Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Dominion Energy is seeking a Senior Cyber Security Analyst focused on penetration testing to identify exploitable weaknesses across applications, networks, cloud, and OT environments. You will plan engagements, perform hands‑on testing, and produce clear, actionable remediation guidance for technical and non‑technical audiences.
The ideal candidate has 5+ years of hands‑on security testing experience, strong report writing, and communication skills.
Dominion Energy is committed to providing reliable, affordable, and increasingly clean energy that powers our customers every day. If you want to work for a purpose-driven company that values safety and collaboration, we’re looking for you. You won’t just find a job here; you’ll find your career.
Military service members and veterans with ranks from E5-E9, W1-CW5, or O3-O6, plus appropriate equivalent combination of education and years of experience as outlined below will be considered for this opportunity. At this time, Dominion Energy cannot transfer or sponsor a work visa or employment authorization for this position. This position does not offer relocation assistance.
Do you have what it takes? This is not a typical cyber security role. The successful candidate will help protect critical infrastructure by identifying and clearly communicating exploitable weaknesses before they can be used by real-world threats. For our employees, cyber security is a mission, not simply a job. If you are an experienced, motivated penetration tester who is committed to learning, improving tradecraft, and helping others reduce risk, we want to hear from you.
This position is specifically focused on penetration testing and offensive security assessments rather than traditional cyber security analyst responsibilities. The selected candidate will join an established team of three penetration testers and conduct authorized assessments across applications, systems, internal and external networks, cloud environments, identity platforms, and related enterprise technologies.
The role includes the full penetration-testing lifecycle: planning and scoping engagements, performing hands‑on testing, identifying and validating attack paths, evaluating security controls, documenting findings, communicating risk, supporting remediation, and validating corrective actions. Testing must be performed ethically, within an authorized scope, and with appropriate consideration for business and operational risk.
The selected candidate must produce clear, high‑quality reports that explain technical findings, potential business impacts, supporting evidence, and practical remediation recommendations. The candidate must also be comfortable presenting results to both technical and non‑technical audiences and tailoring the level of detail to the recipients.
Experience with Operational Technology (OT), Industrial Control Systems (ICS), SCADA, or critical infrastructure environments is preferred. Candidates with this background should understand the additional safety, reliability, availability, and operational considerations associated with assessing industrial environments.
Key Responsibilities
Note: This position can be based in Richmond, Virginia or Cayce, South Carolina.
Five years of hands‑on experience working with systems, networks, cloud environments, identity platforms, OT/ICS environments, or related enterprise infrastructure. A Master’s degree will count as one year of experience. A partial year of six months or more experience will be rounded up to one year.
Other knowledge, skills, abilities and experience include:
Degree or an equivalent combination of education and demonstrated related experience may be accepted in lieu of preferred level of education: Bachelor
Preferred Discipline(s): Computer Science; Engineering; Information Systems; Information Systems Security
Other disciplines may be substituted for the preferred discipline(s) listed above.
Preferred certifications include OSCP, OSEP, PNPT, GPEN, GXPN, GWAPT, GCIH, GCFA, GICSP, CISSP, CPTS, or another comparable GIAC, OffSec, Hack The Box, or recognized offensive security certification.
Travel Up to 25%
No Testing Required
Export Control
Certain positions at Dominion Energy may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in Dominion Energy limiting its consideration of certain applicants.
What You'll Get
Expected Hiring Base Salary Range:
$102300 - $132800
The expected hiring base salary range is the range we anticipate hiring within for this position. The actual salary offered may vary based on factors such as the selected candidate’s qualifications, skills, experience, and work location. This is not intended to represent the full salary range for the position or limit future compensation growth.
Employees are rewarded with a competitive salary and comprehensive benefits package which includes: health, dental, and vision benefits with coverage for families and domestic partners, vacation, retirement plans including 401k contributions and matches, paid holidays, tuition reimbursement, bonus eligibility, sick leave, and disability insurance.
Dominion Energy is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin and/or status as a protected veteran or individual with a disability.
You can experience the excitement of our company – it's the difference between taking a job and starting a career.
Job Segment: Computer Science, ERP, Environmental Engineering, Information Systems, Testing, Technology, Engineering