, Kali Linux, and Cobalt Strike.
  • Mimicking threat behavior.
  • Using multiple operating systems, including Linux, Windows, macOS, and related platforms.
  • Identifying gaps in tools and development techniques.
  • Developing with at least two scripting or programming languages, such as Python, C++, Java, Rust, Assembly, or C#.

Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline.

Required Certification/Qualification
  • DoD 8570.01-M in accordance with DFARS 252.239-7001 Baseline Certification: minimum CSSP Auditor.
  • One of the following certifications: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP).
Benefits & Compensation
  • New employees are eligible to participate in the company’s benefits plan on their date of hire unless noted otherwise.
  • Medical insurance.
  • Vision and dental insurance.
  • Long-term disability, short-term disability, group life, and AD&D insurance: 100% employer paid.
  • Health Savings Account.
  • 401(k) Savings Plan: 100% match for the first 3% contributed, plus 50% of the next 2% contributed; no vesting period, with eligibility on date of hire.
  • Eleven (11) paid holidays per year.
  • One hundred twenty (120) accrued hours of Paid Time Off per year.
  • Professional Development Program.
  • Salary will be determined based on the individual’s education and experience level.
Company Overview

SteelToad Consulting LLC is a leading provider of IT support, cybersecurity, training, and development services to the Department of Defense (DoD) and other government agencies. We are seeking an experienced Red Team Penetration Tester III to support cyber assessment and offensive security work in the defense sector.

Equal Employment Opportunity Policy Statement

It is the policy of SteelToad Consulting LLC. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California), or because he or she is a protected veteran.

It is also the policy of the Company to take affirmative action to employ and advance in employment all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California), or protected veteran status, and to base all employment decisions only on valid job requirements.

This policy applies to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation, and selection for training, including apprenticeship, at all levels of employment.

Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of Maryland), or because he or she is a protected veteran.

Retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing, or otherwise sought to obtain legal rights under any Federal, State, or local EEO law is prohibited.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red Team Penetration Tester (TS/SCI REQUIRED)
Red Team Penetration Tester (TS/SCI REQUIRED)

DirectViz Solutions, LLC • Virginia (MN)

On-site
USD 160,000 - 210,000
TS/SCI clearance
Red Team Penetration Tester (TS/SCI REQUIRED)
Red Team Penetration Tester (TS/SCI REQUIRED)

DirectViz Solutions, LLC • Virginia Beach (VA)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) match
PTO accrual
+3
Red Team Penetration Tester IV
Red Team Penetration Tester IV

DirectViz Solutions, LLC • Virginia Beach (VA)

On-site
USD 100,000 - 130,000
Competitive compensation
Comprehensive medical benefits
401(k) match
+4
Red Team Penetration Tester
Red Team Penetration Tester

DirectViz Solutions, LLC • Dahlgren (VA)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) match
PTO accrual
+1
Penetration Tester
Penetration Tester

WarCollar Industries, LLC • Herndon (VA)

On-site
USD 110,000 - 180,000
Medical insurance premium coverage
PTO based on billable hours
Federal holidays plus your birthday
+6
Red Team Penetration Tester IV - TS/SCI Required
Red Team Penetration Tester IV - TS/SCI Required

DirectViz Solutions, LLC • Dahlgren (VA)

On-site
USD 150,000 - 230,000
Competitive compensation
Comprehensive medical benefits
401(k) match
+4
Red Team Penetration Tester IV - TS/SCI Required
Red Team Penetration Tester IV - TS/SCI Required

DirectViz Solutions, LLC • Dahlgren (VA)

On-site
USD 140,000 - 210,000
Medical benefits
401(k) match
PTO accrual
+2
Penetration Testing Team Lead
Penetration Testing Team Lead

ECS • Richmond (VA)

Hybrid
USD 170,000 - 190,000
Red Team Penetration Tester III
Red Team Penetration Tester III

Take2 Consulting, LLC • Virginia Beach (VA)

On-site
USD 150,000 - 175,000
Cyber Security Engineer
Cyber Security Engineer

Redhorse Corporation • Herndon (VA)

On-site
USD 120,000 - 180,000