Penetration Tester

OCH Technologies, LLC

Leesburg (VA)

Hybrid

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Paid time off
Medical, Dental, and Vision Insurance
401(k)
Tuition Reimbursement

Job summary

OCH Technologies, LLC is seeking a seasoned Penetration Tester to execute network, system, application, and specialized tests against FAA infrastructure, under formal Rules of Engagement. You will report findings in detailed PTRs and participate in red/blue team exercises in simulated environments.

This role supports a proposal effort and requires onboarding and FAA approval. Travel up to 40% nationwide is expected.

Qualifications

  • Bachelor’s degree in Cybersecurity or related field from an accredited institution.
  • 5+ years of hands-on penetration testing experience (network, system, and web apps).
  • Proficiency with Metasploit, Burp Suite, Nmap and related frameworks.
  • Experience working within formal Rules of Engagement and producing structured PTRs.

Responsibilities

  • Execute penetration tests against NAS and Mission Support systems, networks, and apps per approved plans.
  • Identify and exploit vulnerabilities in networks, operating systems, web apps, and databases.
  • Document findings and exploitation paths in detailed PTRs; perform regression tests to verify remediation.
  • Travel up to 40% to FAA facilities; support testing activities in safety-critical environments.

Skills

Metasploit
Burp Suite
Nmap
Penetration testing
OWASP testing

Education

Bachelor's degree in Cybersecurity

Job description

Description

OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate FAA-approved tools, and produce technically detailed test reports. You will also participate in red team and blue team exercises in simulated environments.

This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.

Location

Hybrid- FAA Air Traffic Control System Command Center (ATCSCC)- Washington, DC

This position has the potential to travel up to 40% to other FAA facilities nationwide.

Core Responsibilities & Duties
  • Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
  • Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
  • Participate in red team and blue team exercises in simulated environments. Execute attack scenarios and document findings.
  • Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
  • Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
  • Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
  • Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
  • Assess and document the potential for lateral movement when access is gained during testing. Report high-risk findings immediately.
  • Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
  • Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.

Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.

Minimum Qualifications

Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution.

Experience
  • A minimum of five (5)+ years of hands‑on penetration testing experience, including network, system, and web application testing. At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
  • Experience working within formal Rules of Engagement and producing structured penetration test reports.
  • Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
  • Experience with web application testing following OWASP methodology.
Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust.

Certifications
  • At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
  • Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA.
  • OSCP or GPEN preferred.
Preferred Qualifications
  • Experience testing ICs/OT environments or critical infrastructure systems.
  • Experience with wireless security testing or satellite communication systems.
  • Experience with cloud penetration testing (AWS, Azure).
  • Familiarity with aircraft systems, avionics, or aviation communication protocols.
  • Prior red team experience in a government or military context.
  • C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
  • BloodHound and Impacket for Active Directory attack path analysis and lateral movement.
  • Nuclei for automated vulnerability detection at scale.
  • Cloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments.
  • SDR/HackRF tools for wireless and RF communications testing.
  • AI-assisted fuzzing tools for expanding exploit discovery on complex systems.
Other Required Skills And Abilities
  • Willingness to travel to FAA facilities and WJHTC for on‑site testing engagements.
  • Discipline to operate within strict testing constraints in safety‑critical environments.
  • Ability to conduct manual testing beyond automated tool output. Ability to develop custom scripts and payloads as needed.
About Us

At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting‑edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward‑thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.

What Defines Us
  • Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically.
  • Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead.
  • People‑Focused - We prioritize relationships, championing growth and mutual success.
  • Accountable - We own our outcomes, striving for excellence through continuous improvement.
  • Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions.
Why Join Us?
Benefits

Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference.

  • Paid time off and Holidays
  • Medical, Dental, and Vision Insurance
  • Paid Parental Leave
  • Short‑term disability, long‑term disability, and life insurance - Employer Paid!
  • 401(k)
  • Additional Voluntary Life Insurance
  • Tuition Reimbursement

& More!

E-Verify Participation

OCH Technologies, LLC is a participant of E‑Verify to verify the identity and employment eligibility of newly hired employees.

Veteran’s Preference and Accessibility Statement

At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.

We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at hiring@ochtec.com.

OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Ochtec • Washington

Hybrid
USD 120,000 - 160,000
PTO & Holidays
Medical Insurance
401(k)
Penetration Testing Lead
Penetration Testing Lead

Ochtec • Washington

Hybrid
USD 180,000 - 240,000
Paid time off and Holidays
Medical, Dental, Vision Insurance
401(k)
+1
Cybersecurity Engineer
Cybersecurity Engineer

Ochtec • Washington (NJ)

Hybrid
USD 130,000 - 180,000
Medical, Dental, Vision Insurance
401(k)
Paid time off and holidays
+2
Cybersecurity Engineer
Cybersecurity Engineer

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Insurance
Paid time off & holidays
Parental Leave
+3
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Ochtec • Washington (NJ)

On-site
USD 120,000 - 160,000
Paid time off and Holidays
Medical, Dental, and Vision Insurance
401(k)
+3
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

OCH Technologies, LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Medical, Dental, and Vision Insurance
Paid Time Off
401(k)
+1
Program Manager
Program Manager

Ochtec • Herndon (VA)

Hybrid
USD 150,000 - 210,000
Paid time off
Medical, Dental, Vision Insurance
401(k) plan
+2
Principal Network Engineer
Principal Network Engineer

OCH Technologies LLC • Egg Harbor Township (NJ)

On-site
USD 150,000 - 210,000
PTO & Holidays
Medical/Dental/Vision Insurance
Parental Leave
+3
Principal Network Engineer
Principal Network Engineer

OCH Technologies, LLC • Egg Harbor Township (NJ)

On-site
USD 140,000 - 190,000
Paid time off
Medical, Dental, Vision Insurance
401(k)
NCO (National Cybersecurity Operations) Technical Lead
NCO (National Cybersecurity Operations) Technical Lead

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 180,000 - 240,000
Paid time off
Health Insurance
Parental Leave
+4