Senior Penetration Tester

Jimmy Jazz

Norfolk (VA)

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tharros seeks a Senior Penetration Tester to lead offensive cybersecurity testing across diverse environments. You will plan, execute, and report on advanced cyber tests against physical, virtualized, or cloud platforms while collaborating with the OPTEVFOR mission. Strong expertise in ethical hacking and toolchains is essential.

You will validate exploit safety, analyze attacker tactics, and produce actionable test results for the Navy OT& E program in a fast-moving, mission-focused team.

Qualifications

  • Minimum 6 years of experience performing any combination of penetration testing, red teaming, or exploitation development.
  • Proficient in leading red team operators to accomplish objectives.
  • Offensive security certifications OSCP/OSCE/GX-PT/GXPM/PNPT/HTB CPTS required.
  • Proficient with multiple offensive tools including Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus.

Responsibilities

  • Execute test events, including CVPAs, adversarial assessments, and cyber tabletop exercises.
  • Review and refine test plans to ensure feasibility and safety.
  • Develop test assets and maintain a reference library for future campaigns.
  • Capture and document findings, including risk and deficiency sheets.

Skills

Metasploit
Cobalt Strike
Core Impact
Burp Suite
Nessus
SharpHound
BloodHound

Education

OSCP
OSCE
GX-PT
GXPM
PNPT
HTB CPTS

Tools

Nmap
Kali Linux

Job description

Contact information
  • Employee Type Regular Full-Time
  • Name Talent Acquisition
  • Email recruiting@tharros.com
Description

Tharros has an immediate opportunity to support the US Navy with operational test and evaluation support. The Senior Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and report cyber test results. In this role youwill conduct cyber tests on operational systems, in laboratory environments, or in cyber range environments. Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage all authorized resources and analytic techniques to penetrate/access targeted networks and systems under test in support of OPTEVFOR’s cyber OT&E mission. Team member will perform these duties under the supervision of the 01D Cyber Operations Officer.

  • Review and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance.
  • Maintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.
  • Research, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process.
  • Support development and execution of TTPs for penetration testing or Red Teaming.
  • Research adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.
  • Participate in OPTEVFOR Cyber Test planning:
    • Conduct open-source research and system under test documentation review to familiarize with the system’s mission, architecture and interfaces including critical components to identify its attack surface and threat vectors
    • Participate in check point meetings
    • Guide development of test plan objectives
    • Review test plans, ensuring that test plans objectives are feasible
    • Participate in test planning site visits
  • Participate in test preparation:
    • Participate in site pre-test coordination visits. Support in-brief to the test site.
    • Lead red team test plan review
    • Add relevant system technical information to test reference library
    • Organize and lead research presentations for advanced capability development in support of future tests
    • Prepare OPTEV-RT test assets (Government Furnished)
  • Execute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned:
    • Use OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus).
    • Employee ethical hacking expertise to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols (HTTP, FTP, etc.), and network security services (PKI, HTTPS, etc.) to accomplish test objectives
    • Be able to accomplish testing independently and provide direction to basic and intermediate operators
    • Ensure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to
    • Follow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures
    • Verify collected data for accuracy and completeness
  • Participate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets).
  • Participate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events.
  • Attend OPTEVFOR required meetings in support of OT&E.
  • Generate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.
Requirements
  • Minimum 6 years’ experience performing any combination of: penetration testing, red teaming, or exploitation development.
  • Minimum 6 years’ with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.
  • Offensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.
  • Proficient in multiple offensive tools, including:
    • Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound
  • Ability to validate functionality and safety of offensive tools (e.g. exploits) given the source code and document the results.
  • Ability to detect malicious activity of a program using dynamic analysis techniques and document the results.
  • Independently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and verbal communication skills.
Summary

Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.

In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.

Tharros. See Everything. Secure Anything.

Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Jimmy Jazz • Norfolk (VA)

On-site
USD 85,000 - 120,000
Senior Penetration Tester
Senior Penetration Tester

ANALYGENCE • Norfolk (VA)

On-site
USD 120,000 - 160,000
Range Configuration Manager
Range Configuration Manager

Jimmy Jazz • San Antonio (TX)

On-site
USD 120,000 - 160,000
Senior Portfolio Manager
Senior Portfolio Manager

Jimmy Jazz • Geraghty Village (MD)

On-site
USD 130,000 - 210,000
Senior Penetration Tester: Cyber OT&E & Red Team Lead
Senior Penetration Tester: Cyber OT&E & Red Team Lead

ANALYGENCE • Norfolk (VA)

On-site
USD 120,000 - 160,000
SharePoint Developer
SharePoint Developer

Jimmy Jazz • San Antonio (TX)

On-site
USD 90,000 - 130,000
Senior Information Security Analyst
Senior Information Security Analyst

Jimmy Jazz • Naval Air Station Patuxent River (MD)

On-site
USD 120,000 - 160,000
Cybersecurity Systems Engineer
Cybersecurity Systems Engineer

Jimmy Jazz • Dahlgren (VA)

On-site
USD 120,000 - 160,000
Knowledge Manager
Knowledge Manager

Jimmy Jazz • Geraghty Village (MD)

On-site
USD 95,000 - 130,000
Cyber Penetration Tester for Navy OT&E
Cyber Penetration Tester for Navy OT&E

Jimmy Jazz • Norfolk (VA)

On-site
USD 85,000 - 120,000