Penetration Tester

Gilder Search Group

Norfolk (VA)

On-site

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Input Technology Solutions has an immediate opportunity to support the US Navy with operational test and evaluation. The Penetration Tester will assist in cyber test plans, execute tests, and report results across operational, lab, and cyber range environments.

The role requires extensive experience in penetration testing, red teaming, and using advanced offensive tools to assess Windows/Linux systems and network services. Top-secret clearance or eligibility preferred.

Qualifications

  • Minimum 3 years’ experience performing any combination of: penetration testing, red teaming, or exploitation development.
  • Minimum 3 years’ with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.
  • Offensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.
  • Proficient in multiple offensive tools, including: Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound.

Responsibilities

  • Review OPTEVFOR cyber T&E concepts of operations, SOPs, policies and guidance.
  • Develop and update SOPs and documentation for DCAT authorization per DoDI 8585.01.
  • Research requirements for equipment or cyber capabilities and support test plan objectives.
  • Support development and execution of TTPs for penetration testing or Red Teaming.
  • Execute test events including CVP, adversarial assessments, and cyber tabletop exercises, using approved tools.
  • Ensure tests are conducted safely and in accordance with the plan and policies.
  • Document lessons learned and generate post-test reports.

Skills

Penetration testing
Red teaming
Cyber security
Technical documentation
Unix/Linux
Windows

Tools

Metasploit
Cobalt Strike
Core Impact
Burp Suite
Nessus
BloodHound

Job description

Input Technology Solutions has an immediate opportunity to support the US Navy with operational test and evaluation support. The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and report cyber test results. In this role you will conduct cyber tests on operational systems, in laboratory environments, or in cyber range environments. Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage all authorized resources and analytic techniques to penetrate/access targeted networks and systems under test in support of OPTEVFOR's cyber OT&E mission. Team member will perform these duties under the supervision of the 01D Cyber Operations Officer.

Job Duties
  • Review and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance.
  • Maintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.
  • Research, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process.
  • Support development and execution of TTPs for penetration testing or Red Teaming.
  • Research adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.
  • Participate in OPTEVFOR Cyber Test planning:
    • Conduct open-source research and system under test documentation review to familiarize with the system’s mission, architecture and interfaces including critical components to identify its attack surface and threat vectors
    • Participate in check point meetings
    • Support development of test plan objectives
    • Review test plans, ensuring that test plans objectives are feasible
    • Participate in test planning site visits
  • Participate in test preparation:
    • Participate in site pre-test coordination visits. Support in-brief to the test site.
    • Support red team test plan review
    • Add relevant system technical information to test reference library
    • Organize and support research presentations for advanced capability development in support of future tests
    • Prepare OPTEV-RT test assets (Government Furnished)
  • Execute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned.
    • Use OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus).
    • Employee ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols (HTTP, FTP, etc.), and network security services (PKI, HTTPS, etc.) to accomplish test objectives
    • Be able to accomplish testing independently
    • Ensure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to
    • Follow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures
    • Verify collected data for accuracy and completeness
  • Participate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets).
  • Document lessons learned.
  • Participate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events.
  • Attend OPTEVFOR required meetings in support of OT&E.
  • Generate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.
  • Process exfiltrated data for analysis and/or dissemination to customers.
  • Test and evaluate locally developed tools for operational use and implementation.
Requirements
  • Minimum 3 years’ experience performing any combination of: penetration testing, red teaming, or exploitation development.
  • Minimum 3 years’ with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.
  • Offensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.
  • Proficient in multiple offensive tools, including:
    • Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound
  • Ability to validate functionality and safety of offensive tools (e.g. exploits) given the source code and document the results.
  • Ability to detect malicious activity of a program using dynamic analysis techniques and document the results.
  • Independently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.
  • Skill in assessing current tools to identify needed improvements.
  • Skill in knowledge management, including technical documentation techniques (e.g., Wiki page).
  • Knowledge of current software and methodologies for active defense and system hardening.
  • Knowledge of encryption algorithms and cyber capabilities/tools (e.g., Transport Layer Security, Pretty Good Privacy).
  • Knowledge of evasion strategies and techniques.
  • Knowledge of forensic implications of operating system structure and operations.
  • Knowledge of host-based security products and how they affect exploitation and vulnerability.
  • Knowledge of network administration.
  • Knowledge of network construction and topology.
  • Knowledge of security hardware and software options, including the network artifacts they induce and their effects on exploitation.
  • Knowledge of security implications of software configurations.
  • Knowledge of the fundamentals of digital forensics in order to extract actionable intelligence.
  • Knowledge of cryptologic capabilities, limitations, and contributions to cyber operations.
  • Knowledge of Unix/Linux and Windows operating systems structures and internals (e.g., process management, directory structure, installed applications).
  • Knowledge of network collection procedures to include decryption capabilities/tools, techniques, and procedures.
  • Process exfiltrated data for analysis and/or dissemination to customers.
  • Test and evaluate locally developed tools for operational use.
  • Skill in testing and evaluating tools for implementation.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and verbal communication skills.
Clearance
  • Top-Secret/SCI
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Input Technology Solutions • Norfolk (VA)

On-site
USD 110,000 - 150,000
Penetration Tester
Penetration Tester

ANALYGENCE • Norfolk (VA)

On-site
USD 80,000 - 100,000
Exploitation Analyst
Exploitation Analyst

ANALYGENCE • Norfolk (VA)

On-site
USD 90,000 - 140,000
Senior Cyber Penetration Tester – OT&E & Red Team
Senior Cyber Penetration Tester – OT&E & Red Team

Gilder Search Group • Norfolk (VA)

On-site
USD 110,000 - 170,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 190,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 170,000
Penetration Tester
Penetration Tester

ANALYGENCE • San Antonio (TX)

On-site
USD 90,000 - 120,000
Red Team Penetration Tester
Red Team Penetration Tester

Take2 Consulting, LLC • Virginia Beach (VA)

On-site
USD 180,000 - 240,000
Penetration Tester
Penetration Tester

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Operational Cyber Test Engineer: Penetration & Red Teaming
Operational Cyber Test Engineer: Penetration & Red Teaming

Input Technology Solutions • Norfolk (VA)

On-site
USD 110,000 - 150,000