Senior Cyber Security Analyst - (Penetration Tester) (Cayce, SC or Richmond, VA)

Dominion Energy

Northern (KY)

Hybrid

USD 102,000 - 133,000

Full time

21 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
401k with matching
Vacation and paid holidays
Tuition reimbursement
Bonus eligibility
Sick leave

Job summary

Dominion Energy is seeking a Senior Cyber Security Analyst focused on penetration testing to identify exploitable weaknesses across applications, networks, cloud, and OT environments. You will plan engagements, perform hands‑on testing, and produce clear, actionable remediation guidance for technical and non‑technical audiences.

The ideal candidate has 5+ years of hands‑on security testing experience, strong report writing, and communication skills.

Qualifications

  • Five years of hands-on experience with systems, networks, cloud, OT/ICS environments, or related enterprise infrastructure.
  • A Master’s degree will count as one year of experience; partial years will be rounded up.
  • Ability to plan, scope, execute, and document penetration tests or offensive security assessments.
  • Excellent verbal and written communication, including presenting security findings to diverse audiences.
  • Ethical testing within authorized scope while considering business operations and safety.

Responsibilities

  • Plan, scope, and execute authorized penetration tests and offensive security assessments.
  • Identify and validate vulnerabilities, attack paths, and control gaps.
  • Assess web apps, APIs, networks, cloud, identity platforms, and related technologies.
  • Support OT/ICS/SCADA or critical infrastructure assessments when applicable.
  • Prepare reports describing technical evidence, risk, impact, and remediation recommendations.
  • Present findings to technical teams, system owners, and management.
  • Collaborate with technology owners to prioritize findings and validate fixes.
  • Coordinate testing activities with peers and share knowledge.
  • Research emerging vulnerabilities and offensive security techniques.
  • Conduct testing ethically with minimal business disruption.

Skills

Penetration testing
OT/ICS security
Risk communication
Team collaboration
Report writing
Ethical hacking

Education

Bachelor
Master’s degree counted as experience

Tools

OSCP
CISSP
OSEP
PNPT
GPEN
GXPN
GWAPT
GCIH
GCFA
GICSP

Job description

Senior Cyber Security Analyst - (Penetration Tester) (Cayce, SC or Richmond, VA)

Dominion Energy is committed to providing reliable, affordable, and increasingly clean energy that powers our customers every day. If you want to work for a purpose-driven company that values safety and collaboration, we’re looking for you. You won’t just find a job here; you’ll find your career.

Military service members and veterans with ranks from E5-E9, W1-CW5, or O3-O6, plus appropriate equivalent combination of education and years of experience as outlined below will be considered for this opportunity. At this time, Dominion Energy cannot transfer or sponsor a work visa or employment authorization for this position. This position does not offer relocation assistance.

Introduction

Do you have what it takes? This is not a typical cyber security role. The successful candidate will help protect critical infrastructure by identifying and clearly communicating exploitable weaknesses before they can be used by real-world threats. For our employees, cyber security is a mission, not simply a job. If you are an experienced, motivated penetration tester who is committed to learning, improving tradecraft, and helping others reduce risk, we want to hear from you.

This position is specifically focused on penetration testing and offensive security assessments rather than traditional cyber security analyst responsibilities. The selected candidate will join an established team of three penetration testers and conduct authorized assessments across applications, systems, internal and external networks, cloud environments, identity platforms, and related enterprise technologies.

The role includes the full penetration-testing lifecycle: planning and scoping engagements, performing hands‑on testing, identifying and validating attack paths, evaluating security controls, documenting findings, communicating risk, supporting remediation, and validating corrective actions. Testing must be performed ethically, within an authorized scope, and with appropriate consideration for business and operational risk.

The selected candidate must produce clear, high‑quality reports that explain technical findings, potential business impacts, supporting evidence, and practical remediation recommendations. The candidate must also be comfortable presenting results to both technical and non‑technical audiences and tailoring the level of detail to the recipients.

Experience with Operational Technology (OT), Industrial Control Systems (ICS), SCADA, or critical infrastructure environments is preferred. Candidates with this background should understand the additional safety, reliability, availability, and operational considerations associated with assessing industrial environments.

Key Responsibilities

  • Plan, scope, and execute authorized penetration tests and offensive security assessments.
  • Identify and validate vulnerabilities, exploitable weaknesses, attack paths, and security‑control gaps.
  • Assess web and enterprise applications, APIs, network infrastructure, cloud environments, identity platforms, systems, and related technologies.
  • Where applicable, support assessments involving OT, ICS, SCADA, industrial control networks, or critical infrastructure environments.
  • Prepare high‑quality reports that clearly describe technical evidence, risk, business impact, and practical remediation recommendations.
  • Present findings and recommendations to technical teams, system owners, business stakeholders, and management.
  • Partner with technology owners to prioritize findings, support remediation, and validate corrective actions.
  • Collaborate with the other penetration testers through peer review, methodology development, knowledge sharing, and coordinated testing activities.
  • Research emerging vulnerabilities, attack techniques, tools, and offensive security methodologies.
  • Perform testing in a controlled, ethical, and business‑aware manner that minimizes unintended operational impact.

Note: This position can be based in Richmond, Virginia or Cayce, South Carolina.

Required Knowledge, Skills, Abilities & Experience

Five years of hands‑on experience working with systems, networks, cloud environments, identity platforms, OT/ICS environments, or related enterprise infrastructure. A Master’s degree will count as one year of experience. A partial year of six months or more experience will be rounded up to one year.

Other knowledge, skills, abilities and experience include:

  • Demonstrated experience planning, scoping, executing, and documenting penetration tests or offensive security assessments.
  • Demonstrated ability to identify, validate, document, and communicate exploitable vulnerabilities, attack paths, security‑control weaknesses, and associated risks.
  • Experience developing penetration‑test reports that include clear technical evidence, business‑impact descriptions, risk‑based findings, and practical remediation recommendations.
  • Demonstrated verbal and written communication skills, including experience presenting technical security findings to both technical and non‑technical audiences.
  • Ability to conduct testing ethically and responsibly within an authorized scope while considering business operations, system availability, reliability, and safety.
  • Ability to work cooperatively in a team environment, participate in peer reviews, share technical knowledge, and coordinate testing activities.
  • Demonstrated initiative, analytical and investigative ability, intellectual curiosity, and commitment to developing offensive security skills and methodologies.
  • Experience assessing or securing OT, ICS, SCADA, industrial control networks, or critical infrastructure environments is preferred.
  • Experience testing web applications, APIs, Active Directory, cloud platforms, network infrastructure, identity platforms, or other enterprise technologies is preferred.
Education Requirements

Degree or an equivalent combination of education and demonstrated related experience may be accepted in lieu of preferred level of education: Bachelor

Preferred Discipline(s): Computer Science; Engineering; Information Systems; Information Systems Security

Other disciplines may be substituted for the preferred discipline(s) listed above.

Licenses, Certifications, or Quals Description

Preferred certifications include OSCP, OSEP, PNPT, GPEN, GXPN, GWAPT, GCIH, GCFA, GICSP, CISSP, CPTS, or another comparable GIAC, OffSec, Hack The Box, or recognized offensive security certification.

Working Conditions

Travel Up to 25%

Test Description

No Testing Required

Export Control

Certain positions at Dominion Energy may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in Dominion Energy limiting its consideration of certain applicants.

What You'll Get

Expected Hiring Base Salary Range:

$102300 - $132800

The expected hiring base salary range is the range we anticipate hiring within for this position. The actual salary offered may vary based on factors such as the selected candidate’s qualifications, skills, experience, and work location. This is not intended to represent the full salary range for the position or limit future compensation growth.

Employees are rewarded with a competitive salary and comprehensive benefits package which includes: health, dental, and vision benefits with coverage for families and domestic partners, vacation, retirement plans including 401k contributions and matches, paid holidays, tuition reimbursement, bonus eligibility, sick leave, and disability insurance.

Dominion Energy is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin and/or status as a protected veteran or individual with a disability.

You can experience the excitement of our company – it's the difference between taking a job and starting a career.

Job Segment: Computer Science, ERP, Environmental Engineering, Information Systems, Testing, Technology, Engineering

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Analyst - (Penetration Tester) (Cayce, SC or Richmond, VA) (CAYCE, SC, US, 29033)
Senior Cyber Security Analyst - (Penetration Tester) (Cayce, SC or Richmond, VA) (CAYCE, SC, US, 29033)

Dominion Energy • Cayce (SC)

On-site
USD 102,000 - 133,000
Software Engineer
Software Engineer

Talentify • Cayce (SC)

Hybrid
USD 82,000 - 106,000
Health, dental, vision
401k with match
Tuition reimbursement
+1
Software Engineer
Software Engineer

Dominion Energy • Cayce (SC)

Hybrid
USD 82,000 - 106,000
Health/dental/vision benefits
401k with matches
Tuition reimbursement
+1
Senior Intelligence Analyst (CAYCE, SC, US, 29033)
Senior Intelligence Analyst (CAYCE, SC, US, 29033)

Dominion Energy • Cayce (SC)

On-site
USD 91,000 - 118,000
Health, dental & vision benefits
Retirement plans (401k)
Tuition reimbursement
Consulting Software Engineer (RICHMOND, VA, US, 23219)
Consulting Software Engineer (RICHMOND, VA, US, 23219)

Dominion Energy • Richmond (VA)

Hybrid
USD 116,000 - 151,000
Senior Intelligence Analyst
Senior Intelligence Analyst

Dominion Energy • Cayce (KY)

On-site
USD 91,000 - 118,000
Health benefits
401k plan
Tuition assistance
Intern - Substation Tech Operations (GLEN ALLEN, VA, US, 23060)
Intern - Substation Tech Operations (GLEN ALLEN, VA, US, 23060)

Dominion Energy • Glen Allen (VA)

On-site
USD 30,000 - 41,000
Intern - Substation Tech Operations
Intern - Substation Tech Operations

Dominion Energy • Glen Allen (VA), Northern (KY)

On-site
USD 30,000 - 41,000
Intern - Business Technology Analyst (CAYCE, SC, US, 29033)
Intern - Business Technology Analyst (CAYCE, SC, US, 29033)

Dominion Energy • Cayce (SC)

On-site
USD 30,000 - 34,000
Intern-Network Services - Columbia SC (CAYCE, SC, US, 29033)
Intern-Network Services - Columbia SC (CAYCE, SC, US, 29033)

Dominion Energy • Cayce (SC)

On-site
USD 30,000 - 39,000
Health benefits
Vacation
401k matching
+5