Job Description
Responsibilities
- Conduct advanced penetration testing and red team engagements against enterprise systems and applications.
- Emulate real-world threat actors and Advanced Persistent Threat (APT) tactics, techniques, and procedures (TTPs).
- Perform exploit development, post-exploitation activities, lateral movement, persistence, and privilege escalation.
- Assess Active Directory environments and identify opportunities for compromise and escalation.
- Utilize offensive security tools including Cobalt Strike, Metasploit, Nmap, Kali Linux, Burp Suite, and similar platforms.
- Identify security weaknesses and provide detailed technical findings and remediation recommendations.
- Develop custom scripts and tools to support offensive security operations.
- Produce high-quality technical reports and present findings to technical and non-technical stakeholders.
- Collaborate with defensive cybersecurity teams to improve detection and response capabilities.
Skills and Requirements
- Bachelor's degree in one of the following or a related technical discipline:
- Cybersecurity
- Cyber Operations
- Cyber Engineering
- Information Systems
- Information Technology
- Computer Science
- Software Engineering
- Computer Engineering
- Electrical Engineering
- Mathematics with a Computer Science concentration
- 7+ years of dedicated penetration testing or offensive cyber operations experience.
- Hands-on experience conducting:
- Red team engagements
- Adversary emulation
- Exploit development
- Post-exploitation activities
- Lateral movement and privilege escalation
- Experience working within Active Directory environments.
- Proficiency with offensive security tools such as:
- Cobalt Strike
- Metasploit
- Nmap
- Kali Linux
- Burp Suite
- Experience operating in Windows, Linux, and macOS environments.
- Strong scripting or programming experience in at least two languages such as:
- Python
- C+Java
- Rust
- C#
- Assembly
Certifications
Required:
- One of the following Offensive Security certifications:
- DoD 8570 Baseline Certification:
- Clearance: Active TS/SCI clearance required. Experience supporting Navy or DoD cyber operations programs.
- Experience conducting enterprise-level adversary emulation exercises.
- Familiarity with MITRE ATT&CK methodologies.
- Experience briefing executive leadership and technical stakeholders.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.