Penetration Tester

Jobtailor

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Washington, DC seeks an experienced Penetration Tester to execute complex assessments of networks, systems, and web applications. You will follow formal rules of engagement, document exploitation paths, and contribute to test plans for upcoming engagements.

The role requires 5+ years of hands-on pentesting, strong tool proficiency, and security testing across ICS/OT, cloud, and wireless environments.

Qualifications

  • Bachelor's degree in cybersecurity, CS, IT, engineering, math or physics.
  • 5+ years hands-on penetration testing across networks, systems, and web apps.
  • At least 2 years of recent hands-on testing (last 3 years).
  • Proficiency with Metasploit, Burp Suite, Nmap and related frameworks.
  • Experience with formal Rules of Engagement and producing structured PTRs.
  • Understanding of network protocols, routing, switching, firewalls and misconfigurations.
  • Experience with OWASP testing methodology for web apps.
  • Ability to obtain and maintain a Public Trust.
  • One Red Teaming certification (OSCP/OSCE/OSWP/OSWE/CEH/ECSA etc.).
  • Blue Team certifications accepted (CND/CNDA/GCIH/GCIA/GDAT/GCED/GCFA). OSCP or GPEN preferred.
  • Experience testing ICS/OT environments or critical infrastructure.
  • Experience with wireless security testing or satellite comms.
  • Experience with cloud pen testing (AWS, Azure).
  • Familiarity with aircraft systems, avionics or aviation protocols.
  • Prior red team experience in government/military contexts.
  • C2 frameworks for adversary simulation beyond Metasploit.
  • BloodHound and Impacket for AD attack paths.
  • Nuclei for automated vulnerability detection at scale.
  • Cloud tools (Pacu, AzureHound) for cloud-hosted environments.
  • SDR/HackRF tools for wireless/RF testing.
  • AI-assisted fuzzing tools for exploit discovery.

Responsibilities

  • Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
  • Identify and exploit vulnerabilities in network infrastructure, OS, web apps, and databases.
  • Participate in red team and blue team exercises in simulated environments.
  • Execute attack scenarios and document findings in PTRs.
  • Perform regression penetration tests to validate remediation of vulnerabilities.
  • Support aircraft cyber testing activities including avionics and flight system security assessments.
  • Support edge devices, firewalls, load balancers, and other network components testing.
  • Assess and document potential for lateral movement when access is gained.
  • Report high-risk findings immediately.
  • Maintain and update penetration testing tools and lab environments; FAA-approved tools only.
  • Assist Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.

Skills

Penetration testing
Red Team experience
Blue Team experience
Report writing

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics

Tools

Metasploit
Burp Suite
Nmap
C2 frameworks (Cobalt Strike, Sliver, Mythic)
BloodHound/Impacket

Job description

  • Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
  • Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
  • Participate in red team and blue team exercises in simulated environments.
  • Execute attack scenarios and document findings.
  • Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
  • Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
  • Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
  • Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
  • Assess and document the potential for lateral movement when access is gained during testing.
  • Report high-risk findings immediately.
  • Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
  • Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
  • A minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing.
  • At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
  • Experience working within formal Rules of Engagement and producing structured penetration test reports.
  • Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
  • Experience with web application testing following OWASP methodology.
  • Candidate must have the ability to obtain and maintain a Public Trust
  • At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
  • Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA. OSCP or GPEN preferred.
  • Experience testing ICS/OT environments or critical infrastructure systems.
  • Experience with wireless security testing or satellite communication systems.
  • Experience with cloud penetration testing (AWS, Azure).
  • Familiarity with aircraft systems, avionics, or aviation communication protocols.
  • Prior red team experience in a government or military context.
  • C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
  • BloodHound and Impacket for Active Directory attack path analysis and lateral movement.
  • Nuclei for automated vulnerability detection at scale.
  • Cloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments.
  • SDR/HackRF tools for wireless and RF communications testing.
  • AI-assisted fuzzing tools for expanding exploit discovery on complex systems.
Core Competencies

Demonstrates extensive experience in penetration testing, including network, system, and web application assessments, while adhering to formal Rules of Engagement. Proficient in utilizing advanced penetration testing tools and frameworks to identify and exploit vulnerabilities across various environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Testing Lead
Penetration Testing Lead

Jobtailor • Washington

On-site
USD 180,000 - 240,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 170,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 190,000
Senior Penetration Tester / Red Team Consultant
Senior Penetration Tester / Red Team Consultant

Jobtailor • Seattle (WA)

On-site
USD 140,000 - 210,000
Penetration Tester
Penetration Tester

Gilder Search Group • Norfolk (VA)

On-site
USD 110,000 - 170,000
Red Team Penetration Tester
Red Team Penetration Tester

Take2 Consulting, LLC • Virginia Beach (VA)

On-site
USD 180,000 - 240,000
Penetration Tester
Penetration Tester

ANALYGENCE • San Antonio (TX)

On-site
USD 90,000 - 120,000
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Lead Associate Principal, Adversarial Red Team
Lead Associate Principal, Adversarial Red Team

Jobtailor • United States

On-site
USD 170,000 - 210,000
Senior Red Team Operator
Senior Red Team Operator

Jobtailor • Huntsville (AL)

On-site
USD 90,000 - 150,000